September 26, 2022  —  Eric Swotinsky

Phishing campaign abuses LinkedIn Smart Links

An ongoing phishing campaign is abusing a feature from LinkedIn called Smart Links in order to bypass some security filters.

This feature allows users to create landing pages that contain up to 15 documents, and send this page to other people with trackable links. Unfortunately, the feature can also be used as a redirector, enabling attackers to create links that will redirect the user to dangerous websites. One current theme is falsified package delivery messages which mimic the postal service of Slovakia.

Another phishing actor is currently going after government contractors in the USA. The email lure promises access to government portals that allow the bidding for lucrative government projects. In actuality, these messages link to a PDF which itself redirects victims to a malicious website.

The Advanced Email Security pack for Acronis Cyber Protect Cloud prevents phishing emails from reaching your users' inboxes, preventing them from revealing their credentials in such attacks.