logo

LinkedIn phishing targets finance execs with fake board invites

ID: 52966b98-d11b-520a-8eb9-88b24d1b807e

STIX ID: report--52966b98-d11b-520a-8eb9-88b24d1b807e

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-30

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

Push Security and BleepingComputer observed a LinkedIn-based phishing campaign that sends direct messages offering fake executive board invitations to finance executives; victims are redirected via a Google open redirect to attacker-controlled sites and a Firebase-hosted fake "LinkedIn Cloud Share" which then forces a Cloudflare Turnstile check before presenting an adversary-in-the-middle fake Microsoft login page designed to capture credentials and session cookies. The report lists example malicious domains (e.g., payrails-canaccord.icu, boardproposalmeet.com, sqexclusiveboarddirect.icu), explains the use of CAPTCHA to evade automated analysis, and advises caution with unsolicited LinkedIn links.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.