Security researchers have documented a fast-moving phishing campaign that abuses LinkedIn's reputation, the familiar mechanics of business communication, and the infrastructure of one of the world's largest software companies. The attack begins as an email message, apparently tied to LinkedIn, that claims a potential business partner has sent a signed contract for review. To make the message look credible, the sender's name and company match real individuals, although a quick check would reveal the sender does not actually work at the claimed company. This layered forgery makes even a skeptical user pause.
Key facts
- Target: Professionals who use LinkedIn for business communication.
- Lure: Fake inquiry about business collaboration, with a request to review an attached signed contract.
- Attachment: An HTML file disguised as a PDF using double file extensions.
- Credential capture: The attachment opens a convincing LinkedIn login page with the victim's email pre-filled.
- Infrastructure abuse: The attackers route the victim through Adobe's A/B testing platform, Adobe Target, to evade security filters and track success.
- Impact: LinkedIn credentials are sent to attacker-controlled servers while the victim is redirected to the real LinkedIn.
The anatomy of the attack
From the recipient's perspective, the attack appears straightforward. The email contains an attachment identified as a PDF file, but the actual file is an HTML document designed to render in a browser. When opened, the user is confronted with what looks like LinkedIn's legitimate login page. The email address field is already populated with the intended victim's address, which creates a personalized experience and lowers suspicion.
If the victim types the password and clicks the submit button, the credentials are transmitted to a remote server controlled by the attackers. In the same instant, the browser is redirected to the genuine LinkedIn website. For the victim, nothing seems wrong; they may believe they simply experienced a routine session timeout. Meanwhile, the stolen password is already in the hands of the attackers, who can use it to access the victim's LinkedIn account and potentially other accounts where the same password is reused.
Why the email is easy to fall for
The phishing lure is built around a scenario that is completely normal for professionals: a request from someone who wants to do business, with a contract attached for review. LinkedIn is commonly used for B2B outreach, and receiving emails from LinkedIn is routine. The attackers impersonate both a person and a company that actually exist, searching for targets who are likely to be active on LinkedIn. Unlike generic phishing messages that announce a suspicious account compromise or a package delivery, this one speaks the language of everyday business.
The email text itself is short and professional, with no obvious grammatical red flags. It does not ask the recipient to click a random link; instead, it relies on the attachment being opened. This simple social engineering technique works because many recipients are conditioned to open attached documents from potential business partners. The sender's name may not match the email address when checked carefully, but the message is crafted to be just distracting enough to pass a quick review.
The attachment is not a PDF
A critical technical trick used by the attackers is the double file extension. The attachment is named something like Contract_2026_Form.pdf, but the actual file is an HTML page. Many email providers and operating systems hide known file extensions by default, so users see only the final .pdf and may not notice that the file is actually an .html document hidden behind a longer, multi-part extension. This simple technique has been used for years, but it remains effective because it exploits the visual habits of users and the default settings of many file explorer interfaces.
The HTML file itself is heavily obfuscated. This makes it more difficult for email security tools to analyze the file and detect malicious scripts. Obfuscation can hide the code that constructs the fake login page and manages the data exfiltration. When the antivirus or email gateway looks at the attachment, it may see only scrambled text rather than clear proof of credential phishing. The combination of double extension and obfuscation is intended to defeat both human inspection and automated detection.
Fake login page pre-fills the target's email
Once the HTML file is rendered, the victim sees what appears to be a LinkedIn sign-in screen. The attackers have already inserted the victim's email address into the form field. That small touch makes the page feel more authentic and cuts down on the user's mental friction. Many legitimate websites also remember email addresses, so this is a familiar feature. When the victim only needs to type a password, they are more likely to do so quickly and without inspecting the address bar or the page structure.
The fake page also mimics the overall look and feel of LinkedIn's interface, using the same colors, logos, and layout. Without close scrutiny, it is difficult to distinguish the fraudulent page from the real one. The victim's brain registers the familiar visual cue and may overlook the fact that the URL is not the ordinary LinkedIn web address.
Abusing Adobe Target as a trusted redirection layer
The most distinctive aspect of this campaign is the use of Adobe Target, a legitimate A/B testing and personalization platform housed under Adobe's control. Rather than sending the browser directly to a malicious server, the attackers route the victim through Adobe Target's infrastructure, which is associated with a trusted Adobe-owned domain. From the outside, the network traffic appears to be flowing to Adobe, which is an well-known, trustworthy company.
This strategy has two clear advantages for the attackers. First, it makes the phishing traffic look legitimate to network monitoring tools and security systems that maintain allowlists for major tech companies. A security analyst who sees traffic to Adobe may dismiss it as harmless. Second, the use of Adobe Target allows the attackers to track how many victims click through, submit credentials, and complete the attack funnel. A/B testing platforms are designed to measure user behavior, so the attackers can collect valuable metrics about their campaign's effectiveness, such as how many users opened the attachment and entered a password.
This is not entirely new; cybercriminals have a history of abusing legitimate cloud services, analytics platforms, and tracking domains to hide malicious activity. Google Forms, Microsoft Azure, and various URL shortening services have been used for phishing in the past. The abuse of an A/B testing platform adds a sophisticated layer of trust, as these domains are often present on corporate allowlists and rarely flagged by traditional security controls.
Why this attack is dangerous
The combination of social engineering, file obfuscation, and infrastructure abuse makes this campaign potentially dangerous even for users who consider themselves knowledgeable about phishing. Most people know they should not click suspicious links or open unexpected attachments, but the context here is plausible enough to bypass that instinct. A moment of distraction is often all that is needed to fall into the trap.
Furthermore, LinkedIn accounts hold a significant amount of professional data. An attacker who gains access to a LinkedIn account can collect contact information, private messages, and details about job titles, employment history, and business relationships. That data can then be used for identity theft, targeted business email compromise, or further social engineering attacks against the victim's connections. Because people often reuse passwords across work and personal accounts, the stolen credential may also provide access to email, intranet portals, or even financial systems.
Researchers who analyzed the campaign note that the construction is cheap and easy to reproduce. The components involved - fake emails, HTML attachments, and redirectors - can be assembled quickly by attackers with limited technical skill. The infrastructure required to host the password-harvesting pages is inexpensive and can be taken down and replaced. As a result, similar campaigns are likely to keep circulating, and new ones will appear with different brands, lures, and legitimate services as a disguise.
How users and organizations can defend themselves
The first and most important step is to maintain a healthy skepticism about unsolicited attachments. Even if an email looks as if it came from a business contact or a LinkedIn connection, users should verify the sender's identity before opening any file. If the email is unexpected, a quick phone call or a separate email using a known address can confirm whether the message is genuine. In this campaign, the sender's email address did not match the company they claimed to represent, which is a useful clue.
Users should also avoid logging into sensitive accounts through links embedded in messages. Instead of following the URL shown in the browser, they should type the official website address directly into the browser or use a bookmark that they created themselves. For LinkedIn and other critical accounts, enabling multi-factor authentication is one of the most effective defenses. Even if the attacker steals the password and attempts to use it, a second authentication factor will block them unless they also control the victim's phone or security key.
Organizations should deploy email security tools that inspect attachments in an isolated sandbox, rather than simply scanning them with traditional signatures. Sandboxing can reveal malicious behavior, such as code embedded in HTML that attempts to call out to a remote server. Regular user education and phishing simulation exercises are also essential. Employees who are trained to spot double file extensions, fake login pages, and unusual URLs are less likely to fall victim to a well-crafted attack like this one.
Indicators and long-term mitigation
Red flags that users can watch for include mismatches between the display name and the actual email address, unexpected attachments with name extensions that seem odd or inconsistent with the email's content, and URLs that redirect through third-party platforms before reaching the main site. In this specific case, the fake login page appeared after opening an attachment rather than through a link, and the page used an Adobe-related redirect to hide its final destination.
Security teams should also consider monitoring logs for unusual outbound traffic to localized services and tracking domains, including those associated with marketing platforms. While most traffic to Adobe is legitimate, unexpected connections to A/B testing or personalization services from the same user account could indicate a phishing interaction. Behavioral analytics can identify anomalous patterns, such as a user who has never visited a particular service suddenly receiving a redirect to it.
Although this campaign is sophisticated in its use of trusted infrastructure, the underlying phishing technique remains the same as ever: tricking people into entering their credentials on a page that does not belong to the service they intend to access. The abuse of Adobe Target only increases the chance that the victim will not stop to inspect carefully. As attackers continue to adopt newer tools and services to hide in plain sight, the need for layered security and continuous user awareness becomes more important than ever.
Source: Help Net Security News