Houston News Buzz

collapse
Home / Daily News Analysis / LinkedIn-themed phishing abuses Adobe’s A/B testing platform

LinkedIn-themed phishing abuses Adobe’s A/B testing platform

Jul 17, 2026  Twila Rosenbaum 27 views
LinkedIn-themed phishing abuses Adobe’s A/B testing platform

A sophisticated phishing campaign has emerged, targeting professionals with fraudulent LinkedIn business emails. The attack leverages Adobe's legitimate A/B testing platform to evade security measures and steal login credentials. Security researchers at Malwarebytes documented the campaign, highlighting the growing trend of abusing trusted infrastructure for malicious purposes.

The attack from the victim's perspective

The attack begins with an email that appears to be a routine business inquiry. The subject line often references a signed contract or a business proposal, prompting the recipient to open an attached file. The sender's name and company appear legitimate, though careful inspection reveals that the sender does not actually work at the claimed organization. The email is short and professional, mirroring typical LinkedIn communications.

Upon opening the attachment, which is an HTML file disguised as a PDF using double extensions (e.g., contract.pdf.html), the victim is presented with a realistic LinkedIn login page. The page is pre-filled with the victim's email address, creating a personalized and trustworthy appearance. If the victim enters their password and clicks submit, they are redirected to the real LinkedIn website. In the background, the credentials are sent to a server controlled by the attackers.

The tricks behind the attack

The attackers employ multiple layers of deception to increase the attack's effectiveness and evade detection. First, they impersonate a reputable platform—LinkedIn—which is widely used for professional networking. The lure of a business inquiry is entirely plausible, making it less likely that victims will question the email's authenticity.

Second, they use double extensions to trick users and email security filters. The HTML file is named with a .pdf extension, so unsuspecting users may double-click it believing it to be a PDF. The file's actual extension (.html) is hidden by default on many systems, especially if the file extension display is disabled. This technique exploits common user behavior and expectations.

Third, the HTML file is heavily obfuscated to hinder analysis by security tools. Obfuscation methods include encoding JavaScript strings and using dynamic DOM manipulation to construct the phishing page only when the file is opened in a browser. This makes it difficult for static analysis to detect the malicious intent.

Fourth, the phishing page pre-fills the victim's email address. Attackers likely obtain this information from the email's recipient field or from previously compromised data. This personalization increases the victim's sense of trust and reduces the likelihood they will scrutinize the page's authenticity.

Finally, the attackers abuse Adobe's infrastructure. Instead of directing the browser directly to a malicious server, they route the request through Adobe Target, a legitimate A/B testing platform hosted at the omtrdc.net domain. Adobe Target is used by marketers to test variations of web pages. When a victim clicks the link in the email or the attachment, the browser first contacts Adobe Target, which then redirects to the attacker-controlled server. This makes the network traffic appear to be destined for a trusted Adobe address, bypassing many email and web security filters that whitelist such domains. Additionally, the attackers can use Adobe Target's analytics capabilities to track which victims clicked through and which submitted their credentials, refining future attacks.

These attacks are built to scale

The phishing campaign is cheap to execute and highly scalable. Attackers can send thousands of emails with minimal effort, and the use of Adobe Target allows them to dynamically adjust the campaign based on real-time data. Malwarebytes researchers note that such attacks are likely to continue circulating, especially as professionals increasingly rely on LinkedIn for business communications.

While careful users can spot warning signs—such as mismatched sender information, unsolicited attachments, or requests for credentials—a moment of distraction is often enough to fall victim. The pre-filled email field and the professional tone lower the victim's guard. Moreover, the use of a trusted third-party platform like Adobe Target adds a layer of credibility that even tech-savvy individuals may overlook.

The scale of LinkedIn phishing has grown significantly in recent years. According to industry reports, LinkedIn was the most impersonated brand in phishing attacks in 2025, accounting for nearly 45% of all credential phishing attempts. The professional context makes these attacks particularly effective, as victims are more likely to trust communications related to job offers, business partnerships, or networking opportunities.

How to protect yourself

To defend against such attacks, users should adopt a multilayered security approach. First, avoid opening unsolicited attachments, especially from unknown senders. If an email claims to contain a contract or proposal, verify the sender's identity through a separate communication channel before opening any files.

Second, enable multi-factor authentication (MFA) for all critical accounts, including LinkedIn. MFA adds an extra layer of security, ensuring that even if credentials are stolen, the attacker cannot access the account without the second factor. LinkedIn supports various MFA methods, including authenticator apps and hardware tokens.

Third, develop the habit of accessing online accounts only through official apps or by typing the official website URL directly into the browser. Avoid clicking links in emails, even if they appear legitimate. Bookmarking important sites can help ensure you are visiting the correct page.

Fourth, keep web browsers and security software up to date. Modern browsers often include built-in phishing protection that can warn users when they visit known malicious sites. However, because the attackers are using a trusted platform like Adobe Target, the browser may not flag the initial redirect. Therefore, user vigilance remains the most critical defense.

Fifth, regularly monitor account activity and audit login credentials. If you suspect your credentials have been compromised, change your passwords immediately and review your account's login history for unauthorized access. LinkedIn allows users to see recent login attempts and locations, which can help identify breaches.

Organizations should also educate employees about phishing risks, conduct simulated phishing exercises, and implement email security solutions that can detect double extension attachments and obfuscated HTML files. Advanced threat protection tools can analyze file behavior and block malicious scripts even if they are disguised or hosted behind whitelisted domains.

The evolving threat landscape

Phishing attacks are becoming increasingly sophisticated, leveraging legitimate services and social engineering to bypass traditional defenses. The abuse of Adobe Target is a notable example of a technique known as "domain fronting" or "trusted platform abuse." Security researchers warn that other platforms, such as Google Cloud Functions, Amazon Web Services, and Microsoft Azure, are also being exploited in similar ways.

The use of A/B testing platforms for phishing is particularly insidious because these services are designed to handle high traffic volumes and complex redirects, making them ideal for large-scale campaigns. Attackers can dynamically change the destination URL based on geographic location, device type, or other parameters, further evading detection.

As the cat-and-mouse game between attackers and defenders continues, users must remain proactive about security. The key facts to remember are: phishing emails impersonating LinkedIn are common and often target business professionals; attackers use trusted platforms like Adobe Target to hide malicious activity; multi-factor authentication is a critical safeguard; and verifying any unsolicited communication before acting is essential.


Source:Help Net Security News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy