n8n webhooks abused to send malware via phishing emails

Cisco Talos research found threat actors abusing n8n cloud-hosted webhooks (*.app.n8n.cloud) to send automated phishing emails that deliver malware and fingerprint devices. The abuse has been observed since October 2025 through March 2026, leveraging per-account trusted domains to bypass email filters and enable persistent remote access.

Part of the PlainSec briefing for 2026-04-15

Sources