
Google examines ransomware scheme that uses fake LinkedIn profiles
Source: Daniel Rubino / Windows Central
Microsoft’s security teams routinely report on bad happenings going on in the cybercriminal world, including when such happenings affect the competition. But this time around, it’s Google highlighting how Microsoft’s services and products are being used by bad guys for bad purposes.
Google released a report exposing the operations of a group nicknamed “Exotic Lily,” an Initial Access Broker (IAB). IABs infiltrate networks then auction that access to whichever cybercriminal will pay the most.
Exotic Lily’s methods for infiltration are a bit more personal and crafty than those of the usual threat actor, according to Google. Here’s the play: The group creates fake social media profiles, including LinkedIn profiles, utilizing easily obtainable data on employees so that the illegitimate duplicates appear authentic. They also utilize spoofed email accounts and then begin engaging with targets, establishing rapport.
In short, Exotic Lily has used a wide range of Microsoft services and products for maleficent purposes, and threats like fake LinkedIn profiles remain a danger. With that being said, Microsoft addressed the aforementioned MSHTML zero-day and Google has guidance in its report for what to look out for, as well as more details on the technical aspects of Exotic Lily’s operations should you want to dig deeper.
We may earn a commission for purchases using our links. Learn more.

Review: Shredders on Xbox is a love letter to snowboarding
Shredders is an Xbox console exclusive launching day and date into Xbox Game Pass, and lets players live out their greatest fantasies of being a professional snowboarder. Despite some performance issues, Shredders largely succeeds at enabling epic fun in the snow.

Microsoft has hit its stride with Surface Duo 2 after recent updates
When Microsoft launched Surface Duo 2 back in October 2021, it was met with very negative reviews. But it wasn’t the hardware that was the problem but the software, which was still buggy with plenty of touch issues. After three significant updates, Zac and Dan discuss whether Microsoft has done enough to make Surface Duo 2 stable enough to recommend.