LinkedIn is a platform that many people in society love to use. On it, you can log in to your personal work experience, position, expertise, and works to communicate with other people in the same field. You can also wait for Bole to discover you, but from another perspective, it is equivalent to exposing some of your own business-related information to the eyes of interested people. Recently, Russian hackers have taken advantage of the uniqueness of this platform and launched large-scale attacks. If your work is relatively confidential, you should be careful.

Russian hackers launch massive attack via fake LinkedIn emails
LinkedIn is a platform that often sends letters to members to notify whether someone has viewed your profile, sent you a message, etc. The frequency is so frequent that the volume of letters can almost be considered spam. Security researchers at Google have discovered a massive hacking campaign in their latest investigation, which likely originated from Russian government-linked hackers sending fraudulent LinkedIn profiles to members. This new attack mainly exploits vulnerabilities in Windows and iOS. It is unclear how many members were targeted by this attack. In this operation, attackers used LinkedIn messages as a pretext to target government officials from Western European countries by sending malicious links to the country. If the target accessed the links from an iOS device, they would be redirected to a domain controlled by the attackers.

In addition to announcing this new information, Google’s threat analysis team also disclosed some new attack methods that hackers use zero-day vulnerabilities to carry out. For example, a vulnerability in all major browsers that use Webkit on iOS such as Safari has also been exploited, but fortunately Apple has fixed the problem before (CVE-2021-1879). This year has been pretty bad with hackers exploiting WebKit and zero-day vulnerabilities. In order to gain access and exploit vulnerabilities in iOS devices, hackers designed scam-type websites to deceive people. According to Google, this attack was launched by Russian hackers in order to steal authentication cookies through well-known platforms such as LinkedIn, Microsoft, Google, Yahoo and Facebook.

Shane Huntley, who led the study, said it was impossible to know the success rate of these scams, but Google sends more than 4,000 warnings to users every month to remind users that someone is trying to penetrate their accounts.
Source: KOCPC Chinese