In a recent phishing campaign aimed at gathering personal information for LinkedIn ,unsuspecting users were tricked into revealing their account usernames and passwords via an HTML file.
Phishing scams are very common in our time, but the latest one was a big one that led security researchers to look into it in depth.
They found that the fake emails contained an HTML file attachment , which had the same code as the LinkedIn log-in page, except that once the user filled in their details, they would go straight to the scammers.
The recipient is tricked into going to the website by informing them that irregular activity has been detected on their LinkedIn account and that they must perform a mandatory security update, which is available in the email attachment.
Using an HTML file for phishingis particularly important because the user is no longer protected from the blacklists of dangerous websites, which are used by browsers to prevent users from loading dangerous pages.
It was also observed that the scammers modified the LinkedIn name in the email and did not use the capital “i” but the lowercase “l,” in order to avoid any filters that email clients have, without users noticing the difference.
Symantec advises enabling the two-factor authentication (2FA) security feature for the website. This is done from the privacy and security settings of the profile and ensures that, even if the username and password are lost, a third code sent to the account holder's phone ensures that no one else can use that account.

