logo

Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT

ID: bcdf907c-a142-5e5e-960a-1b46f48ef890

STIX ID: report--bcdf907c-a142-5e5e-960a-1b46f48ef890

Feed Name: Elastic Security Labs

Threat Score
80/100

Date Published: 2026-04-14

Date Updated: 2026-04-27

...
...

**Executive Summary:** Elastic Security Labs documents REF6598, a targeted campaign that uses social engineering to trick finance and cryptocurrency professionals into enabling Obsidian community-plugin sync, causing trojanized Shell Commands and Hider plugins to execute a multi-stage cross-platform attack that delivers the PHANTOMPULL loader and the PHANTOMPULSE RAT (Windows) and an obfuscated AppleScript dropper (macOS); PHANTOMPULSE features in-memory reflective loading, advanced injection, and a blockchain-based C2 rotation mechanism, and the report includes indicators (hashes, IPs, domains, wallet) and detection/hunting guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.