Cisco Talos reported that threat actors are abusing the workflow automation platform n8n to run phishing campaigns, deliver malware, and fingerprint targets through trusted *.app.n8n.cloud webhook infrastructure. The activity has been observed since at least October 2025, and Talos said email volume containing these links in March 2026 was about 686% higher than in January 2025. In observed campaigns, emails posing as shared documents or Microsoft OneDrive messages directed recipients to n8n-hosted pages that used CAPTCHA prompts to make the activity appear legitimate before redirecting victims to external malware downloads.
The downloaded payloads included executables and MSI installers that deployed modified legitimate remote monitoring and management tools, including Datto RMM and ITarian Endpoint Management, to establish persistence, enable command execution, and support data exfiltration. Talos also found n8n webhook URLs embedded as invisible tracking pixels in emails, allowing attackers to confirm message opens and collect device information for victim profiling. The findings show how legitimate low-code and AI automation services can be repurposed as stealthy attack infrastructure that helps bypass conventional email and web filtering defenses.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
A Gurucul threat research notice detailed ongoing abuse of n8n and similar AI workflow automation platforms in phishing and malware campaigns, and released multiple malicious URLs, two SHA-256 hashes, and example detection queries. The publication gave defenders concrete indicators and hunting guidance tied to the activity.
Talos also observed n8n webhook URLs embedded as invisible tracking images in emails to confirm when messages were opened and collect recipient device information for fingerprinting.
In one observed campaign, phishing emails posing as shared documents or Microsoft OneDrive content led victims to an n8n-hosted CAPTCHA page that triggered downloads of malicious executables or MSI installers from an external host. The payloads deployed modified legitimate remote management tools including Datto RMM and ITarian Endpoint Management for persistence, command execution, and data exfiltration.
Cisco Talos reported that email volume containing n8n webhook URLs in March 2026 was about 686% higher than in January 2025, indicating a significant escalation in abuse of the platform's trusted infrastructure.
Cisco Talos said attackers have been abusing n8n-hosted webhook URLs on trusted *.app.n8n.cloud subdomains since at least October 2025 to support phishing, malware delivery, and device fingerprinting while blending into legitimate infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
blog.knowbe4.com
Open sourcetechrepublic.com
Open sourcesecurityaffairs.com
Open sourcecommunity.gurucul.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.