City
Epaper

Hackers exploiting LinkedIn's chat, job posting tools to steal users' data

By IANS | Updated: August 30, 2022 11:25 IST

New Delhi, Aug 30 Microsoft-owned LinkedIn is being used by hackers to spread data stealing malware via sending ...

Open in App

New Delhi, Aug 30 Microsoft-owned LinkedIn is being used by hackers to spread data stealing malware via sending connection requests in disguise of people working with reputed companies, a report showed on Tuesday.

Researchers from AI cyber-security firm CloudSEK found that scammers are exploiting LinkedIn's chat and job posting features to share links/files that are laced with stealer malware.

Since most LinkedIn users accept any and all connection requests they receive, scammers can easily make connections and build credibility on the platform.

After building credibility, the actors share malicious files and links, which are then opened by unsuspecting victims.

Once opened, a stealer malware is deployed on the victim's system, from which it steals passwords, credit card information, and other sensitive data, and sends it to the threat actors.

"This large-scale misuse of LinkedIn could be the gravest threat yet. The underlying promise of professionalism makes it easier for scammers to run campaigns at scale," said Rahul Sasi, CEO and Founder of CloudSEK.

This is how it works.

A LinkedIn connection reaches out to you regarding a project, from a well-known company, that might be of interest to you.

The connection shares a URL or a zip file with the information stealer embedded. The file size is usually restricted to 100MB to evade antivirus or security tools.

"Once opened, the file automatically downloads the stealer malware onto your system. It then steals passwords and cookies stored on your browser," warned the report.

The stolen credentials are then used to compromise and take over the victim's social media and email accounts.

"We recommend that all users verify connection requests before accepting them, even if the requester is connected to someone you know," said Sasi.

It is also important to scan documents and files shared on LinkedIn, before opening them on your systems.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: Rahul SasidharanLinkedinLin linLe corporation
Open in App

Related Stories

MumbaiMumbai Cyber Police Nab Man Behind International Job Scam Racket

Entertainment‘No One Can See It’: Shraddha Kapoor Says LinkedIn Marked Her Verified Account as Fake

BusinessShantanu Naidu, Ratan Tata's Millennial Manager Joins Tata Motors In New Role; Pens Emotional Note

TechnologyWomen Hiring for Leadership Roles in India Rises to 23.2% in Early 2024: LinkedIn Report

NationalSurvey Reveals 88% of Indian Employees Considering For A Job Change in 2024

Technology Realted Stories

TechnologyRBI eases forex norms to help exporters amid global uncertainties

TechnologyMPC decisions to further increase credit flow, promote inclusive growth: Bankers

TechnologyIndian job market witnesses 10 per cent growth in September: Report

TechnologyYoung night shift workers more at risk of developing kidney stones: Study

TechnologyRBI slashes inflation forecast to 2.6 pc in FY26 over GST reforms, benign food prices