Trending Topics

LinkedIn users under attack via private messages: do not click that link!
With 1.2 billion users, LinkedIn falls way behind the largest social networking site, Facebook, with its staggering 3 billion active monthly users. What it lacks in numbers, however, LinkedIn more than makes up for in the value of its data. Never mind the width, feel the quality.
That’s why cybercriminals are aggressively targeting the professional networking platform. In the past year, they’ve upped their game, and the latest attack methodology highlights how the threat is evolving.
I recently reported how attackers were using public reply comments on posts, appearing to be from LinkedIn itself. The posts claim policy violations and tell users to lodge an official appeal to prevent account suspension. The cybercriminals used the official LinkedIn URL shortener, “lnkd.in,” making it harder for users to see that it was an external credentials phishing link.
Now these attackers are moving their attention from reply comments to LinkedIn private messaging with one-on-one conversations.
“Attackers targeted high-value individuals with precision, then used trusted open-source tools to bypass detection and achieve persistent access,” confirmed ReliaQuest Threat Intelligence Analyst Emily Jia in a January 20 report.
The evolved campaign exploits private messaging in order to deliver “weaponized files via Dynamic Link Library (DLL) sideloading,” Jia said, “combined with a legitimate, open-source Python pen-testing script – likely to deploy a remote access trojan (RAT)”.
Not only can the attackers bypass email-based detection controls but they can scale with ease. All while maintaining persistence within any compromised systems.
LinkedIn warning: what can you do?
“As professionals spend more time communicating through social platforms and direct messages, attackers are following them there, exploiting the trust, informality, and lack of monitoring that often exist outside traditional security controls,” warned Bobby Ford, Chief Strategy and Experience Officer at Doppel.
“When a malicious message arrives through a professional network instead of email, it feels more legitimate and faces far less scrutiny.”
I urge you to read the original analysis if you are of a technical bent. If not, ask someone in the organisation who is technical to do so. Knowledge is power; understanding attack methodologies is key to preventing them.
“Security awareness must extend beyond email to include social DMs,” said Ford, “with active monitoring for impersonation and account abuse, stronger account recovery controls, and clear guidance around what information or files should never be shared through social channels.”
