logo

LinkedIn-themed phishing abuses Adobe’s A/B testing platform

ID: cb942976-f1c5-5165-b409-fd1b3ed88430

STIX ID: report--cb942976-f1c5-5165-b409-fd1b3ed88430

Feed Name: Help Net Security

Threat Score
55/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: Zeljka Zorz

...
...

A phishing campaign sends seemingly legitimate LinkedIn business emails with double-extension attachments (HTML disguised as PDF). When opened, the attachment shows a heavily obfuscated, personalized fake LinkedIn login page; credentials entered are exfiltrated to attacker servers while the user is redirected to the real LinkedIn. The attackers also abuse Adobe Target (omtrdc.net) to make traffic appear trusted and to track victim interactions. Users are advised to enable MFA, avoid opening unsolicited attachments, and access accounts via official sites or bookmarks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.