Hackers Exploit Obsidian Plugin to Deploy Cross-Platform Malware
ID: b88e17be-5d55-5199-8648-8b3b95303cf5
STIX ID: report--b88e17be-5d55-5199-8648-8b3b95303cf5
Feed Name: GBHackers
Elastic Security Labs observed a targeted social‑engineering campaign where attackers posing as a venture capital firm used LinkedIn and Telegram group chats to convince financial and cryptocurrency professionals to open an attacker‑controlled Obsidian cloud vault. When victims enabled Obsidian's community plugin sync, a malicious Shell Commands configuration and cosmetic plugin were synced and triggered platform‑specific loaders: a Base64 PowerShell chain on Windows that fetched a memory‑only loader (PHANTOMPULL) and ultimately the PHANTOMPULSE RAT, and an obfuscated osascript‑based dropper on macOS with LaunchAgent persistence and Telegram/on‑chain C2 discovery. The report includes technical indicators (IPs, domains, loader names), analysis of evasive techniques (memory‑only loaders, on‑chain C2 resolution), and defensive recommendations to monitor Obsidian child processes and enforce strict plugin policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
