An Iran-nexus cyber espionage group known as UNC1549 has been attributed to a new campaign targeting European telecommunications companies, successfully infiltrating 34 devices across 11 organizations as part of a recruitment-themed activity on LinkedIn. The targeted 11 companies are located in Canada, France, the United Arab Emirates, the United Kingdom, and the United States. "The malicious DLL files used by the threat actor exhibit similar characteristics in the export section." "Legitimate DLL files are modified to facilitate a seamless execution of a DLL side-loading attack, where function names are substituted with direct string variables. "They do not just infect devices; they actively search for sensitive data and ways to keep their access alive."