{"id":18193,"date":"2022-02-03T13:17:11","date_gmt":"2022-02-03T21:17:11","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/02\/03\/news-11926\/"},"modified":"2022-02-03T13:17:11","modified_gmt":"2022-02-03T21:17:11","slug":"news-11926","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/02\/03\/news-11926\/","title":{"rendered":"How Phishers Are Slinking Their Links Into LinkedIn"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Thu, 03 Feb 2022 18:49:38 +0000<\/strong><\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-58391\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/02\/redirect.png\" alt=\"\" width=\"760\" height=\"460\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/02\/redirect.png 1019w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/02\/redirect-768x465.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/02\/redirect-782x473.png 782w\" sizes=\"auto, (max-width: 760px) 100vw, 760px\" \/><\/p>\n<p>If you received a link to <strong>LinkedIn.com<\/strong> via email, SMS or instant message, would you click it? Spammers, phishers and other ne&#8217;er-do-wells are hoping you will, because they&#8217;ve long taken advantage of a marketing feature on the business networking site which lets them create a LinkedIn.com link that bounces your browser to other websites, such as phishing pages that mimic top online brands (but chiefly Linkedin&#8217;s parent firm <strong>Microsoft<\/strong>).<\/p>\n<p>At issue is a &#8220;redirect&#8221; feature available to businesses that chose to market through LinkedIn.com. The LinkedIn redirect links allow customers to track the performance of ad campaigns, while promoting off-site resources. These links or &#8220;<strong>Slinks<\/strong>&#8221; all have a standard format: &#8220;https:\/\/www.linkedin.com\/slink?code=&#8221; followed by a short alphanumeric variable.<\/p>\n<p>Here&#8217;s the very first Slink created: http:\/\/www.linkedin.com\/slink?code=1, which redirects to the homepage for <strong>LinkedIn Marketing Solutions<\/strong>.<\/p>\n<p>The trouble is, there&#8217;s little to stop criminals from leveraging newly registered or hacked LinkedIn business accounts to create their own ad campaigns using Slinks. <strong>Urlscan.io<\/strong>, a free service that provides detailed reports on any scanned URLs, also offers a historical look at suspicious links submitted by other users. <a href=\"https:\/\/urlscan.io\/search\/#task.domain%3Alinkedin.com%20AND%20task.url%3Aslink%20AND%20NOT%20page.domain%3Alinkedin.com\" target=\"_blank\" rel=\"noopener\">This search via Urlscan<\/a> reveals dozens of recent phishing attacks that have leveraged the Slinks feature.<\/p>\n<p>Here&#8217;s <a href=\"https:\/\/urlscan.io\/result\/74a84028-d554-43c1-a9ea-1618586c64f2\/\" target=\"_blank\" rel=\"noopener\">one example from Jan. 31<\/a> that uses Linkedin.com links to redirect anyone who clicks to a site that spoofs <strong>Adobe<\/strong>, and then prompts users to log in to their <strong>Microsoft<\/strong> email account to view a shared document.<\/p>\n<div id=\"attachment_58387\" style=\"width: 755px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" aria-describedby=\"caption-attachment-58387\" loading=\"lazy\" class=\"size-full wp-image-58387\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/02\/adobe-msphish.png\" alt=\"\" width=\"745\" height=\"283\" \/><\/p>\n<p id=\"caption-attachment-58387\" class=\"wp-caption-text\">A recent phishing site that abused LinkedIn&#8217;s marketing redirect. Image: Urlscan.io.<\/p>\n<\/div>\n<p>Urlscan also found <a href=\"https:\/\/urlscan.io\/result\/4b08c28c-b313-4d79-a6b0-f3ab301136dc\/\" target=\"_blank\" rel=\"noopener\">this phishing scam from Jan. 12<\/a> that uses Slinks to spoof the <strong>U.S. Internal Revenue Service<\/strong>. <a href=\"https:\/\/urlscan.io\/result\/00abef42-70a6-4e89-aa29-2ec951a8752f\/#behaviour\" target=\"_blank\" rel=\"noopener\">Here&#8217;s a Feb. 3 example<\/a> that leads to a phish targeting <strong>Amazon <\/strong>customers. <a href=\"https:\/\/urlscan.io\/result\/5bd64123-b19e-4f72-8cc9-0fc7b38c841e\/\" target=\"_blank\" rel=\"noopener\">This Nov. 26 sample from Urlscan<\/a> shows a LinkedIn link redirecting to a <strong>Paypal<\/strong> phishing page.<span id=\"more-58383\"><\/span><\/p>\n<p>Let me be clear that the activity described in this post is not new. Way back in 2016, security firm <strong>Fortinet<\/strong> <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/linkedin-and-baidu-redirecting-to-fat-loss-and-brain-improvement-scam\" target=\"_blank\" rel=\"noopener\">blogged about LinkedIn&#8217;s redirect being used to promote phishing sites and online pharmacies<\/a>. More recently in late 2021, <strong>Jeremy Fuchs<\/strong> of <strong>Avanan<\/strong> wrote that the use of a LinkedIn URL may mean that any profession &#8212; the market for LinkedIn &#8212; could click.<\/p>\n<p>&#8220;Plus, more employees have access to billing and invoice information, meaning that a spray-and-pray campaign can be effective,&#8221; Fuchs <a href=\"https:\/\/www.avanan.com\/blog\/shortened-linkedin-url-used-for-phishing\" target=\"_blank\" rel=\"noopener\">wrote<\/a>. &#8220;The idea is to create a link that contains a clean page, redirecting to a phishing page.&#8221;<\/p>\n<p>In a statement provided to KrebsOnSecurity, Linkedin said it has &#8220;industry standard technologies in place for URL sharing and chained redirects that help us identify and prevent the spread of malware, phishing and spam.&#8221; LinkedIn also said it uses 3rd party services &#8212; such as Google Safe Browsing, Spamhaus, Microsoft, and others &#8212; to identify known-bad URLs.<\/p>\n<p>KrebsOnSecurity couldn&#8217;t find any evidence of phishers recently using LinkedIn&#8217;s redirect to phish LinkedIn credentials, but that&#8217;s certainly not out of the question. In a less complex attack, an adversary could send an email appearing to be a connection request from LinkedIn that redirects through LinkedIn to a malicious or phishous site.<\/p>\n<p>Also, malicious or phishous emails that leverage LinkedIn&#8217;s Slinks are unlikely to be blocked by anti-spam or anti-malware filters, because LinkedIn is widely considered a trusted domain, and the redirect obscures the link&#8217;s ultimate destination.<\/p>\n<p>Linkedin&#8217;s parent company &#8212; Microsoft Corp &#8212; is by all accounts the most-phished brand on the Internet today. A <a href=\"https:\/\/blog.checkpoint.com\/2021\/07\/15\/brand-phishing-report-q2-2021-microsoft-continues-reign\/\" target=\"_blank\" rel=\"noopener\">report last year<\/a> from <strong>Check Point<\/strong> found roughly 45 percent of all brand phishing attempts globally target Microsoft. Check Point said LinkedIn was the sixth most phished brand last year.<\/p>\n<p>The best advice to sidestep phishing scams is to avoid clicking on links that arrive unbidden in emails, text messages and other mediums. Most phishing scams invoke a temporal element that warns of dire consequences should you fail to respond or act quickly. If you\u2019re unsure whether the message is legitimate, take a deep breath and visit the site or service in question manually \u2014 ideally, using a browser bookmark to avoid <a href=\"https:\/\/krebsonsecurity.com\/?s=typosquatting&amp;x=0&amp;y=0\" target=\"_blank\" rel=\"noopener\">potential typosquatting sites<\/a>.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2022\/02\/how-phishers-are-slinking-their-links-into-linkedin\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/02\/redirect.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Thu, 03 Feb 2022 18:49:38 +0000<\/strong><\/p>\n<p>If you received a link to LinkedIn.com via email, SMS or instant message, would you click it? Spammers, phishers and other ne&#8217;er-do-wells are hoping you will, because they&#8217;ve long taken advantage of a marketing feature on the business networking site which lets them create a LinkedIn.com link that bounces your browser to other websites, such as phishing pages that mimic top online brands (but chiefly Linkedin&#8217;s parent firm Microsoft).<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[16740,5588,24811,16186,24812,11187,24813,16888,11448,10516,11372,24814,17006],"class_list":["post-18193","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-a-little-sunshine","tag-amazon","tag-avanan","tag-check-point","tag-fortinet","tag-irs","tag-jeremy-fuchs","tag-latest-warnings","tag-linkedin","tag-microsoft","tag-paypal","tag-slinks","tag-web-fraud-2-0"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18193","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18193"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18193\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18193"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18193"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18193"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}