Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks
ID: 8bff680a-b15f-5703-9b79-133761ae0201
STIX ID: report--8bff680a-b15f-5703-9b79-133761ae0201
Feed Name: The Hacker News
Elastic Security Labs observed a targeted social-engineering campaign leveraging LinkedIn and Telegram to lure financial and crypto professionals into opening a malicious Obsidian cloud vault that abuses the app's community plugin sync to execute a novel remote access trojan called PHANTOMPULSE. The backdoor—cross-platform with Windows and macOS execution paths—uses blockchain-based C2 resolution, supports injection, file drop, screenshots, keylogging and privilege escalation, but the documented intrusion was detected and blocked before the attackers achieved their objectives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
