Linchakin

Cybercriminals Can Post Jobs on LinkedIn Posing as Any Employer They Want

 August 26, 2021     No comments   

Cybercriminals LinkedInLax verification around what company is offering a given job on LinkedIn allows attackers to create bogus job postings for malicious purposes.

It appears that despite LinkedIn being potentially used as medium by cybercriminals to connect with victims, the ability exists today for a threat actor to impersonate being part of a legitimate company when posting a job.

Scams using job postings are one of the most powerful social engineering tactics used today – using a well-established site like LinkedIn to begin with and completely putting aside email-based phishing, matched with the desire of the potential candidate to follow whatever process is necessary to get that cool job at that great company with the awesome pay adds up to be a perfect cyber-storm.

I wrote about such attacks back in 2019, where a developer at a bank was looking for a new job and was tricked into installing a RAT under the premise it was a program designed to allow him to fill out an application. It appears that LinkedIn still has no means for verifying that the poster is from the company they say they are.

According to Bleeping Computer, security researchers were recently able to walk through the posting process without needing to validate the company they purported to work for. This is a huge advantage for the threat actor. Think about it – if I want to target a specific industry or company, post a dev job as a competing company in that same sector. Simple, elegant, and likely effective social engineering – all thanks to LinkedIn.

This kind of attack is one of the slickest as the victim feels completely like they are initiating the connection (as opposed to a phishing email that shows up in your Inbox) and is emotionally invested in following the process through to completion.

Falling for social engineering is one of the main reasons organizations need their users to enroll in continual Security Awareness Training – it’s not just within email that social engineering tactics are found; and this latest finding on LinkedIn affirms that notion.

Adblock test (Why?)


You may be interested in:
>> Is a Chromebook worth replacing a Windows laptop?
>> Find out in detail the outstanding features of Google Pixel 4a
>> Top 7 best earbuds you should not miss

Related Posts:
>> Recognizing 12 Basic Body Shapes To Choose Better Clothes
>>Ranking the 10 most used smart technology devices
>> Top 5+ Best E-readers: Compact & Convenient Pen
  • Share This:  
  •  Facebook
  •  Twitter
  •  Google+
  •  Stumble
  •  Digg
Email ThisBlogThis!Share to XShare to Facebook

Related Posts:

  • The EVGA X570 Dark Motherboard Review: A Dark Beast For Ryzen Quite a few of the motherboards we have reviewed over the last month have been aimed at enthusiasts with a penchant for extreme overclocking. Today'… Read More
  • SketchUp Pro 2021.1.1 Crack + Keygen [32/64 Bit] DownloadSketchUp Pro 2021.1.1 Crack + License Key [Win+ Mac] SketchUp Pro 21.1.299 Crack is truly an advanced software in the field of 3D graphics and desig… Read More
  • Big Tech Vs. Big Government: The Choice is Pretty Bleak October 8th 2021 new story After years of rapid growth without limits, Big Tech’s power is facing challenges from lawmakers that … Read More
  • What is Kindergarten CogAT? Here’s Everything you Must Know Have you ever wondered that your child may be finding it difficult to cope up with the early years of school? It has been established now that every… Read More
  • Apple's iOS 15.1 could make your iPhone camera even betterByAmelia Bamsey NewsSnap happy!It's been three weeks since we were introduced to iOS 15 and already beta testing for 15.1 is underway. But what does the next update have in store fo… Read More
Newer Post Older Post Home

0 Comments:

Post a Comment


Copyright © 2025 Linchakin | Powered by Blogger
Design by Hardeep Asrani | Blogger Theme by NewBloggerThemes.com | Distributed By Gooyaabi Templates