A newly documented phishing campaign is targeting professionals with fake LinkedIn business emails and abusing a trusted service operated by Adobe to evade detection. The attackers have combined social engineering with technical obfuscation to create a scalable threat that is likely to persist, as experts from Malwarebytes recently highlighted.
The attack from the victim’s perspective
The attack begins with an email that, at first glance, resembles a routine business inquiry. The subject line typically suggests that someone wants to initiate a business relationship through LinkedIn, and has attached a signed contract for the recipient to review. The message is short, professional, and uses the name of an actual company and employee. However, if the potential victim does a quick check, they will find that the sender does not actually work at the company mentioned.
Those who open the attachment—an HTML file disguised as a PDF using double extensions—are greeted by a familiar-looking LinkedIn login page. The email address of the target is already filled in, making the page feel personalized and trustworthy. If the victim types their password and hits submit, they are redirected to the real LinkedIn. But in the background, the credentials are sent to a server controlled by the attackers. The victim may never realize their account has been compromised, especially because they land on the legitimate LinkedIn site after the fake login.
The tricks behind the attack
The attackers employed several layers of deception to make the campaign effective and difficult to detect—both for users and for email security solutions. First, they impersonate a legitimate platform (LinkedIn) and use a lure that feels natural: professionals routinely receive business inquiries through LinkedIn. Second, they disguise the attached HTML file as a PDF by using double extensions (e.g., contract.pdf.html), which may cause some email clients or operating systems to hide the real extension. The HTML file itself is heavily obfuscated, making it harder for automated scanners to parse its malicious intent.
Third, the fake login form is pre-filled with the target’s email address, which increases the psychological trust factor. The attackers likely obtain the victim’s email from public sources or previous data breaches. Fourth—and most critically—the attackers abuse Adobe’s infrastructure. Instead of sending the victim’s browser directly to their own servers, they route the request through Adobe Target, a legitimate A/B testing platform hosted at an omtrdc.net domain. Adobe Target is widely used by enterprises to run experiments on their websites, and its network traffic is generally trusted by security systems. By hijacking this legitimate platform, the attackers make the outgoing network traffic appear to be going to an Adobe address, not a malicious one. Furthermore, the Adobe infrastructure likely allows the attackers to track which victims actually clicked through and submitted their credentials, enabling them to prioritize follow-up attacks.
Why this matters for cybersecurity
Phishing campaigns that abuse trusted third-party services are a growing trend. Attackers are increasingly leveraging legitimate platforms—such as cloud storage services, marketing tools, or analytics platforms—to host malicious content or to redirect traffic through. This technique, sometimes called “living off the cloud,” helps attackers bypass traditional security controls that rely on domain reputation and URL filtering. The use of Adobe Target in this campaign is particularly clever because omtrdc.net is a domain often whitelisted by organizations, and its traffic blends in with normal business web requests.
The campaign also highlights the sophistication of modern credential harvesting. Pre-filling email addresses, using obfuscated HTML, and double extensions are not new tricks individually, but combining them with platform abuse creates a potent mix. The average user—even one who is security-aware—might miss the warning signs when everything feels familiar and professional.
How Adobe Target works and why it’s abused
Adobe Target is a personalization and A/B testing tool that allows marketers to deliver different content variations to users and measure performance. It works by running JavaScript that communicates with Adobe’s servers at omtrdc.net. When a legitimate website uses Adobe Target, the user’s browser sends requests to that domain. Attackers can leverage the same infrastructure by embedding calls to Adobe Target in their phishing pages. They might create a scenario where the phishing page loads from a seemingly benign URL that then redirects to Adobe Target, which in turn redirects to the attacker’s credential collection page—or simply passes the user through Adobe’s systems to mask the true destination. In this campaign, the attackers appear to have used Adobe Target as a redirector: the phishing link in the email initially points to a URL on omtrdc.net, and that server then forwards the victim to the fake LinkedIn login hosted on the attacker’s server. Because the first hop is to a trusted Adobe domain, many email security gateways and web proxies let the request through.
These attacks are built to scale
Careful users might spot the phishing warning signs: the attachment is an HTML file, not a PDF; the URL after the redirect is not linkedin.com but a lookalike domain; the email’s sender address may be slightly off. But a moment of distraction is often all it takes. Moreover, as Malwarebytes researchers correctly note, these attacks are cheap to set up, easy to scale, and likely to keep circulating. The attackers can reuse the same phishing kit with minor modifications, change the lure, and target new victims with minimal effort.
The implications for businesses are significant. A compromised LinkedIn account can be used for further social engineering attacks, business email compromise (BEC), or to spread malware within professional networks. LinkedIn accounts often contain a wealth of information about employees, partners, and clients, making them valuable targets.
Defending against such attacks
To protect against these types of credential harvesting campaigns, organizations and individuals should adopt a multi-layered approach. For users, the most important rule is to avoid opening unsolicited attachments, even if they appear to come from a known contact. Instead, verify the email’s legitimacy through an independent channel—for example, by calling the sender directly. Users should enable multi-factor authentication (MFA) for critical accounts, including LinkedIn. Even if a password is stolen, MFA can block the attacker from logging in. Additionally, users should make it a habit to only access their accounts through official apps, by typing the official website directly into their browser, or via a bookmark they created themselves—never through links in emails.
On the organizational side, email security solutions should be configured to flag attachments that are HTML files pretending to be PDFs, and security teams should consider blocking or monitoring access to domains like omtrdc.net if Adobe Target is not used within the organization. However, for companies that do use Adobe Target, monitoring is more complex. Advanced detection rules can look for anomalous behavior, such as a user accessing an Adobe Target URL and then immediately being redirected to an unknown domain. Security awareness training should include specific examples of phishing that abuse trusted services, so employees know to be wary even when the email appears to come from a legitimate brand.
The role of URL filtering and web gateways
Modern secure web gateways (SWG) and next-generation firewalls can perform deep inspection of HTTPS traffic, but they cannot inspect encrypted traffic from trusted domains unless they decrypt it. Many organizations avoid decrypting traffic to major cloud services due to privacy concerns and performance overhead. This leaves a gap that attackers can exploit. Security teams should consider implementing policies that monitor traffic to and from A/B testing platforms, especially if such platforms are not required for business operations. If they are required, separating the testing environment from production and using dedicated subdomains may help.
Wider implications for platform abuse
This campaign is part of a broader trend where attackers abuse legitimate internet infrastructure to conduct phishing and malware distribution. From Google Forms to Facebook Pages to Amazon S3 buckets, almost any widely used platform can be co-opted for malicious purposes. The abuse of Adobe Target is particularly insidious because it leverages a tool designed for marketing optimization, a space often overlooked by security teams. As the line between marketing technology and security continues to blur, organizations must adopt a holistic view of risk that includes their marketing tech stack.
Security researchers have long warned that threat actors will continue to exploit the trust placed in well-known domains. The LinkedIn-themed phishing campaign is a textbook example: it combines social engineering, technical obfuscation, and platform abuse into an attack that is hard to detect and easy to scale. The only way to stay ahead is to combine user education with robust technical controls that can adapt to evolving tactics.
Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats.
Source:Help Net Security News

Leave a comment
Your email address will not be published. Required fields are marked *