logo

Fake LinkedIn emails abuse Adobe to track victims

ID: 12bd114d-279e-5f00-8973-8178e51471a8

STIX ID: report--12bd114d-279e-5f00-8973-8178e51471a8

Feed Name: Malwarebytes Blog

Threat Score
50/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

...
...

Malwarebytes details a LinkedIn-themed phishing campaign where attackers send emails with a double-extension attachment (pdf.html) containing obfuscated JavaScript that displays a fake LinkedIn login. The campaign abuses Adobe Target (lnkd.tt.omtrdc.net) as a redirect/tracking point and exfiltrates credentials via a Russian-hosted PHP endpoint (http://a1263367.xsph.ru/taam/Ln.php), then redirects victims to the legitimate LinkedIn site to avoid detection; the report includes indicators and mitigation advice.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.