Skip to content

Hackers exploiting LinkedIn DMs in major phishing campaign

Digit.Fyi November 3, 2025

Security researchers have flagged a surge in phishing attacks targeting direct messages, with cyber-criminals using a complex series of redirects through trusted Google and Microsoft services to mask the destination of malicious links.

Push Security’s latest research reveals the ‘undetected and unreported’ threat lurking within the professional networking platform, as threat actors increasingly exploit DMs to deliver seemingly benign links.

After a series of redirects through legitimate platforms and cloud services, such as Google Sites, Google , Firebase, and Microsoft Dynamics, Push found victims were presented with a Microsoft-branded “view document” page, protected by a Cloudflare Turnstile challenge.

Once completed, the victim was served an adversary-in-the-middle (AiTM) phishing page designed to steal the user’s Microsoft session, bypassing controls like MFA.

That, coupled with page obfuscation techniques, such as randomised visual elements, titles, and code structures, can defeat detection signatures, bypassing routine safeguards with inboxes.

“These tactics are becoming increasingly common in the phishing ecosystem and reflect just how well attackers understand how modern defences operate,” said Jacques Louw, chief product officer at Push Security.

“Because sits outside enterprise phishing filters and other traditional cybersecurity solutions, attackers are able to initiate , send malicious links, and socially engineer victims with fewer barriers.

“The result is a blind spot in enterprise visibility and control, leaving employees exposed even on devices managed by corporate IT.”

This is the second -targeted campaign identified by Push in recent months, suggesting that attackers are increasingly viewing the platform as a reliable route to reach high-value targets such as executives, sales leaders, and hiring managers.

The security firm said that the rise of social media–delivered phishing campaigns underscores a broader shift in the evolution of attacker strategy, with adversaries turning to less-guarded communication channels as corporate email defences improve.

Push researchers expect this trend to continue, with future phishing operations blending across channels and platforms that sit outside traditional enterprise security visibility, and attackers utilising legitimate cloud services to maximise reach and minimise the chance of detection.

“These campaigns show how attackers are bypassing every traditional control point — email gateways, link scanners, domain filters — by abusing the same trusted tools that enterprises rely on,” added Louw.

“We’re seeing adversaries take advantage of the trust placed in legitimate services like Google and Microsoft to build redirect chains that hide their activity. This level of sophistication means phishing is becoming increasingly difficult to detect and stop for most organisations.”

Extracted Entities