A targeted social-engineering campaign tracked as REF6598 impersonated a venture-capital firm on LinkedIn and Telegram to target financial and cryptocurrency-sector personnel. Victims were persuaded to synchronize Obsidian community plugins, allowing the attackers to abuse the legitimate Shell Commands and Hider plugins—not an Obsidian vulnerability—to launch a cross-platform payload chain. Windows victims received the in-memory PHANTOMPULL loader and the previously undocumented PHANTOMPULSE remote-access trojan, while macOS victims received an obfuscated AppleScript dropper, LaunchAgent persistence, and a Telegram dead-drop fallback for command-and-control (C2) resolution.
PHANTOMPULSE uses direct syscalls, hardware-breakpoint evasion of AMSI, WLDP, and ETW, process injection, scheduled-task persistence, and a public UAC-bypass technique. It can collect system and wallet data, capture screenshots and keystrokes, execute or inject payloads, and manipulate privileges; its C2 resolver retrieves encoded transaction-input data from Ethereum, Base, and Optimism Blockscout services. The resolver does not authenticate transaction senders, allowing defenders or third parties to potentially sinkhole or hijack it. The activity’s crypto-focused victimology and tradecraft align with North Korea-linked operations that have also used fake developer recruitment projects to deploy macOS RustDoor and Koi Stealer malware for theft of browser, Keychain, SSH, VPN, messaging, and cryptocurrency-wallet data.

Pull IOCs and campaign context straight into your stack.
11 events from the most recent confirmed update back to the earliest known activity.
A subsequent self-transaction to the PHANTOMPULSE resolver wallet encoded https://panel.fefea22134.net as a C2 URL.
A self-transaction to the PHANTOMPULSE resolver wallet encoded the C2 URL thoroughly-publisher-troy-clara.trycloudflare.com in its transaction input.
The public dis0rder0x00/DbgNexum proof of concept, whose core was later incorporated into PHANTOMPULSE's executable-payload execution component, was published.
Elastic assessed that PHANTOMPULSE's crypto-wallet reconnaissance, blockchain dead-drop C2 design, infrastructure, targeting, and tradecraft aligned with DPRK-associated clusters including Lazarus, BlueNoroff, UNC5342/Contagious Interview, and APT38. The assessment was not presented as definitive attribution.
On macOS, the Obsidian plugin execution path ran an obfuscated AppleScript dropper that created the com.vfrfeufhtjpwgray LaunchAgent with KeepAlive and RunAtLoad enabled. The dropper checked hardcoded domains and used a Telegram channel as a fallback C2 dead drop, though the C2 servers were offline during analysis.
PHANTOMPULSE resolved C2 URLs from the latest transaction input to an Ethereum wallet using Blockscout services for Ethereum, Base, and Optimism. Because it accepted XOR-decoded values beginning with "http" without validating the transaction sender, a third party could submit a suitably encoded transaction to redirect implants to a sinkhole or another C2 server.
The Windows infection chain downloaded syncobs.exe, the PHANTOMPULL in-memory PE loader, which decrypted and reflectively loaded payloads and retrieved the PHANTOMPULSE RAT from panel.fefea22134.net. PHANTOMPULSE supported host reconnaissance, screenshots, keylogging, payload injection, file execution, privilege actions, and persistence management.
Elastic Defend detected suspicious PowerShell spawned by the signed Obsidian application and blocked the observed intrusion at an early stage, before PHANTOMPULSE executed or the operators achieved their objectives.
Actors posing as a venture-capital firm used LinkedIn and Telegram to lure targets into synchronizing an attacker-controlled Obsidian vault. The campaign abused the legitimate Shell Commands and Hider community plugins, rather than an Obsidian vulnerability, to initiate cross-platform payload delivery.
The observed payload chain attempted LastPass extension theft, archive exfiltration, and reverse-shell deployment, while Koi Stealer collected credentials, host reconnaissance, browser and wallet-related data, Keychain files, SSH configuration, messaging data, and other files for HTTP exfiltration.
Attackers posing as recruiters or prospective employers used malicious interview or development projects targeting job-seeking cryptocurrency-sector software developers. The activity delivered RustDoor and a previously undocumented macOS Koi Stealer variant, and Unit 42 assessed with moderate confidence that it was conducted for the North Korean regime.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 50 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourceelastic.co
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.