AI platform n8n abused for stealthy phishing and malware delivery
ID: 32fd9844-2fb8-568d-97a0-a3442a5acaef
STIX ID: report--32fd9844-2fb8-568d-97a0-a3442a5acaef
Feed Name: Security Affairs
Cisco Talos and SecurityAffairs report that threat actors are abusing the n8n automation platform by hosting webhook links that serve phishing pages and malware. Victims receive emails mimicking OneDrive links which open CAPTCHA-protected pages on n8n-hosted domains; once solved they download malicious executables or MSI installers that deploy modified RMM tools (Datto, ITarian) as backdoors for persistence, command execution, and data exfiltration. Attackers also use invisible tracking images and webhook callbacks for device fingerprinting and to confirm email access, leveraging trusted infrastructure to evade traditional security controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
