logo

Hackers Abuse n8n AI Workflow Automation to Deliver Malware Through Trusted Webhooks

ID: 5fae3b7c-29c4-567f-b5fa-d3cdacff471d

STIX ID: report--5fae3b7c-29c4-567f-b5fa-d3cdacff471d

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Researchers observed a campaign (Oct 2025–Mar 2026) where threat actors created free n8n developer accounts and used n8n.app subdomains and URL-exposed webhooks to host phishing content and tracking pixels, enabling delivery of malicious payloads and silent device fingerprinting; delivered payloads included modified Datto and ITarian RMM installers that provided persistent remote access, data exfiltration, and command-and-control connectivity, exploiting the platform’s trusted reputation to bypass traditional security filters.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.