LinkedIn-Themed Phishing Abuses Adobe Target (A/B Testing) for Credential Theft
LinkedIn-Themed Phishing Abuses Adobe Target (A/B Testing) (TL-2026-0630) is a high-severity phishing campaign, first published 2026-05-29. It has no confirmed attribution, affects LinkedIn (Microsoft) LinkedIn account credentials, maps to 12 MITRE ATT&CK techniques (T1027, T1036, T1056), and is covered by 9 detection rules and 14 indicators of compromise.
Key facts for TL-2026-0630
- Threat ID
- TL-2026-0630
- Severity
- HIGH
- Status
- MONITORING
- Category
- PHISHING
- First published
- 2026-05-29
- Last reviewed
- 2026-05-29
- Attribution confidence
- NONE
- Motivation
- FINANCIAL
- Target sectors
- business services, recruitment, sales, technology, professional services, financial
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 14
A financially motivated phishing campaign impersonates LinkedIn business/contract inquiries and delivers double-extension HTML attachments (pdf.html) that render a fake LinkedIn login page with the victim's email pre-filled. Victim browsers are routed through Adobe's legitimate Adobe Target A/B-testing edge (lnkd.tt.omtrdc.net) to lend trust and track click-through, after which harvested credentials are exfiltrated to a PHP endpoint on a Russian SprintHost-hosted domain (a1263367.xsph.ru) and the victim is bounced to the real LinkedIn.
How LinkedIn-Themed Phishing Abuses Adobe Target (A/B Testing) works
Researchers at Malwarebytes (2026-05-27), with corroboration from Help Net Security and TechNADU (2026-05-29), documented an active credential-theft phishing campaign that pairs classic brand impersonation with novel abuse of a legitimate enterprise marketing service. The lure is a short, professional business-inquiry email built around a signed-contract theme: the attacker claims to be a buyer who 'would like to do business with you via LinkedIn.' The spoofed sender uses a real company name and address but a fabricated employee identity, and the company location is frequently mismatched (non-US), which is one of the few reliable tells.
The email carries an HTML attachment that uses a deceptive double file extension (e.g. *.pdf.html) so that recipients believe they are opening a PDF contract. When opened in the browser, the file executes heavily obfuscated JavaScript. The payload is concealed using two layers of encoding: URL-encoding wrapping two Base64-encoded sections. Once decoded, the script renders a pixel-accurate fake LinkedIn login page with the victim's own email address hardcoded into the form and made non-editable, increasing perceived legitimacy and ensuring the harvested username matches the targeting list.
The campaign's distinguishing tradecraft is its use of Adobe Target, a legitimate A/B-testing and personalization platform within Adobe Experience Cloud, hosted on the omtrdc.net domain. The phishing flow sends the victim's browser through https://lnkd.tt.omtrdc.net/rest/v1/delivery (the Adobe Target delivery API; lnkd.tt.omtrdc.net resolves via CNAME to adobetarget.data.adobedc.net on Adobe-owned IP space). This 'living-off-trusted-sites' hop serves two purposes: network traffic appears to flow to a trusted Adobe address, evading reputation-based controls, and the A/B-testing telemetry lets the operator track exactly which recipients clicked through and reached the credential form. Adobe Target is not used to receive the stolen credentials — it is purely a trusted redirect and victim-tracking channel.
When the victim submits the form, the credentials are POSTed in the background to http://a1263367.xsph.ru/taam/Ln.php, where the parameter AA carries the hardcoded email and BB carries the user-entered password. The exfiltration host is a free subdomain on xsph.ru, the free virtual-hosting service operated by Russian provider SprintHost (AS35278), which has a documented history of hosting malware and phishing content (tracked by URLhaus and phish.report). Immediately after exfiltration the victim is redirected to the genuine business.linkedin.com to minimize suspicion and delay incident reporting. The operation is described as cheap and scalable, consistent with a commodity credential-harvesting crew rather than a tracked APT; the Russian hosting and free-tier infrastructure provide weak attribution signal only.
MITRE ATT&CK techniques used in TL-2026-0630
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1684.001 Impersonation
Credential Access
Command and Control
T1071 Application Layer Protocol; T1102 Web Service
Execution
Initial Access
Exfiltration
T1567 Exfiltration Over Web Service
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts
Reconnaissance
Affected products and versions in LinkedIn-Themed Phishing Abuses Adobe Target (A/B Testing)
- LinkedIn (Microsoft) — LinkedIn account credentials
Vulnerable versions: All user accounts (brand impersonated; credentials targeted) - Adobe — Adobe Target / Adobe Experience Cloud (omtrdc.net delivery edge)
Vulnerable versions: Public delivery API abused as trusted redirect/tracking hop
Remediation for LinkedIn-Themed Phishing Abuses Adobe Target (A/B Testing)
Immediate actions
- Block the exfiltration host a1263367.xsph.ru and the broader *.xsph.ru free-hosting space at the web proxy and DNS layer
- Quarantine inbound email carrying HTML attachments with double extensions (e.g. *.pdf.html, *.pdf.htm)
- Force password reset and session revocation for any user who opened the attachment or submitted credentials
- Threat-hunt proxy/EDR logs for outbound POSTs to /taam/Ln.php and for browser navigation to lnkd.tt.omtrdc.net/rest/v1/delivery originating from email-attachment opens
Workarounds
- Disable automatic browser rendering of email-borne HTML attachments
- Block or alert on subdomains of known free-hosting providers (xsph.ru, sprinthost.ru) at the perimeter
Longer-term hardening
- Enforce phishing-resistant MFA (FIDO2/WebAuthn) so harvested passwords alone cannot complete authentication
- Deploy email security that detonates/renders HTML attachments and inspects embedded Base64/URL-encoded JavaScript
- Add secure email gateway rules to strip or sandbox .html/.htm attachments from external senders
- Run targeted user-awareness training on HTML-attachment lures and double-extension masquerading
- Baseline and monitor endpoint traffic to omtrdc.net / adobedc.net so anomalous delivery-API calls from non-marketing hosts are flagged
Weaknesses (CWE) in LinkedIn-Themed Phishing Abuses Adobe Target (A/B Testing)
CWE-451, CWE-1021, CWE-656
Timeline of LinkedIn-Themed Phishing Abuses Adobe Target (A/B Testing)
- Exfiltration endpoint http://a1263367.xsph.ru/taam/Ln.php and abused Adobe Target hop lnkd.tt.omtrdc.net/rest/v1/delivery documented as primary network IOCs.
- Malwarebytes Labs publishes analysis of the active LinkedIn-themed phishing campaign abusing Adobe Target; Malwarebytes Scam Guard flags the campaign as malicious.
- As of 2026-05-29, this LinkedIn/Adobe-Target credential-phishing campaign remains a live concern: multiple vendors (Malwarebytes, Help Net, TechNADU) reported it active days ago with no takedown or Adobe-side block announced. The original exfil node (a1263367.xsph.ru) shows lame DNS likely burned, but the LOTS technique and rotating SprintHost free-hosting persist, warranting monitoring.
- Threat documented in Threadlinqs Intelligence as TL-2026-0630 with full MITRE mapping, IOCs, and remediation guidance.
- Infrastructure analysis confirms lnkd.tt.omtrdc.net CNAMEs to adobetarget.data.adobedc.net (Adobe-owned IP space 63.140.38.0/24, 63.140.39.0/24) and that xsph.ru is SprintHost (AS35278, RU) free hosting with prior malware/phishing abuse history.
- TechNADU reports on the fake LinkedIn collaboration emails and Adobe Target tracking abuse.
- Help Net Security corroborates the campaign, emphasizing the dual purpose of the Adobe Target redirect (trusted traffic appearance plus victim click/submit tracking).
Sources cited for LinkedIn-Themed Phishing Abuses Adobe Target (A/B Testing)
- Fake LinkedIn emails abuse Adobe to track victims
- LinkedIn-themed phishing abuses Adobe's A/B testing platform
- Fake LinkedIn Collaboration Emails Abuse Adobe Target to Track Victims in Phishing Campaign
- URLhaus — xsph.ru host abuse tracking (SprintHost free hosting)
- phish.report — Report phishing to SPRINTHOST, RU
- AbuseIPDB — SPRINTHOST.RU 141.8.193.236
Threats related to LinkedIn-Themed Phishing Abuses Adobe Target (A/B Testing)
- Kratos Phishing-as-a-Service Platform Targeting Microsoft 365 Users Across US and Europe
- German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFA
- Kratos Phishing-as-a-Service Platform Dismantled in Operation Olympus Blade — BKA/FBI/Indonesian Police Takedown of AiTM Microsoft 365 Credential Theft Kit
- Magecart Skimmer Abuses Stripe API + Google Tag Manager for Payload Hosting, C2 & Card Exfiltration
Detection coverage for TL-2026-0630
As of 2026-05-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0630 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.