Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT in Targeted Finance, Crypto Attacks
Obsidian, a cross-platform note-taking program, has been abused by a "novel" social engineering campaign to disseminate PHANTOMPULSE, an undocumented Windows remote access trojan, in attacks directed at people in the financial and cryptocurrency industries.
The activity, dubbed REF6598 by Elastic Security Labs, has been discovered to use sophisticated social engineering techniques via LinkedIn and Telegram to compromise both Windows and macOS systems. It approaches potential clients on the professional social network while posing as a venture capital firm, then transfers the conversation to a Telegram group where a number of alleged partners are present.
The Telegram group conversation, where participants debate financial services and cryptocurrency liquidity options, is designed to...

