Obsidian Plugin Ecosystem Enables Stealthy Cross-Platform RAT Attacks

Obsidian's community plugins and shared cloud vaults are being exploited to deliver a novel remote access trojan (RAT) called PhantomPulse, bypassing traditional software vulnerability requirements for initial access. This attack breaks the assumption that sharing vaults and using plugins in Obsidian is safe, exposing financial and cryptocurrency professionals to silent, targeted intrusions without obvious signs. Elastic Security Labs uncovered the REF6598 campaign abusing Obsidian's Shell Commands and Hider plugins to execute malicious code when victims open shared vaults. The attack uses elaborate social engineering on LinkedIn and Telegram to target individuals in financial sectors. PhantomPulse is an AI-assisted backdoor with blockchain-based command and control, advanced process injection, and cross-platform execution on Windows and macOS. This campaign reveals that trusted collaboration tools and their plugin ecosystems can be weaponized for stealthy initial access. The risk will persist as long as vault sharing and plugin use remain common, requiring defenders to rethink trust boundaries in cloud-shared environments and plugin management.

Part of the PlainSec briefing for 2026-04-13

Sources