Crypto Users Targeted in Social Engineering Attack Using Obsidian Community Plugins
Cryptocurrency transactions are typically difficult to reverse once recorded on-chain, making industry professionals with access to wallet credentials high-risk targets for social engineering. Chainalysis estimates that compromises of personal crypto wallets caused $713 million in losses in 2025. The incident also shows how legitimate productivity tools such as Obsidian and their community plugins can be turned into entry points for corporate breaches.
Elastic Security Labs disclosed the REF6598 campaign on April 14, 2026. Scammers posed as a venture capital firm, initially contacting finance and crypto professionals on LinkedIn before moving conversations to Telegram and persuading victims to open an attacker-controlled Obsidian cloud vault and sync its plugins. The campaign targeted both Windows and macOS systems and deployed the PHANTOMPULSE remote access trojan. Elastic said it intercepted the attack at an early stage.
All Coverage
1 original reportsThe Backstory
The history behind this eventKaspersky Identifies OkoBot Malware Targeting Crypto Investors
As the cryptocurrency market expands, investors face a growing array of cybersecurity threats. The emergence of the OkoBot malware framework highlights the serious challenges confronting digital-asset holders. The software can inject fake webpages targeting cold wallets such as Ledger and Trezor to steal users’ wallet seed phrases and browser credentials. The discovery is a significant warning that hackers’ methods are evolving into highly modular attacks that are increasingly difficult to defend against.
Cybersecurity firm Kaspersky said on July 15, 2026, that OkoBot had been active since April 2025 and was distributed through ClickFix social engineering and GitHub. The malware includes more than 20 malicious modules, including TookPS. It has affected hundreds of cryptocurrency holders across more than 25 countries, including Brazil, Canada and Vietnam, transferring assets by monitoring browsers and stealing seed phrases.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.