Warning: A LinkedIn Phishing Campaign is Targeting Executives

KnowBe4 Team | Feb 3, 2026

Facebook Disrupts Social Engineering OperationA phishing campaign is abusing LinkedIn private messages to target executives and IT workers, according to researchers at ReliaQuest. The messages attempt to trick victims into opening an archive file, which will install a legitimate pentesting tool.

“A critical element of this attack was the use of a legitimate, open-source Python script designed for pen-testing,” ReliaQuest says. “Relying on publicly available tools means less effort for attackers and allows them to reduce costs and detection risks—all while lowering the technical barrier to entry.”

The researchers stress that the abuse of legitimate tools makes the campaign more likely to bypass security defenses.

“In this campaign, attackers used WinRAR and Python, but similar tactics could extend to other widely used tools, such as PowerShell,” the researchers write. “These tools are integral to daily operations, making it impractical for organizations to block them entirely. This highlights the ongoing challenge of distinguishing between legitimate activity and malicious behavior, leaving organizations vulnerable to similar attacks.

“What’s more, as organizations increasingly rely on social media platforms for business and marketing purposes, these channels create new attack surfaces. Employees managing corporate social media accounts or engaging on these platforms are exposed to phishing attempts in environments with minimal security controls.”

Employees need to maintain a healthy sense of suspicion across all online platforms in order to avoid falling for social engineering attacks.

“This campaign serves as a reminder that phishing isn’t confined to email inboxes,” the researchers write. “Phishing attacks take place over alternative channels like social media, search engines, and messaging apps—platforms that many organizations still overlook in their security strategies. Social media platforms, especially those frequently accessed on corporate devices, provide attackers with direct access to high-value targets like executives and IT administrators, making them invaluable to cybercriminals.”

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 HRM+ platform to strengthen their security culture and reduce human risk.

ReliaQuest has the story.


Free Phishing Security Test

Would your users fall for convincing phishing attacks? Take the first step now and find out before bad actors do. Plus, see how you stack up against your peers with phishing Industry Benchmarks. The Phish-prone percentage is usually higher than you expect and is great ammo to get budget.

PST ResultsHere's how it works:

  • Immediately start your test for up to 100 users (no need to talk to anyone)
  • Select from 20+ languages and customize the phishing test template based on your environment
  • Choose the landing page your users see after they click
  • Show users which red flags they missed, or a 404 page
  • Get a PDF emailed to you in 24 hours with your Phish-prone % and charts to share with management
  • See how your organization compares to others in your industry

Go Phishing Now!



Subscribe to Our Blog


Gartner Magic Quadrant




Get the latest insights, trends and security news. Subscribe to CyberheistNews.