AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get the latest gadgets delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

A social engineering campaign has exploited the Obsidian note-taking app to deliver a new, sophisticated RAT called PHANTOMPULSE. Attackers use shared vaults and malicious plugins, with the malware using blockchain to hide C2 communication. The attack targets finance and crypto sectors on Windows and macOS.

Cybersecurity researchers have confirmed that a targeted social engineering campaign is exploiting the Obsidian note-taking application to deploy a previously undocumented remote access trojan named PHANTOMPULSE, primarily targeting professionals in finance and cryptocurrency sectors on Windows and macOS.

The attack involves threat actors posing as venture capitalists on platforms like LinkedIn and Telegram, engaging victims in conversations that lead to shared Obsidian vaults. The malicious campaign hinges on convincing users to enable community plugins within Obsidian, which then executes malicious scripts to deploy the RAT.

Once activated, PHANTOMPULSE can perform keylogging, screen capturing, file exfiltration, and remote command execution. It employs a novel command-and-control mechanism that queries the Ethereum blockchain for instructions, embedding the C2 address within blockchain transactions, making it highly resistant to takedown efforts.

Why It Matters

This development underscores a sophisticated evolution in malware delivery, exploiting legitimate productivity tools and blockchain technology to evade detection and disruption. The targeted nature and use of blockchain for C2 communications make this threat particularly challenging for defenders, especially in high-stakes financial and crypto environments.

Amazon

cybersecurity threat detection software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background

Obsidian is a popular note-taking app used by many professionals for secure documentation. Recent campaigns have increasingly targeted collaboration features and third-party plugins to deliver malware. The PHANTOMPULSE RAT is a new, advanced payload that demonstrates the growing sophistication of cyber threats leveraging legitimate tools and decentralized infrastructure.

“The use of blockchain for command-and-control makes PHANTOMPULSE highly resistant to traditional takedown techniques.”

— Cybersecurity researcher

“Users should exercise caution when enabling community plugins, especially from untrusted sources.”

— Obsidian security team

Amazon

malware analysis tools for Windows

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What Remains Unclear

It is not yet clear how widespread the campaign is or how many victims have been compromised. Details about the full scope of the malware’s capabilities and the specific infrastructure used for command-and-control are still emerging. Additionally, attribution to specific threat actors remains unconfirmed.

Amazon

blockchain network monitoring tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What’s Next

Cybersecurity teams are expected to enhance monitoring for Obsidian activity, especially regarding plugin installations and blockchain-related network traffic. Researchers will continue analyzing the malware’s infrastructure and develop detection signatures. Further disclosures may reveal the scope and impact of the campaign.

Amazon

secure note-taking app for professionals

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

How does the malware infect victims through Obsidian?

The infection occurs when users open a malicious shared vault and are tricked into enabling community plugins, which execute malicious scripts to deploy the RAT.

What makes PHANTOMPULSE difficult to detect?

It uses in-memory payloads, exploits legitimate plugin features, and employs blockchain-based C2 communication to evade traditional detection methods.

Who is most at risk from this attack?

Professionals in finance and cryptocurrency sectors who use Obsidian for sensitive data are primary targets due to the high value of their information.

What steps can users take to protect themselves?

Users should avoid enabling untrusted plugins, disable auto-sync for unknown vaults, and remain vigilant against social engineering tactics. Organizations should enforce application control and network monitoring for blockchain activity.

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

AI Trading Bot — Week Two: The candidate edge collapsed

The initial advantage of a new AI trading bot has vanished after two weeks, raising questions about its long-term viability and market impact.

Sam Altman says Elon Musk’s mind games were damaging OpenAI

OpenAI CEO Sam Altman testified that Elon Musk’s management style caused significant damage to the company’s culture during Musk’s lawsuit.

Clawdmeter turns your Claude Code usage stats into a tiny desktop dashboard

Clawdmeter is an open source hardware project that displays Claude Code usage stats via a tiny, customizable desktop dashboard, blending fun with productivity.

Idempotency is easy until the second request is different

Understanding why idempotency is straightforward until the second request differs, highlighting key issues for API reliability and design.