If there is way for threat actors to abuse legitimate tools, of course they do it! No, it is not deja vu!

The headline equally applies to the abuse of LinkedIn Smart Links:

LinkedIn Smart Links abused in evasive email phishing attacks (bleepingcomputer.com)

This is a feature in the LinkedIn Sales Navigator and Enterprise versions and allows packages of documents to be sent out and the metrics for the documents can be tracked. Threat actors have been abusing the system to send out phishing communications, that can bypass regular email security, and because Smart Links will send them information on if and when the malicious documents are opened, they can track the effectiveness of their attacks!