logo

New Phishing Attack Turns n8n Into On-Demand Malware Machine

ID: d5f2003f-ed74-5589-84f2-7161519eb903

STIX ID: report--d5f2003f-ed74-5589-84f2-7161519eb903

Feed Name: TechRepublic Security

Threat Score
72/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Joseph Ofonagoro

...
...

Cisco Talos research describes active campaigns abusing the n8n workflow automation platform (app.n8n.cloud) to send phishing emails and webhooks that dynamically fingerprint victims and deliver tailored malware (e.g., MSI installers and executables that establish C2 and exfiltrate data). Attackers leverage n8n’s trusted domains to improve deliverability and evade detection, use invisible tracking pixels to identify active targets, and vary payloads by reading request headers; Talos recommends behavior-based detection, IOC sharing, stronger email security, and user awareness to mitigate this threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.