Hackers Abuse n8n AI Workflow Automation to Deliver Malware Through Trusted Webhooks
ID: 5fae3b7c-29c4-567f-b5fa-d3cdacff471d
STIX ID: report--5fae3b7c-29c4-567f-b5fa-d3cdacff471d
Feed Name: cybersecurityNews.com
Researchers observed a campaign (Oct 2025–Mar 2026) where threat actors created free n8n developer accounts and used n8n.app subdomains and URL-exposed webhooks to host phishing content and tracking pixels, enabling delivery of malicious payloads and silent device fingerprinting; delivered payloads included modified Datto and ITarian RMM installers that provided persistent remote access, data exfiltration, and command-and-control connectivity, exploiting the platform’s trusted reputation to bypass traditional security filters.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
