{"id":420898,"date":"2026-10-01T16:10:49","date_gmt":"2026-10-01T16:10:49","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=420898"},"modified":"2026-10-01T16:10:49","modified_gmt":"2026-10-01T16:10:49","slug":"fake-investors-obsidian-vault-remote-access-malware","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/fake-investors-obsidian-vault-remote-access-malware\/","title":{"rendered":"Fake Investors Use Shared Obsidian Vaults to Install Remote Access Malware"},"content":{"rendered":"<p>A finance contact wants to share research before a call. The files are in an Obsidian vault, and a small setup change seems necessary to view them.<\/p><div id=\"mwtad875378622\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>That request can sound like ordinary collaboration. The part worth slowing down for is what the shared workspace asks your computer to trust.<\/p>\n<figure class=\"wp-block-image size-full\"><img fetchpriority=\"high\" decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-420899 lazyload\" alt=\"Illustrative fictional professional-network message inviting a finance professional into a shared Obsidian vault\" width=\"1536\" height=\"1024\" loading=\"eager\" title=\"\" sizes=\"(max-width: 1536px) 100vw, 1536px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/obsidian-recruiter-hero.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/obsidian-recruiter-hero.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/obsidian-recruiter-hero-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/obsidian-recruiter-hero-1024x683.png 1024w\"><\/figure>\n<div id=\"mwtad1608839653\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The business conversation sets up the technical request<\/h3>\n<p>Fake investors used professional-network contact and a group conversation to make a shared research workspace appear useful during a financial discussion.<\/p><div id=\"mwtad151900531\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p><a href=\"https:\/\/www.elastic.co\/security-labs\/threat-command\/phantom-in-the-vault\" target=\"_blank\" rel=\"noopener\">Elastic Security Labs documented<\/a> one intrusion attempt aimed at people in financial and cryptocurrency sectors. The approach began on LinkedIn and moved to Telegram.<\/p>\n<p>The supposed venture-capital contacts discussed cryptocurrency liquidity. They offered access to an Obsidian vault described as a management database or shared dashboard.<\/p>\n<p>Those details gave the victim a reason to open unfamiliar material. The malicious step was not reading a note. It was enabling community-plugin synchronization for the supplied vault.<\/p><div id=\"mwtad900227369\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>The real Obsidian application was abused, not replaced<\/h3>\n<p>Obsidian is a legitimate notes application. Elastic checked the signed application and found that the suspicious behavior originated from plugin configuration, not a counterfeit installer.<\/p>\n<p>The attacker-controlled vault contained community-plugin settings. One plugin could run shell commands on configured events, including when the vault opened.<\/p>\n<p>Elastic found that plugin synchronization is disabled by default. An attacker could not silently turn it on through the shared vault alone.<\/p><div id=\"mwtad2238335148\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The victim had to cross that boundary by enabling the relevant sync options. That human decision is the scam&#8217;s turning point.<\/p>\n<h3>A security product stopped the observed intrusion early<\/h3>\n<p>Elastic observed suspicious PowerShell execution from Obsidian and blocked the attack before the Windows remote-access payload achieved the attacker&#8217;s objectives.<\/p>\n<div id=\"mwtad126804297\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Researchers analyzed a multi-stage Windows chain ending in a backdoor named PHANTOMPULSE. They also found a separate macOS path using AppleScript.<\/p>\n<p>That is evidence of a real malicious campaign, not proof that every person receiving a shared vault was infected.<\/p>\n<p>The key checks are concrete:<\/p>\n<ul>\n<li>A stranger supplies account credentials to a shared vault for a proposed deal.<\/li>\n<li>The conversation moves from a professional network into a private group chat.<\/li>\n<li>Access supposedly depends on enabling community plugins or plugin sync.<\/li>\n<li>The vault contains plugins you did not choose or inspect.<\/li>\n<li>The contact discourages independent verification of the firm or project.<\/li>\n<li>A notes app unexpectedly launches a shell, installer, or security warning.<\/li>\n<\/ul>\n<div id=\"mwtad2033752903\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why This Approach Works on Careful Professionals<\/h2>\n<div id=\"mwtad2404372735\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>Many finance teams exchange research before a meeting. A private workspace can seem more credible than a random attachment, especially when several supposed colleagues join the conversation.<\/p>\n<p>A stranger who knows your role, company, and subject matter may sound informed. Those details can come from public profiles and do not establish authority.<\/p>\n<p>Moving to a group chat creates social proof. Two or three accounts agreeing on next steps can look like a real investment team.<\/p>\n<div id=\"mwtad326565487\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The vault itself presents ordinary notes and project language. That visible content can keep attention away from configuration files and plugin behavior.<\/p>\n<p>Obsidian&#8217;s legitimate plugin ecosystem is useful because plugins extend the app. It also means enabling an unknown plugin can permit actions beyond displaying text.<\/p>\n<p>Most users know to be cautious about executable files. Far fewer think of a synced plugin configuration as code they are allowing onto their machine.<\/p>\n<p>Elastic&#8217;s investigation matters because it separates those pieces. The app was real, the shared content was attacker-controlled, and the requested configuration change enabled execution.<\/p>\n<p>The scam does not require a universal Obsidian flaw. It relies on persuasion to get a target to change a default protection for a stranger&#8217;s workspace.<\/p>\n<div id=\"mwtad2391978876\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the Shared Obsidian Vault Scam Works<\/h2>\n<h3>Step 1: A professional contact opens a plausible conversation<\/h3>\n<p>An account presents itself as a venture investor or other finance contact. The outreach refers to a real field of work and offers a discussion rather than demanding money.<\/p>\n<p>That softer opening reduces suspicion. A person exploring a legitimate opportunity may reasonably expect research materials before the first serious call.<\/p>\n<h3>Step 2: The conversation moves into a small group<\/h3>\n<p>Additional supposed partners join a Telegram conversation. They discuss liquidity solutions and the firm&#8217;s work in language suited to the target.<\/p>\n<p>The number of participants is not proof. One operator can control several accounts, and copied profiles can make a fictional team look established.<\/p>\n<h3>Step 3: The target receives access to a shared vault<\/h3>\n<p>The contacts supply credentials for an attacker-controlled cloud vault. It is presented as the place where the team keeps its management notes and research.<\/p>\n<p>Because the application is well known, the target may focus on signing in correctly rather than asking who prepared the workspace.<\/p>\n<h3>Step 4: Plugin synchronization is framed as setup<\/h3>\n<p>The user is told to enable community-plugin sync to make shared materials work. That turns an unfamiliar security decision into a minor onboarding task.<\/p>\n<p>Elastic reproduced the behavior and found the plugin list and installed plugins did not sync by default. Manual enablement was necessary.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" class=\"wp-image-420900 lazyload\" alt=\"Illustrative fictional vault sync settings showing community-plugin synchronization disabled\" width=\"1536\" height=\"1024\" loading=\"lazy\" title=\"\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/obsidian-vault-detail.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/obsidian-vault-detail.png 1536w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/obsidian-vault-detail-300x200.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/obsidian-vault-detail-1024x683.png 1024w\"><\/figure>\n<h3>Step 5: A plugin runs attacker-defined commands<\/h3>\n<p>Once the malicious configuration is present and active, a command-capable community plugin can launch the next stage when its configured event occurs.<\/p>\n<p>Elastic observed Obsidian spawning PowerShell. The path was not a browser pop-up merely claiming infection; it was process activity on the machine.<\/p>\n<p>Another installed plugin helped hide parts of the configuration. A user browsing ordinary notes might not notice what had been prepared behind the interface.<\/p>\n<h3>Step 6: A remote-access payload is fetched<\/h3>\n<p>On Windows, the analyzed chain used an intermediate loader before PHANTOMPULSE. On macOS, researchers described an AppleScript-based delivery path.<\/p>\n<p>These are capabilities observed in the investigated campaign. It would be wrong to claim that every shared vault contains the same payload or that every attempt succeeded.<\/p>\n<h3>Step 7: The attacker seeks continued access<\/h3>\n<p>A remote-access tool can allow further commands, information collection, and movement toward valuable accounts. The exact outcome depends on what ran and what protection blocked.<\/p>\n<p>Elastic&#8217;s observed victim was protected early. That does not make the lure harmless; it shows why endpoint behavior detection and prompt reporting matter.<\/p>\n<div id=\"mwtad3334293780\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Why the Plugin Setting Matters More Than the Vault Link<\/h2>\n<p>The first invitation does not itself give a stranger remote control. It creates a reason to connect your normal application to content that the stranger prepared.<\/p>\n<p>A vault can contain ordinary text and also configuration files. Those files influence how plugins behave after the workspace is synchronized.<\/p>\n<p>Elastic found the Shell Commands community plugin in the malicious vault. That plugin is a legitimate extension capable of launching commands when configured.<\/p>\n<p>The dangerous part was the attacker-selected configuration, not the existence of a command-capable plugin in every user&#8217;s installation.<\/p>\n<p>Its settings included an event trigger. When the plugin and settings reached the victim&#8217;s computer, that event could start the next attack stage.<\/p>\n<p>Another plugin helped conceal configuration from casual inspection. It did not make the malicious process invisible to Elastic&#8217;s endpoint monitoring.<\/p>\n<p>The researchers tested synchronization themselves. By default, the remote vault did not deliver its installed plugin directory and active plugin list to the new device.<\/p>\n<p>That default matters. It means the attacker needed the target to change settings that most people would leave untouched.<\/p>\n<p>Social engineering supplied the missing step. The contacts could describe plugin sync as normal collaboration and make refusal feel like delaying a deal.<\/p>\n<p>For a victim, the interface may show only notes and a setup prompt. For the operating system, enabling the plugin can permit a new process.<\/p>\n<p>That is why a signed, genuine app can appear in the process tree of a malicious incident. Legitimate software can perform actions requested by untrusted content.<\/p>\n<p>On Windows, Elastic saw PowerShell run from Obsidian. The detection provided stronger evidence than a vague warning about suspicious links.<\/p>\n<p>On macOS, the reported path used AppleScript. A Mac user should not assume the Windows-specific PowerShell detail makes the lure irrelevant.<\/p>\n<p>The observed macOS command server was offline during parts of the research. That limits what can be said about subsequent payload execution on that platform.<\/p>\n<p>Security teams should review process events and plugin settings together. A clean-looking document view cannot answer whether a command already ran.<\/p>\n<p>For personal users, the safest rule is simpler: do not enable executable extensions in a stranger&#8217;s shared workspace merely to read proposed business materials.<\/p>\n<div id=\"mwtad842511143\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What the Evidence Does and Does Not Prove<\/h2>\n<p>Elastic inspected a specific intrusion and reproduced the critical plugin-sync path. It identified the fake investment discussion, the shared vault, command execution, and staged payloads.<\/p>\n<p>The report does not prove that Obsidian itself is fraudulent. It does not say its ordinary notes or official plugins are generally unsafe.<\/p>\n<p>It also does not show every LinkedIn finance contact using this technique. The warning applies when a stranger controls the vault and asks you to enable executable extensions.<\/p>\n<p>The April 2026 research named the attack set REF6598. That label helps defenders correlate technical indicators; ordinary readers need only understand the trust boundary.<\/p>\n<p>In the Reddit community, a commenter separately <a href=\"https:\/\/www.reddit.com\/r\/Scams\/comments\/1wih7nc\/us_fake_takehome_coding_assignment_repo_from\/\" target=\"_blank\" rel=\"noopener\">described<\/a> a recruiter supplying an Obsidian vault and asking to trust its author and enable plugins.<\/p>\n<p>That account is a tip, not independent malware analysis of the same operation. The Elastic report is the basis for the confirmed technical claims here.<\/p>\n<p>There is another important limit: Elastic found the Windows payload blocked before the adversary achieved its objectives in the observed case.<\/p>\n<p>Do not turn an attempted infection into a reported financial theft or assume that a named company lost funds. The practical danger remains serious without that embellishment.<\/p>\n<div id=\"mwtad2161853564\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How to Evaluate a Shared Vault Safely<\/h2>\n<p>Verify the person and organization through a channel you locate yourself. Use the firm&#8217;s published website or a known telephone number, not a link inside the chat.<\/p>\n<p>Ask why the material must be delivered through a live, synchronized workspace. A static PDF or plain-text summary may be enough for an initial discussion.<\/p>\n<p>If you must inspect a vault, treat its configuration and plugins as untrusted code. Notes can be read without enabling community-plugin synchronization.<\/p>\n<p>Check the vault&#8217;s plugin list, installed plugin files, and sync settings before allowing anything to run. In a company environment, involve IT or security.<\/p>\n<p>Do not use a workstation that holds production wallet keys, administrator sessions, customer records, or cloud credentials for a stranger&#8217;s assessment.<\/p>\n<p>An isolated test environment reduces exposure, but only if it has no shared folders, credentials, clipboard integration, or access to the corporate network.<\/p>\n<p>Even that is not a substitute for verifying the people. A convincing app workflow can still be a dishonest business approach.<\/p>\n<p>If the contact insists that disabling protections is necessary to proceed, stop the interaction. A real partner can provide a safer way to share documents.<\/p>\n<div id=\"mwtad71761035\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Have Fallen Victim to This Scam<\/h2>\n<ol>\n<li>Stop interacting with the vault. Do not enable another plugin or rerun a command to see whether the first attempt worked.<\/li>\n<li>Disconnect the affected device from the network if a plugin ran or a security alert appeared. Tell your employer&#8217;s security team immediately.<\/li>\n<li>Preserve the messages, vault invitation, account names, configuration files, and alert details. Do not wipe the machine before responders collect evidence.<\/li>\n<li>From a clean device, change exposed passwords and revoke active sessions. Include email, cloud, developer accounts, finance systems, and password managers.<\/li>\n<li>Rotate API keys, SSH keys, wallet credentials, and recovery codes that were accessible from the affected system. Ask your organization which secrets require emergency rotation.<\/li>\n<li>Review account activity for unfamiliar logins, forwarding rules, new devices, downloads, and financial actions. Report any unauthorized transfer promptly.<\/li>\n<li>Have the endpoint examined with trusted security tools. Malwarebytes can help detect known threats, but enterprise incident response may require deeper forensic work.<\/li>\n<li>Report the fake profiles and group conversation to the platforms involved. Notify the legitimate firm if its identity was copied.<\/li>\n<li>If money or confidential business data was exposed, contact the relevant institution and file a report with <a href=\"https:\/\/www.ic3.gov\/\" target=\"_blank\" rel=\"noopener\">IC3<\/a> or local cybercrime authorities.<\/li>\n<\/ol>\n<p>AdGuard can reduce access to known malicious destinations, but it cannot make an attacker-controlled vault safe after dangerous plugins have been enabled.<\/p>\n<p>Someone offering to recover stolen crypto or clean the device through a private message may be another scammer. Use your organization&#8217;s trusted responders.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<h3>Is Obsidian itself a scam or malware?<\/h3>\n<p>No. Elastic found the genuine application was abused through attacker-controlled community-plugin configuration in a shared vault.<\/p>\n<h3>Can simply reading a note install PHANTOMPULSE?<\/h3>\n<p>Elastic&#8217;s reproduced path required manual enabling of community-plugin synchronization. Reading notes alone was not the documented trigger.<\/p>\n<h3>Were all victims infected?<\/h3>\n<p>No such claim is supported. Elastic said its protection blocked the observed intrusion early, before the attackers achieved their objectives.<\/p>\n<h3>Does a group of investors in chat prove the firm is real?<\/h3>\n<p>No. Multiple accounts can be controlled or coordinated by an attacker. Verify the firm and the people through independent channels.<\/p>\n<h3>Should I delete the vault after opening it?<\/h3>\n<p>Do not erase evidence if plugins executed or a company device was involved. Disconnect, alert security, and let responders decide what to preserve.<\/p>\n<h3>What if I enabled sync but did not see a warning?<\/h3>\n<p>Tell your security team anyway. An absent alert does not prove safety, and the plugin settings and process history should be reviewed.<\/p>\n<h2>The Bottom Line<\/h2>\n<p>Fake investment contacts used a real notes application to hide a malicious handoff inside a normal-looking research request.<\/p>\n<p>Do not enable community plugins for a stranger&#8217;s vault just to keep a business conversation moving. Verify the contact and inspect the workspace first.<\/p>\n<div id=\"mwtad2519174548\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A finance contact wants to share research before a call. The files are in an Obsidian vault, and a small setup change seems necessary to view them. That request can sound like ordinary collaboration. The &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"Fake Investors Use Shared Obsidian Vaults to Install Remote Access Malware\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/fake-investors-obsidian-vault-remote-access-malware\/#more-420898\" aria-label=\"Read more about Fake Investors Use Shared Obsidian Vaults to Install Remote Access Malware\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":420899,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-420898","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420898","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=420898"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420898\/revisions"}],"predecessor-version":[{"id":420901,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/420898\/revisions\/420901"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/420899"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=420898"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=420898"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=420898"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}