Obsidian plugin was abused to deploy a remote access trojan
Researchers discovered a social engineering campaign targeting finance and crypto sectors using a malicious Obsidian vault. Victims are tricked into enabling community plugins, triggering the PHANTOMPULSE RAT. This malware features a sophisticated blockchain-based C2 mechanism for resilience, enabling full system control on Windows and macOS. Defensive measures include plugin restrictions and user training.
Summaries are AI-generated to help you scan faster. Open the original source for full context.