Cointime

Download App
iOS & Android

Crypto users targeted in ‘elaborate’ scam using popular notes app

Crypto users have been warned of a new social engineering scam that tricks victims into using community plugins on the note-taking app Obsidian to unknowingly run malware that can take control of their devices.

Elastic Security Labs said in a report on Tuesday that it found a novel campaign targeting those in crypto and finance using “elaborate social engineering on LinkedIn and Telegram” to trick victims into allowing malicious, yet seemingly safe, software to run on their devices.

Attackers abuse the community plugin ecosystem on Obsidian to “silently execute code when a victim opens a shared cloud vault,” with attacks working on both Windows and macOS devices.

It's the latest known attack campaign targeting crypto users, a popular target for scammers, as blockchain transactions cannot be reversed. In 2025, $713 million was stolen via compromises of individual crypto wallets, according to Chainalysis.

Elastic said the scammers contact victims on LinkedIn under the guise of being a venture capital firm and eventually steer the conversation to Telegram in discussions around “financial services, specifically cryptocurrency liquidity solutions, creating a plausible business context.”

The attackers ask their target to use Obsidian, framing it as their fake company’s database for accessing a shared dashboard, and the potential victim is given a login to connect to a cloud-hosted vault controlled by the attackers.

“This vault is the initial access vector,” Elastic said. “Once opened in Obsidian, the target is instructed to enable community plugins sync. After that, the trojanized plugins silently execute the attack chain.”

  Source: Elastic Security Labs


The attacks differ slightly on Windows and macOS, but both deploy a previously undocumented remote access trojan, or RAT, which Elastic dubbed “PHANTOMPULSE.”

The malware, which is disguised as legitimate software, gives the attackers control over the victim's device, with Elastic adding it was “designed for stealth, resilience, and comprehensive remote access.”

Elastic said that PHANTOMPULSE uses a decentralized command-and-control mechanism via at least three different blockchain networks, using on-chain transaction data tied to a specific wallet to connect to the attacker and receive instructions.

“This technique provides the operator with an infrastructure-agnostic rotation capability,” Elastic said. “Because blockchain transactions are immutable and publicly accessible, the malware can always locate its C2 [command-and-control mechanism] without relying on centralized infrastructure.”

“The use of three independent chains adds redundancy: even if one chain's explorer is blocked or unavailable, the remaining two provide alternative resolution paths,” it added.

Elastic said it was able to block the attack, but it shows that attackers “continue to find creative initial access vectors” as abusing Obsidian's community-run plugin ecosystem allowed them to skirt “traditional security controls entirely, relying on the application's intended functionality to execute arbitrary code.”

It added that financial and crypto companies “should be aware that legitimate productivity tools can be turned into attack vectors,” and organizations should enforce app-level plugin policies to defend against similar attacks.

Comments

All Comments

Recommended for you

  • BTC Falls Below $61,000

    Market data shows that BTC has fallen below $61,000, currently priced at $60,996, with a 24-hour decline of 1.15%. The market is experiencing significant volatility, so please ensure proper risk management.

  • BTC Surpasses $61,000

    Market data shows that BTC has surpassed $61,000, currently priced at $61,005.65, with a 24-hour decline of 3.74%. The market is experiencing significant volatility, so please ensure proper risk management.

  • USDT Surpasses ETH to Become the Second Largest Cryptocurrency by Market Cap

    On June 6, market data showed that USDT's market capitalization surpassed that of ETH, making it the second largest cryptocurrency by market cap. As of now, USDT's market cap stands at $187.034 billion, while ETH's market cap is $184.423 billion.

  • BTC Falls Below $60,000

    Market data shows that BTC has fallen below $60,000, currently priced at $59,995.63, with a 24-hour decline of 4.36%. The market is experiencing significant volatility, so please ensure proper risk management.

  • US Spot Ethereum ETF Sees $6 Million Net Outflow

    On June 6, according to monitoring data from Farside Investors, the US spot Ethereum ETF experienced a net outflow of $6 million yesterday.

  • US Spot Bitcoin ETF Sees $325.7 Million Net Outflow

    On June 6, according to data monitored by Farside Investors, the US spot Bitcoin ETF experienced a net outflow of $325.7 million yesterday.

  • BTC Briefly Drops Below $60,000

    Market data shows that BTC briefly dropped below $60,000, currently recovering to $61,290.9, with a 24-hour decline of 3.5%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Yili Hua: US Stocks Correct as Expected, Decline Faster Than Anticipated

    On June 5, Liquid Capital (formerly LD Capital) founder Yili Hua stated, "As we anticipated, US stocks have begun to correct, and expectations for interest rate cuts have changed. Trading is always the most challenging task; getting it right ten times and wrong once can lead to problems. It is essential to remain cautious and manage risks. The speed of this decline following the rebound has far exceeded expectations. However, it also comes with greater opportunities; historically, bear markets have been the time to make money, while bull markets often lead to losses."

  • Fed's Harker: Maintaining Stable Rates is Reasonable for Now

    On June 5, Fed's Harker stated that it may soon be time to adjust interest rates. Given the uncertainty, maintaining stable rates is reasonable at this time.

  • President Trump: Recent Employment Report is Strong, Stock Market Should Rise, Not Fall

    On June 5, U.S. President Trump stated that the recently released employment report is very strong, and the stock market should rise, not fall. This has been the case for the past 200 years. Economic growth does not mean inflation!