[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f5LyhkGaftsnGAgPxJMPYfA0W62HcoYXB8bEp57xs16M":3},{"article":4,"iocs":41,"watch_terms":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":11,"published_at":13,"ingested_at":14,"relevance_score":15,"entities":16,"category_id":26,"category":27,"article_tags":30},"1f42c567-e73d-428c-8164-32f79bb36d58","Key takeaways:\n- Threat actors posed as a VC firm on LinkedIn and Telegram, luring targets into o...","key-takeaways-threat-actors-posed-as-a-vc-firm-on-linkedin-and-telegram-luring-t-51d8a6","Key takeaways:\n- Threat actors posed as a VC firm on LinkedIn and Telegram, luring targets into opening a weaponized Obsidian vault\n- The attack abuses Obsidian's Shell Commands plugin to execute a malicious payload on vault open, no vulnerability required\n- PHANTOMPULSE is a","Threat actors posing as a venture capital firm on LinkedIn and Telegram are luring targets into opening a weaponized Obsidian vault that executes malicious payloads. The attack exploits Obsidian's Shell Commands plugin to run code when the vault is opened, requiring no underlying vulnerability. The campaign, tracked as PHANTOMPULSE, combines social engineering with legitimate application functionality to compromise targets.","Threat actors impersonate VC firm via LinkedIn\u002FTelegram to deliver malware via weaponized Obsidian vault.",null,"https:\u002F\u002Fx.com\u002Felasticseclabs\u002Fstatus\u002F2043738797527994543","2026-04-13T17:11:14+00:00","2026-04-13T18:00:10.452886+00:00",8,[17,20,23],{"name":18,"type":19},"PHANTOMPULSE","campaign",{"name":21,"type":22},"Obsidian","product",{"name":24,"type":25},"Shell Commands plugin","technology","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":26,"icon":11,"name":28,"slug":29},"Threat Intelligence","threat-intelligence",[31,36],{"category":32},{"id":33,"icon":11,"name":34,"slug":35},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":37},{"id":38,"icon":11,"name":39,"slug":40},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",[42],{"type":40,"value":18,"context":43},"Campaign name for Obsidian vault-based malware delivery attack",[21]]