{"id":11071,"date":"2023-10-18T11:13:39","date_gmt":"2023-10-17T22:13:39","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=11071"},"modified":"2023-10-18T11:13:39","modified_gmt":"2023-10-17T22:13:39","slug":"look-out-for-linkedin-smart-links","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=11071","title":{"rendered":"Look out for LinkedIn Smart Links"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.22.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row column_structure=&#8221;1_2,1_2&#8243; _builder_version=&#8221;4.22.2&#8243; _module_preset=&#8221;default&#8221; background_image=&#8221;\/wp-content\/uploads\/2023\/10\/LinkedInMobile.png&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.22.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.22.2&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;rgba(255,255,255,0.96)&#8221; custom_padding=&#8221;20px|20px|20px|20px|false|false&#8221; border_radii=&#8221;on|20px|20px|20px|20px&#8221; border_width_all=&#8221;1px&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>This is a great example of needing new tools that didn&#8217;t used to exist, to keep cyber-safe, even if they add cost to our cyber-protection.<\/p>\n<h2>Hijacking your trust in LinkedIn<\/h2>\n<p><a href=\"https:\/\/cofense.com\/blog\/linkedin-smart-links-credential-phishing-campaign\/\">Cybersecurity firm Cofense have detected phishing campaigns<\/a> that used LinkedIn links called &#8220;Smart Links\u201d to bypass security gateways for deliver credential phishing.<\/p>\n<p>Smart Links are used by LinkedIn Sales Navigator and other business users to track content and engagement.\u00a0 A smartlink is the mysterious 8 character code in a LinkedIn URL at the end.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"\/wp-content\/uploads\/2023\/10\/CoFenseSmartLinkFig1.webp\" width=\"652\" height=\"168\" alt=\"\" class=\"wp-image-11074 alignnone size-full\" \/><\/p>\n<p style=\"text-align: center;\"><em>Fig 1 Cofense SmartLink structure<\/em><\/p>\n<p>We&#8217;re told that the hacker code uses this to read from the attached email and use that to present a fake Microsoft login page.<\/p>\n<p>If they can convince you to put in your details, and to enter your MFA code, then voila, they have access to your 365.<\/p>\n<p>Because it&#8217;s using the LinkedIn URL, and we all tend to trust LinkedIn, your email filter is blindsided.\u00a0 It is not something we can easily filter out because LinkedIn is a trusted domain.<\/p>\n<p>That means the victim recieves a legitmate looking email,\u00a0 with a link they are enticed to click on, that opens a fake Microsoft 365 which includes the victims email address so it looks even more authentic.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_2&#8243; _builder_version=&#8221;4.22.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.22.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.22.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text _builder_version=&#8221;4.22.2&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;rgba(0,0,0,0.07)&#8221; custom_padding=&#8221;20px|20px|20px|20px|false|false&#8221; border_radii=&#8221;on|20px|20px|20px|20px&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;]<\/p>\n<p>&nbsp;<\/p>\n<h2>Kinetics KARE is stepping up<\/h2>\n<p><span><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\">The Kinetics KARE team are testing a brand new tool that helps isolate login pages in a virtual sandbox to test them and filter out fakes. It is brand new technology. Subject to testing, this will be deployed to our <a href=\"http:\/\/kinetics.co.nz\/kare-security-plus\/\">Kinetics Security Plus<\/a> premium service.<\/span><\/span><span><span class=\"ui-provider a b c d e f g h i j k l m n o p q r s t u v w x y z ab ac ae af ag ah ai aj ak\" dir=\"ltr\"><\/span><\/span><\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is a great example of needing new tools that didn&#8217;t used to exist, to keep cyber-safe, even if they add cost to our cyber-protection. Hijacking your trust in LinkedIn Cybersecurity firm Cofense have detected phishing campaigns that used LinkedIn links called &#8220;Smart Links\u201d to bypass security gateways for deliver credential phishing. Smart Links are [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":11076,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-11071","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/11071","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11071"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/11071\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11071"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11071"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11071"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}