Cointime

Download App
iOS & Android

Crypto users targeted in ‘elaborate’ scam using popular notes app

Crypto users have been warned of a new social engineering scam that tricks victims into using community plugins on the note-taking app Obsidian to unknowingly run malware that can take control of their devices.

Elastic Security Labs said in a report on Tuesday that it found a novel campaign targeting those in crypto and finance using “elaborate social engineering on LinkedIn and Telegram” to trick victims into allowing malicious, yet seemingly safe, software to run on their devices.

Attackers abuse the community plugin ecosystem on Obsidian to “silently execute code when a victim opens a shared cloud vault,” with attacks working on both Windows and macOS devices.

It's the latest known attack campaign targeting crypto users, a popular target for scammers, as blockchain transactions cannot be reversed. In 2025, $713 million was stolen via compromises of individual crypto wallets, according to Chainalysis.

Elastic said the scammers contact victims on LinkedIn under the guise of being a venture capital firm and eventually steer the conversation to Telegram in discussions around “financial services, specifically cryptocurrency liquidity solutions, creating a plausible business context.”

The attackers ask their target to use Obsidian, framing it as their fake company’s database for accessing a shared dashboard, and the potential victim is given a login to connect to a cloud-hosted vault controlled by the attackers.

“This vault is the initial access vector,” Elastic said. “Once opened in Obsidian, the target is instructed to enable community plugins sync. After that, the trojanized plugins silently execute the attack chain.”

  Source: Elastic Security Labs


The attacks differ slightly on Windows and macOS, but both deploy a previously undocumented remote access trojan, or RAT, which Elastic dubbed “PHANTOMPULSE.”

The malware, which is disguised as legitimate software, gives the attackers control over the victim's device, with Elastic adding it was “designed for stealth, resilience, and comprehensive remote access.”

Elastic said that PHANTOMPULSE uses a decentralized command-and-control mechanism via at least three different blockchain networks, using on-chain transaction data tied to a specific wallet to connect to the attacker and receive instructions.

“This technique provides the operator with an infrastructure-agnostic rotation capability,” Elastic said. “Because blockchain transactions are immutable and publicly accessible, the malware can always locate its C2 [command-and-control mechanism] without relying on centralized infrastructure.”

“The use of three independent chains adds redundancy: even if one chain's explorer is blocked or unavailable, the remaining two provide alternative resolution paths,” it added.

Elastic said it was able to block the attack, but it shows that attackers “continue to find creative initial access vectors” as abusing Obsidian's community-run plugin ecosystem allowed them to skirt “traditional security controls entirely, relying on the application's intended functionality to execute arbitrary code.”

It added that financial and crypto companies “should be aware that legitimate productivity tools can be turned into attack vectors,” and organizations should enforce app-level plugin policies to defend against similar attacks.

Comments

All Comments

Recommended for you

  • DeepSeek Seeks Over $300 Million in First Round of External Funding

    According to The Information, DeepSeek is seeking over $300 million in its first round of external funding, with a valuation exceeding $10 billion.

  • BTC Surpasses $78,000

    Market data shows that BTC has surpassed $78,000, currently priced at $78,024.64, with a 24-hour increase of 5.63%. The market is highly volatile, so please ensure proper risk management.

  • BTC Surpasses $77,000

    Market data shows that BTC has surpassed $77,000, currently priced at $77,022.24, with a 24-hour increase of 3.42%. Due to significant market fluctuations, please ensure proper risk management.

  • US and Iran Discuss Plan to End War

    On April 17, U.S. media reported, citing two American officials and two sources familiar with the negotiations, that the United States and Iran are communicating about a plan aimed at ending the war. One key topic is the U.S. potentially unfreezing $20 billion of Iran's frozen assets in exchange for Iran giving up its enriched uranium stockpile. The report also quoted another source familiar with the mediation efforts, stating that negotiations are expected to take place this Sunday in Islamabad, the capital of Pakistan. (Xinhua News Agency)

  • ETH Surpasses $2400

    Market data shows that ETH has surpassed $2400, currently priced at $2402.37, with a 24-hour increase of 2.58%. The market is experiencing significant volatility, so please ensure proper risk management.

  • US Plans to Unfreeze $20 Billion in Funds for Iran's Uranium Cessation

    On April 17, according to AXIOS, two US officials and two sources familiar with the negotiations revealed that the US and Iran are negotiating a three-page plan to end the conflict, one element of which involves the US unfreezing $20 billion of Iranian funds in exchange for Iran abandoning its enriched uranium stockpile. According to the two sources, in the early stages of negotiations, the US proposed unfreezing $6 billion for humanitarian supplies, while Iran requested $27 billion. The latest figures being discussed between the US and Iran are $20 billion. One US official stated that this is the US proposal. Another US official described the concept of 'cash for uranium' as 'one of many discussions.' Meanwhile, the US is demanding that Iran agree to send all its nuclear materials to the US, while Iran has only agreed to 'dilution' within its territory. Under the compromise being discussed, some highly enriched uranium would be sent to a third country (not necessarily the US), while some would be diluted under international supervision within Iran.

  • Iranian Foreign Minister Amir-Abdollahian: Commercial Shipping in the Strait of Hormuz is Open

    On April 17, Iranian Foreign Minister Amir-Abdollahian announced that commercial shipping in the Strait of Hormuz is now open.

  • Payward Agrees to Acquire Crypto Derivatives Firm Bitnomial for $550 Million

    Kraken's parent company Payward has announced that it has agreed to acquire the stock and crypto derivatives trading company Bitnomial for $550 million. This is a cash and stock transaction that enables Payward to gain control of a fully licensed U.S. cryptocurrency derivatives stack, accelerating its expansion in regulated markets.

  • Senator Pressures U.S. DOJ and Treasury on Binance-Iran Fund Flow Issues

    On April 17, U.S. Senator Richard Blumenthal (Democrat, Connecticut) sent a letter to the Department of Justice (DOJ) and the Financial Crimes Enforcement Network (FinCEN) requesting clarification on the status of two compliance supervisors at Binance. Reports had previously indicated that internal investigators at Binance warned executives about over $1 billion in funds flowing to wallets related to Iran, but were subsequently fired. Binance denies that the dismissals were related to the investigation's findings and claims that its compliance system is stringent. Notably, the DOJ had previously terminated independent oversight requirements for Glencore and Boeing, raising concerns about whether similar oversight mechanisms have also been suspended for Binance. In 2023, Binance was fined $4.3 billion for failures in anti-money laundering and sanctions compliance, and the two supervisors were part of the agreement at that time.

  • Goldman Sachs: Without Monetary Policy Support, US Stock Gains May Be Unsustainable

    On April 17, Goldman Sachs' head of asset allocation research, Muller-Grissman, stated that the recent rise in US stocks requires the Federal Reserve to restart interest rate cuts to maintain momentum. He described the recent stock market rebound as a 'rapid and intense recovery phase,' partly driven by technical factors, including hedge funds that previously sold stocks to reduce risk now being forced to rebuild their positions. Although the S&P 500 is expected to rise over 3% for three consecutive weeks, he questioned whether the gains could be sustained without monetary policy support. He noted that while the stock market is rising, oil prices remain high and the credit market is lagging. The strong performance of the stock market is partly due to high exposure to technology stocks.