n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails
ID: bbe76829-be4a-5bbc-8cf0-bb44ba35bea4
STIX ID: report--bbe76829-be4a-5bbc-8cf0-bb44ba35bea4
Feed Name: The Hacker News
Cisco Talos researchers observed threat actors abusing n8n's cloud-hosted webhook URLs in phishing campaigns to host HTML/JavaScript that either triggers downloads of malicious executables/MSI (which install modified RMM tools to establish persistence and C2) or act as tracking pixels to fingerprint recipients; use of the trusted *.app.n8n.cloud domain allows these messages to bypass typical security filters and the volume of such emails rose sharply (≈686% from Jan 2025 to Mar 2026), illustrating active, widespread abuse of low-code automation infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
