Cointime

Download App
iOS & Android

Crypto users targeted in ‘elaborate’ scam using popular notes app

Crypto users have been warned of a new social engineering scam that tricks victims into using community plugins on the note-taking app Obsidian to unknowingly run malware that can take control of their devices.

Elastic Security Labs said in a report on Tuesday that it found a novel campaign targeting those in crypto and finance using “elaborate social engineering on LinkedIn and Telegram” to trick victims into allowing malicious, yet seemingly safe, software to run on their devices.

Attackers abuse the community plugin ecosystem on Obsidian to “silently execute code when a victim opens a shared cloud vault,” with attacks working on both Windows and macOS devices.

It's the latest known attack campaign targeting crypto users, a popular target for scammers, as blockchain transactions cannot be reversed. In 2025, $713 million was stolen via compromises of individual crypto wallets, according to Chainalysis.

Elastic said the scammers contact victims on LinkedIn under the guise of being a venture capital firm and eventually steer the conversation to Telegram in discussions around “financial services, specifically cryptocurrency liquidity solutions, creating a plausible business context.”

The attackers ask their target to use Obsidian, framing it as their fake company’s database for accessing a shared dashboard, and the potential victim is given a login to connect to a cloud-hosted vault controlled by the attackers.

“This vault is the initial access vector,” Elastic said. “Once opened in Obsidian, the target is instructed to enable community plugins sync. After that, the trojanized plugins silently execute the attack chain.”

  Source: Elastic Security Labs


The attacks differ slightly on Windows and macOS, but both deploy a previously undocumented remote access trojan, or RAT, which Elastic dubbed “PHANTOMPULSE.”

The malware, which is disguised as legitimate software, gives the attackers control over the victim's device, with Elastic adding it was “designed for stealth, resilience, and comprehensive remote access.”

Elastic said that PHANTOMPULSE uses a decentralized command-and-control mechanism via at least three different blockchain networks, using on-chain transaction data tied to a specific wallet to connect to the attacker and receive instructions.

“This technique provides the operator with an infrastructure-agnostic rotation capability,” Elastic said. “Because blockchain transactions are immutable and publicly accessible, the malware can always locate its C2 [command-and-control mechanism] without relying on centralized infrastructure.”

“The use of three independent chains adds redundancy: even if one chain's explorer is blocked or unavailable, the remaining two provide alternative resolution paths,” it added.

Elastic said it was able to block the attack, but it shows that attackers “continue to find creative initial access vectors” as abusing Obsidian's community-run plugin ecosystem allowed them to skirt “traditional security controls entirely, relying on the application's intended functionality to execute arbitrary code.”

It added that financial and crypto companies “should be aware that legitimate productivity tools can be turned into attack vectors,” and organizations should enforce app-level plugin policies to defend against similar attacks.

Comments

All Comments

Recommended for you

  • Trump Again Threatens to Attack Iranian Civilian Infrastructure

    On April 15, U.S. President Trump stated in an interview aired on the same day that he believes the war with Iran is 'coming to an end,' but also warned that it could last until the midterm elections in November. Trump reiterated his threat to attack Iranian civilian infrastructure, while expressing hope that 'it won't escalate to that point.' (CCTV)

  • Iranian Foreign Ministry Spokesman: The Degree and Type of Nuclear Enrichment Can Be Negotiated

    On April 15, the Iranian Foreign Ministry spokesman stated that the degree and type of nuclear enrichment can be negotiated. (Jinshi)

  • Trump: Rates May Decrease After Walsh Takes Office

    On April 15, President Trump stated that Federal Reserve Chairman Powell would be fired if he did not resign on time. He does not intend to abandon the investigation into Chairman Powell. (Regarding the Federal Reserve) Rates may decrease after Walsh takes office.

  • Iran Claims Southern Shipping Activities Are Operating Normally Without Disruption

    On April 15, according to local news from Iran, information from the southern shipping and port industry indicates that despite U.S. claims of a maritime blockade on Iranian ports, Iran's maritime transport continues to operate normally and without interruption. In the past 24 hours, Iranian merchant ships have sailed to various destinations around the world as planned, and import and export operations have been smoothly conducted through Iranian ports. The U.S. Central Command stated on the 14th that the blockade of Iranian ports has been fully implemented, claiming that 'the U.S. military has completely cut off Iran's maritime import and export economic trade.' Additionally, shipping data shows that several vessels passed through the Strait of Hormuz on the 14th.

  • US Media: US and Iran 'Principally Agree' to Extend Ceasefire

    On April 15, according to the Associated Press: Mediators have made progress in extending the ceasefire agreement between the United States and Iran and restarting negotiations. Regional officials stated on Wednesday that the US and Iran have reached a 'principled agreement' to create conditions for further diplomatic mediation.

  • Iranian Military Responds to US Maritime Blockade

    On April 15, a spokesperson for the Central Headquarters of the Iranian Armed Forces, Khatam al-Anbiya, stated that if the United States continues to enforce a maritime blockade that endangers Iranian merchant ships and oil tankers, the Iranian armed forces will not allow any import or export activities to continue in the Persian Gulf, Gulf of Oman, and the Red Sea. (Xinhua News Agency)

  • S&P 500 and Nasdaq 100 Futures Decline Deepens

    Market data shows that the futures for the S&P 500 Index and Nasdaq 100 Index have widened their declines, reaching intraday lows.

  • Trump: 'Final Outcome' of Iran Conflict May Be Achieved Soon

    On April 15, U.S. President Trump stated in an interview broadcast by American media that the 'final outcome' of the Iran conflict may be achieved soon. In an interview with Fox Business Network, Trump said, 'I think we are doing very well, but what matters is the final outcome, and it may be achieved very soon.' He also mentioned that if Iran intends to possess nuclear weapons, the U.S. will not reach an agreement with them. (Xinhua News Agency)

  • SocGen brings MiCA-compliant USDCV dollar stablecoin to MetaMask

    Societe Generale-FORGE said MetaMask will add its MiCA-compliant USDCV stablecoin, extending distribution for one of Europe’s bank-backed digital dollars.

  • Crypto, banks continue Senate bill spat with new proposal concerns: Report

    US Senator Thom Tillis will publicly share an agreement to end a crypto and banking clash over stablecoin yields, but both sides are resisting the proposal, Politico reports.