Executive Summary
Since August 2025, Unit 42 has tracked a series of sophisticated phishing campaigns where attackers impersonate Palo Alto Networks talent acquisition staff. These attacks specifically target senior-level professionals by leveraging scraped LinkedIn data to craft highly personalized lures.
The specific attack vector uses social engineering to manufacture a bureaucratic barrier reg...
These sophisticated phishing campaigns highlight the growing threat of targeted attacks in modern recruitment processes. The attackers exploit professionals' eagerness for employment opportunities, create artificial bureaucratic barriers to solicit fees, and weaponize the complexity of hiring systems. This pattern echoes earlier manipulation strategies such as preying on job seekers' aspirations (ARC-0017) and utilizing psychological tactics like urgency and scarcity (ARC-0023). By posing as leg...
