Security agency: Hackers are using Obsidian to spread the PHANTOMPULSE Trojan

By: rootdata|2026/04/15 15:42:02
0
Share
copy

The security research organization Elastic Security Labs has disclosed a new social engineering attack targeting personnel in the finance and cryptocurrency industries. The attackers impersonate venture capital firms on LinkedIn and Telegram, tricking targets into opening an Obsidian note repository that contains a built-in malicious payload, thereby deploying a previously unrecorded Windows remote access Trojan called PHANTOMPULSE.

This attack does not exploit any software vulnerabilities but instead abuses the Shell Commands plugin of Obsidian to automatically execute malicious code when the note repository is opened. On the macOS side, it uses an obfuscated AppleScript launcher in conjunction with a Telegram channel as a backup command and control server, while on the Windows side, it leverages Ethereum transaction data to achieve blockchain-based C2 address resolution.

-- Price

--

You may also like

CROO officially releases the CROO Agent Protocol (CAP), building a decentralized business infrastructure for AI agents

CROO officially launched the CROO Agent Protocol (CAP) in the Base ecosystem today, providing AI agents with four core capabilities: identity, collaboration, settlement, and reputation, enabling autonomous intelligent agents to achieve commercial monetization and assetization.

Who is swimming naked, and who is breaking the waves? Analysis Report on the Comprehensive Ranking of Hong Kong Licensed Virtual Asset Trading Platforms (VATP)

The latest power ranking of 12 licensed crypto platforms in Hong Kong is out: HashKey and OSL firmly hold the top two positions, while the rising star EX.IO makes a strong comeback with RWA innovation, becoming the strongest dark horse. Click to reveal who is swimming naked and who is riding the wav...

Deconstructing RAVE Dealer Control Techniques

RAVE Extreme Control Warning: 96% of the chips are locked by whales, with contract positions exceeding spot, creating an epic short squeeze deadlock. Please be highly vigilant of the risk of OKX chain liquidations and the possibility of the manipulators closing in and crashing the market at any time...

70x in a Month: When $RAVE Put Istanbul’s Dancefloor on the Chain

A Web3 project with zero VCs and no whitepaper started with a midnight party for 200 people. Eighteen months later, its token $RAVE is up 70x, and its contract liquidations briefly eclipsed Ethereum’s. Is this just pure speculation, or are we looking at a new breed of cultural asset?

Bearish Traders Continue to Short Bitcoin | Rewire News Morning Update

Binance Perpetual Contract Funding Rate has been negative for 46 consecutive days, with open interest rising accordingly

Is Nasdaq About to Reach a New High, Is the Bull Market Back?

Almost all assets are up

Popular coins

Latest Crypto News

Read more