logo

Malware Delivered Through Trusted Webhooks In New n8n Abuse Campaign

ID: af7ca08c-c389-5ab1-b21a-5a0a17339216

STIX ID: report--af7ca08c-c389-5ab1-b21a-5a0a17339216

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-16

Author: Varshini

...
...

Cisco Talos observed threat actors weaponizing n8n cloud-hosted webhooks in phishing campaigns to mask malicious payload delivery and fingerprint targets: victims clicking CAPTCHA-protected n8n links received JavaScript-triggered executables or backdoored installers (modified RMM tools) that established persistent access and exfiltrated data; attackers also used invisible tracking pixels to capture IPs and email activity. The report highlights a large rise in malicious emails using n8n URLs and recommends behavior-based detections and monitoring of unexpected automation-platform communications rather than blanket domain blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.