Security researchers have warned that LinkedIn is being used in over half of all phishing attack incidents at a global level.

This data comes from Check Point, which recorded a dramatic uptick in LinkedIn brand abuse in phishing incidents in the first quarter of 2022.

This is a significant increase, as, during the last quarter of 2021, LinkedIn held the fifth spot on the list, holding only 8% of impersonations in all global phishing attacks.

The second most mimicked brand in the first quarter of 2022 is German package delivery company DHL. Increased shopping has caused shipping-related phishing messages to rise significantly, with impersonations from DHL, FedEx, Maersk, and Ali Express, representing 21% of all phishing attacks.

Below is our chart showing which brands have been impersonated by threat actors in the first quarter of 2022, as a percentage of global phishing attacks:


LinkedIn phishing attacks invariably mimic the social networking platform’s “Request to connect” emails. Other scam emails include LinkedIn’s profile reports, as can be seen below:

When clicked, these emails will redirect the user to a fake LinkedIn login page, which will prompt the user to submit their account details. This page will look legitimate, much as the one featured below:

These login pages can easily deceive most people, especially if the user is busy or has no concern about the risks of phishing. However, there is an easy way to check that this page is fake. The URL at the top of the screen does not contain “LinkedIn”, and does not contain any information that would normally be found in a LinkedIn login page URL.

Other clues that you may encounter will be that LinkedIn does feature in the URL, but is misspelt, or contains additional words such as “LinkedInpage” or “LinkedInUK“.

Social media phishing is becoming more popular amongst threat actors. This is largely due to the many uses hackers have for the takeover of accounts.

For example, hackers may use compromised social media accounts to perform spear-phishing attacks, post links to malware-hosting sites on workgroup chats, or send spyware directly to users who trust them.

Another potential scam would be sending malware disguised as job offer documents, and convincing applicants to open the file and activate malicious macro code.

Another theory regarding why LinkedIn is used so much is that threat actors are likely aiming to perform spear-phishing attacks on high-interest targets, such as employees of organisations with private data.


Mobile Phishing Links

During TecSec’s phishing training, we discovered that phishing emails viewed on mobile devices are significantly more dangerous than those viewed on desktop computers. This is likely due to the lack of a cursor, which can help to identify the URL of a phishing link before it is clicked. By hovering over the link and reading it before clicking it, users can inspect the destination URL, and decide whether or not this is a website that they trust. This can still be done on a mobile device, it’s just less obvious.

In Outlook mobile, if users ‘long press‘ – (press down on the link), the app will display the destination URL, as shown below:

While this technique can be used to check the destination URL of links, it is more difficult compared to its desktop equivalent, and hard to perform without accidentally clicking on the malevolent link. Overall, this makes mobile phishing links much more dangerous.

North Korean hackers have launched multiple spear-phishing campaigns in the past that disguise themselves using LinkedIn, and these have proven to be very successful.


North Korea, Phishing, and LinkedIn

A North Korean cybercriminal organization, known as “The Lazarus Group“, has utilized LinkedIn lures in their ongoing spear-phishing campaigns.

A security researcher at F-Secure labs has stated that “Lazarus Group’s activities are a continued threat: the phishing campaign associated with the attack has been observed continuing into 2020, raising the need for awareness and ongoing vigilance amongst organizations operating in the targeted verticals“.

In 2018, Lazarus stole roughly $250 million in a single targeted phishing attack.

In this attack, Lazarus spearphished a member of a cryptocurrency exchange using a fake LinkedIn email. This email contained a word document disguised as a General Data Protection Regulation (GDPR) protected file, which required the user to enable content to gain access. However, after enabling the content the document executed a malicious embedded macro code that connected to a bit.ly link and deployed malware payloads after first collecting and exfiltrating information about the user’s system to the attackers’ servers.

Their malware features several capabilities allowing Lazarus hackers to “download additional files, decompress data in memory, execute arbitrary commands, and steal credentials from several sources“.

The United Nations Security Council have stated that North Koreans were behind major cryptocurrency heists that led to losses of $571 million in just 2 years. The U.S. Treasury later sanctioned three DPRK-sponsored and financially motivated hacking groups, these being Lazarus, Andarial, and Bluenoroff.

The U.S. military has estimated that North Korea’s total number of hackers is over 6,000, with many operating from other countries including Russia, China and India.

It is important to realize that while North Korea does implement targeted phishing campaigns, the size of their organisation is required to run their automated mass-phishing campaigns. The ability to continuously make, test, execute, and maintain phishing campaigns that target millions of users requires criminal groups such as Lazarus to employ thousands of hackers.

These automated campaigns are indiscriminate and target any organisation. Even small organisations are vulnerable, especially those that do not have adequate cyber security training and are unaware of the dangers that phishing presents.

If you are interested in protecting your organisation from attack campaigns such as these, invest in effective and comprehensive cyber security training.

TecSec offers cyber security training that includes simulated phishing campaigns. These are fake phishing emails which will test the ability of employees to spot emails that could harm their organisation.


TecSec are qualified providers of cyber security services, and are endorsed by seven separate UK police forces. We can provide affordable cyber security training of the kind mentioned in this article to help prevent your staff from falling victim to phishing emails, whether they be targeted or automated.

If you would like to organise a conversation with us, please call us at 0114 223 8000 or email us at info@tecsec.co.uk