logo

AI-Generated RAT “PHANTOMPULSE” Targets Crypto Sector via Social Engineering

ID: cbecd5ad-25ee-5e6a-91d3-513381713e3e

STIX ID: report--cbecd5ad-25ee-5e6a-91d3-513381713e3e

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Ddos

...
...

Elastic Security Labs uncovered REF6598, a targeted campaign that lures victims via LinkedIn/Telegram and weaponizes Obsidian community plugins (Shell Commands and Hider) to silently execute a custom in-memory loader (PHANTOMPULL) that deploys PHANTOMPULSE, an AI-assisted Windows RAT. PHANTOMPULSE uses Ethereum-family blockchains as a decentralized C2 dead drop but contains a parsing flaw enabling defenders to craft transactions to sinkhole infected hosts; recommended mitigations include parent-process-based detection and caution with untrusted plugins and shared vaults.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.