logo

n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails

ID: bbe76829-be4a-5bbc-8cf0-bb44ba35bea4

STIX ID: report--bbe76829-be4a-5bbc-8cf0-bb44ba35bea4

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-04-15

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cisco Talos researchers observed threat actors abusing n8n's cloud-hosted webhook URLs in phishing campaigns to host HTML/JavaScript that either triggers downloads of malicious executables/MSI (which install modified RMM tools to establish persistence and C2) or act as tracking pixels to fingerprint recipients; use of the trusted *.app.n8n.cloud domain allows these messages to bypass typical security filters and the volume of such emails rose sharply (≈686% from Jan 2025 to Mar 2026), illustrating active, widespread abuse of low-code automation infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.