LinkedIn InMail Spoofing Malware Campaign Unleashes ConnectWise RAT

LinkedIn InMail spoofing delivers the ConnectWise RAT via outdated branding and weak email security — posing a significant risk to organizations.

執筆者
Sunny Yadav
Sunny Yadav
Mar 6, 2025
2 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Cybersecurity defenders are confronting yet another sophisticated phishing tactic that uses the trusted LinkedIn brand.

Recently detailed by Cofense, the campaign uses a spoofed LinkedIn InMail notification to distribute the ConnectWise Remote Access Trojan (RAT). The attackers aim to deceive recipients with an email that mimics a legitimate business inquiry, prompting them to unwittingly download malicious software.

Crafting a convincing deception

The campaign’s email is meticulously designed to appear as if it originates from a LinkedIn InMail notification — a feature that lets users communicate with professionals outside their network. However, subtle indicators reveal the deception:

  • The email employs an outdated template, reminiscent of LinkedIn’s pre-2020 interface, to resonate with users familiar with the older design.
  • It purports to be from a sales director seeking a quote. It includes a profile image of Cho So-young, a real individual, repurposed to boost authenticity.
  • The supposed company, “DONGJIN Weidmüller Korea Ind.,” cleverly blends names from legitimate entities, though no such firm exists.

Bypassing security protocols

Despite these red flags, the email bypassed modern security defenses. An analysis of its security headers reveals that the Sender Policy Framework (SPF) check resulted in a softfail due to an unauthorized IP address.

Additionally, the absence of a proper DomainKeys Identified Mail (DKIM) signature — ordinarily present in legitimate LinkedIn communications — further underscores its fraudulent nature. Interestingly, the configured Domain-Based Message Authentication, Reporting and Conformance (DMARC) policy, which marked suspicious emails as spam rather than rejecting them outright, enabled the email to slip past even robust systems like Microsoft Defender for Endpoint.

Advertisement

The operational mechanics of the attack

Once a user interacts with the email by clicking the “Read More” or “Reply To” buttons, an embedded link silently triggers the download of the ConnectWise RAT installer.

The campaign does not push a direct “download” command — a tactic often associated with malware delivery — but instead relies on the pretext of a legitimate business inquiry. This subtle approach is designed to lower the guard of even cautious users, particularly those accustomed to LinkedIn’s messaging interface.

Why this matters to organizations

For organizations, the implications of such sophisticated phishing campaigns are significant. This attack is a prime example of how threat actors repurpose trusted brands to exploit human psychology and bypass technical defenses.

A successful compromise could grant adversaries remote access to critical systems, leading to data breaches, operational disruptions, and substantial financial losses. In today’s interconnected business environment, maintaining robust email authentication measures and continuous employee training is not just advisable — it is essential. You must scrutinize even seemingly routine communications and implement advanced security protocols to safeguard your digital assets.

Explore the best ways to improve your email security and protect your organization from evolving cyber threats.

Sunny Yadav

Sunny Yadav

Content Writer

Sunny is a content writer for eSecurity Planet (eSP) with a bachelor’s degree in technology and experience writing for leading cybersecurity brands like Panda Security, Upwind, and Vanta. At eSP, he covers the latest news on cyberattacks, cryptography, data protection, and emerging threats and vulnerabilities. He also explores security policies, governance, and endpoint and mobile security. Sunny enjoys hands-on testing, rigorously evaluating tools to assess their capabilities and real-world performance. He also has extensive experience working with AI tools like ChatGPT and Gemini, experimenting with their applications in cybersecurity, content creation, and research.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。