Obsidian-based social engineering attack

Found this report via HackerNews. Attackers are getting victims to download Obsidian, enable community plugins, and use a shared “vault” to automatically download and execute scripts from a malicious plugin. End result is the phantompulse RAT on the system.

IOCs include Obsidian.exe spawning powershell.exe or cmd.exe on Windows or Obsidian spawning osascript on MacOS.

Details:

2 Likes

This smells like a poorly done AI-generated summary. Notice how three of the “references” at the bottom don’t even link to valid webpages. The STIX file download also has no actual IOCs in it. (The STIX file also describes this article as an “Original threat intelligence article”, which is just laughable.)

The only link reference that does work is this The Hacker News article, which links to the actual original report from Elastic: Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT — Elastic Security Labs. There are a lot more actual details there.

(Not frustrated at you, just frustrated at the fact that it’s harder and harder to find original threat intel reporting in a sea of AI slop.)

We actually have another topic about this, from Elastic Security Labs.

2 Likes

Sorry, I hadn’t gone through all the links before I posted this. I’ll keep a better eye out for junk like this in the future!

1 Like

Interesting, I saw the post but I didn’t put the two together because the other one mentions clickfix. Thanks for pointing it out.