Hackers are exploiting LinkedIn Smart Links in phishing to bypass security measures and avoid detection. Their goal is to steal credentials for Microsoft accounts. This is not the first time that LinkedIn Smart Links have been misused in attacks.

Smart Links are part of LinkedIn 's Sales Navigator service and are used for marketing and tracking purposes . They allow business accounts to send content, using trackable links to determine who engaged with that content .
Hackers exploit Smart Links because they use the LinkedIn domain followed by eight characters. They appear to come from a trusted source, thus bypassing email.
See also: Gmail: Strengthens defenses against phishing and malware from 2024
As mentioned above, the same technique has been used in the past. Cofense researchers discovered a similar campaign in late 2022 targeting users in Slovakia.
New campaign aims to steal credentials from Microsoft accounts
A recent increase in the abuse of LinkedIn Smart Links was detected, with over 800 emails with various subjects directing users to phishing pages.
According to Cofense, the recent attacks occurred between July and August 2023 and used 80 smart links that came from new or compromised business accounts on LinkedIn.
According to Cofense data, the most targeted sectors of this latest campaign are the financial, construction, energy and healthcare.
See also: EvilProxy: Phishing in Microsoft 365 via open redirect indeed.com

The emails sent to targets use topics related to payments, human resources, documents, security , and more, with the embedded link/button triggering a series of redirects from a “trusted” LinkedIn Smart Link.
To increase the sense of authenticity on the Microsoft login page , the smart links sent to victims are customized to contain the target's email
The phishing page will read the email address from the link clicked by the victim and automatically fill it in the form. The victim will only have to fill in the password ,just like on the legitimate login portal.
The phishing page resembles the regular Microsoft login portal rather than a custom company-based portal. This may deter some individuals who are familiar with their employer's unique portals.
See also: AtlasCross Group: Using the American Red Cross as a phishing lure
Users should be educated not to rely solely on email security tools to block threats. Phishing attacks are an ever-growing threat in the digital world, as attackers use various techniques to trick victims into giving up their personal information. It is essential to always be vigilant.
Source: www.bleepingcomputer.com
