Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
financial-sector-threatcryptocurrency-platform-riskremote-access-implantphishing-campaign-intelligence

Obsidian Plugin Abuse Delivered PhantomPulse RAT to Finance and Crypto Targets

Updated 3h agoFirst seen Apr 13, 20263 sources

Attackers targeted individuals in the financial and cryptocurrency sectors by posing as a venture capital firm on LinkedIn and shifting conversations to Telegram, where they lured victims into opening an attacker-controlled Obsidian vault. The campaign, tracked as REF6598, did not rely on a software vulnerability; instead, it abused Obsidian’s community plugin synchronization to deliver trojanized Shell Commands and Hider plugins that executed attacker-defined code when enabled.

On Windows, the infection chain downloaded a PowerShell stage that deployed PHANTOMPULL, an in-memory loader used to decrypt and reflectively load the previously undocumented PHANTOMPULSE RAT. On macOS, victims received a multi-stage obfuscated AppleScript dropper that established LaunchAgent persistence and used Telegram as a fallback command-and-control channel. Researchers said PHANTOMPULSE supports process injection, keylogging, screenshots, telemetry collection, and privilege escalation, while resolving C2 through Ethereum transaction data; they also identified a flaw in that blockchain-based mechanism that could let defenders hijack infected implants by publishing a newer crafted transaction to the monitored wallet.

Share:
Obsidian Plugin Abuse Delivered PhantomPulse RAT to Finance and Crypto Targets
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Feb 19, 20264mo ago

Elastic detects and blocks the intrusion and publishes technical findings

Elastic Security Labs reported that Elastic Defend detected and blocked the observed attack early. The researchers publicly documented the REF6598 campaign, PHANTOMPULSE capabilities, related infrastructure, and a design flaw in the malware's blockchain-based C2 logic that could allow defenders to hijack infected implants.

Attackers deploy PHANTOMPULSE RAT through trojanized Obsidian plugins

In the observed intrusion chain, trojanized Shell Commands and Hider plugins executed malware on both Windows and macOS. On Windows, the chain used PowerShell and the PHANTOMPULL in-memory loader to deploy the previously undocumented PHANTOMPULSE RAT, while macOS infections used an obfuscated AppleScript dropper with LaunchAgent persistence and Telegram fallback C2.

REF6598 campaign targets finance and crypto professionals via Obsidian lures

Attackers conducted a targeted social-engineering campaign against individuals in the financial and cryptocurrency sectors, impersonating a venture capital firm on LinkedIn and Telegram. Victims were lured into opening an attacker-controlled cloud-hosted Obsidian vault and enabling community plugin sync to trigger malicious code execution.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

20 LINKEDOpen in app
Affected products
9 linked
ObsidianWindowsApplescriptPowershellMacosMacosTelegramLinkedinChrome
Organizations
9 linked
ObsidianElasticLinkedinCloudflareXTelegramLet's EncryptMEVSPACE sp. z o.o.Google
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.