LinkedIn Phishing Spoof Bypasses Google Workspace Security

  /     /     /  
Publicated : 23/11/2024   Category : security


LinkedIn Phishing Spoof Bypasses Google Workspace Security


A credential-stealing attack that spoofed LinkedIn and targeted a national travel organization skates past DMARC and other email protections.



A phishing email purportedly from LinkedIn with the subject line We noticed some unusual activity was discovered targeting users at a travel organization, in an attempt to pilfer their credentials on the social-media platform.
The phishing campaign slipped past Googles email security controls after cheating email authentication checks via SFP and
DMARC
, according to Armorblox, whose email security system at the victim organization found and stopped the attack pointed at some 500 user inboxes.
The main call-to-action button (
Secure my account
) included within the email contains a bad URL and took victims to a fake landing page. This fake landing page ... mimicked a legitimate LinkedIn sign in page that included LinkedIn logos, language, and illustrations that mirrored true LinkedIn branding, Armorblox wrote
in a post
about the attack campaign.

Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
LinkedIn Phishing Spoof Bypasses Google Workspace Security