Warnings remain rampant, social networks are great sources of information for attackers and a great way to enter a victims’ circle of trust. But there are plenty of victims to go around.

An ongoing social engineering campaign targeting LinkedIn users has been using the “professional” social network to popularize a dating site but, according to Websense researchers, the final aim of the campaign is not to find true love.

RELATED STORIES
Social Media Big Attack Target: IBM Report
Trojans Make Up 80% of Malware
New Revenue Stream for Ransomware
Malware Targets Java, Adobe Bugs

The attackers created a fake LinkedIn account under the name Jessica Reinsch, which currently has over 400 connections, and ends up used to view the profiles of potential targets and to lead them to a specific dating site.

“Search features within the social network provide an easy way for scammers and legitimate LinkedIn users to zoom in on their target audience,” the researchers said. “Whether you are a recruiter looking for potential candidates, a dating scammer looking for “mature gentlemen,” or an advanced attacker looking for high-profile directors within particular industry sectors, LinkedIn users have access to tools to help refine their search.”

Schneider Bold

In order to do this more effectively, the scammers made sure to make the account in question a premium account, which allows them to search for users based on their job function, seniority level and company size — all information that can come in handy for future social engineering attacks.

Features of the premium account also allow for a greater degree of interaction with targets. Should a target view the scam profile, the scammer can then see that, for all views. The scammer could also contact any LinkedIn member and search across a greater number of profiles, the researchers said.

The researchers said the scammers are using the dating site as a lure. They pointed out the site does not currently sport any malicious code, but that its IP address has been previously linked to domains that did, as well as to a Autonomous System Number (ASN) that, at one time, included C&C URLs for a number of exploit kits.

ISSSource

Pin It on Pinterest

Share This