Security agency: Hackers are using Obsidian to spread the PHANTOMPULSE Trojan
The security research organization Elastic Security Labs has disclosed a new social engineering attack targeting personnel in the finance and cryptocurrency industries. The attackers impersonate venture capital firms on LinkedIn and Telegram, tricking targets into opening an Obsidian note repository that contains a built-in malicious payload, thereby deploying a previously unrecorded Windows remote access Trojan called PHANTOMPULSE.
This attack does not exploit any software vulnerabilities but instead abuses the Shell Commands plugin of Obsidian to automatically execute malicious code when the note repository is opened. On the macOS side, it uses an obfuscated AppleScript launcher in conjunction with a Telegram channel as a backup command and control server, while on the Windows side, it leverages Ethereum transaction data to achieve blockchain-based C2 address resolution.
You may also like

The "PayPal Mafia" of the AI era, from an internship to a net worth of billions

The Most Crypto-Knowledgeable Fed Chair in History: What Cryptocurrencies Does Kevin Warsh Hold?

X Launches Cashtag, Musk's Super App Most Concrete Landing

Educational | How Can the Average Person Quickly Identify Token Rug Pull and Trading Strategy?

Rhythm X Zhihu Event Guest Announcement, featuring experts from academia, institutions, and individuals covering all aspects of the AI Agent's transformative financial model.

Is It a Dead Cat Bounce or the Bull Market Revival? How Do Traders View It?

Why Can Bitcoin Rise Against the Tide of Turmoil?

OpenAI and Anthropic, both pre-IPO, want to keep brawling

Entry is Revenue, Is YouTube Turning into a Neobank?

NEET Reaches New High, Another Cultural Phenomenon of AI Meme

CROO officially releases the CROO Agent Protocol (CAP), building a decentralized business infrastructure for AI agents

Who is swimming naked, and who is breaking the waves? Analysis Report on the Comprehensive Ranking of Hong Kong Licensed Virtual Asset Trading Platforms (VATP)

Deconstructing RAVE Dealer Control Techniques

70x in a Month: When $RAVE Put Istanbul’s Dancefloor on the Chain
A Web3 project with zero VCs and no whitepaper started with a midnight party for 200 people. Eighteen months later, its token $RAVE is up 70x, and its contract liquidations briefly eclipsed Ethereum’s. Is this just pure speculation, or are we looking at a new breed of cultural asset?

Bearish Traders Continue to Short Bitcoin | Rewire News Morning Update

Is Nasdaq About to Reach a New High, Is the Bull Market Back?

Goldman Sachs Applies for Bitcoin ETF, Wall Street's Final Bastion Falls

