Crypto users targeted by scam via popular notes app
Summarize this article with:

Cybercriminals do not lack imagination. This time, they turned a simple note-taking app into a silent weapon to empty their targets' crypto wallets. And the worst? The victim doesn't see anything coming.

Terrified crypto user sees his smartphone release mechanical tentacles while dark hacker manipulates orange glowing digital trap

In brief

  • Scammers are using the Obsidian app to deploy malware via booby-trapped community plugins.
  • Victims are recruited on LinkedIn and Telegram, under the cover of a fake venture capital company.
  • A new Trojan horse, called PHANTOMPULSE, takes full control of the infected device.

Notes app hijacked to trap crypto investors

Elastic Security Labs sounded the alarm this Tuesday in a detailed report. Malicious actors are actively targeting crypto and financial professionals via a sophisticated social engineering campaign. They operate mainly on LinkedIn and Telegram, using community plugins from Obsidian, a note-taking application very popular in tech and financial circles.

Start your crypto adventure with Kraken
This link uses an affiliate program

The scenario is well established. The attacker contacts his target on LinkedIn presenting himself as a representative of a fictitious venture capital company. The conversation then migrates to Telegram, where he discusses credible topics: crypto liquidity, financial services, treasury solutions. The objective is simple, to build trust before taking action.

Then comes the trap: the victim receives credentials to access a “shared dashboard” hosted in an Obsidian cloud vault, presented as the fake company’s internal database. Once the vault is opened, Obsidian prompts the user to enable community plugin syncing. At this point, the infected plugins run silently.

The result? A Trojan horse called PHANTOMPULSE installs discreetly, compatible with Windows and macOS. It provides attackers with full remote access to the device. Designed for stealth and resilience, it evades traditional antivirus software by disguising itself as legitimate software.

Malware that uses blockchain to disappear into the crowd

What sets PHANTOMPULSE apart from its predecessors is its control infrastructure. Rather than relying on centralized, easily identifiable and blockable servers, it communicates via three independent blockchains. Instructions pass through on-chain transactions linked to a specific wallet.

Result: even if a block explorer is inaccessible, the other two networks take over. And since blockchain transactions are public and immutable, the malware always finds its order server, without ever depending on a centralized infrastructure. A virtually indestructible design.

This attack does not take place in a vacuum: it is part of a broader wave of sophisticated fraud targeting the crypto ecosystem. At the beginning of April, a fake Ledger Live application infiltrated into the Apple App Store allowed the embezzlement of nearly $9.5 million in less than a week, affecting more than fifty victims on Bitcoin, Ethereum, Solana and other major networks.

Elastic highlights a clear warning to businesses: everyday productivity tools can become attack vectors. The recommendation is formal, apply strict plugin management policies at the application level.

Finally, we must remember a fundamental reality: crypto transactions are irreversible. Once the funds are gone, no recourse is possible. In this context, the best defense remains systematic distrust: never activate unknown plugins, verify the identity of your professional contacts, and treat any request for access to a shared tool as a potential intrusion attempt.

Maximize your Tremplin.io experience with our 'Read to Earn' program! For every article you read, earn points and access exclusive rewards. Sign up now and start earning benefits.

Similar Posts