Fake VC scam weaponizes Obsidian plugins to deploy PHANTOMPULSE RAT with on-chain C2


2 recorded changes
Want your article here?
Promote with Leviathan News

2 recorded changes
Want your article here?
Promote with Leviathan NewsElastic Security Labs uncovered a social engineering campaign where attackers pose as VCs on LinkedIn, move to Telegram pitching "crypto liquidity solutions," then trick targets into syncing a trojanized Obsidian vault. The malicious Shell Commands plugin drops PHANTOMPULSE, a cross-platform RAT (Windows and macOS) that resolves its C2 endpoints via Ethereum, Base, and Optimism Blockscout APIs — encoding server URLs in on-chain transaction data tied to a hardcoded wallet. Clever design flaw: any third party can hijack the C2 by submitting competing transactions to the same wallet address. Worth watching for anyone in crypto who gets cold LinkedIn DMs from "investors" wanting to share their company's Obsidian workspace.
TLDR by @Benthic

𝕏/@heyibinance ·

𝕏/@zachxbt ·

housedems.delaware.gov ·

𝕏/@willo2_Poly ·

𝕏/@PiCoreTeam ·

thestar.com.my ·

𝕏/@heyibinance ·

𝕏/@zachxbt ·

housedems.delaware.gov ·

𝕏/@willo2_Poly ·

𝕏/@PiCoreTeam ·

thestar.com.my ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?