LinkedIn phishing targets finance execs with fake board invites
ID: 52966b98-d11b-520a-8eb9-88b24d1b807e
STIX ID: report--52966b98-d11b-520a-8eb9-88b24d1b807e
Feed Name: Bleeping Computer
Push Security and BleepingComputer observed a LinkedIn-based phishing campaign that sends direct messages offering fake executive board invitations to finance executives; victims are redirected via a Google open redirect to attacker-controlled sites and a Firebase-hosted fake "LinkedIn Cloud Share" which then forces a Cloudflare Turnstile check before presenting an adversary-in-the-middle fake Microsoft login page designed to capture credentials and session cookies. The report lists example malicious domains (e.g., payrails-canaccord.icu, boardproposalmeet.com, sqexclusiveboarddirect.icu), explains the use of CAPTCHA to evade automated analysis, and advises caution with unsolicited LinkedIn links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
