A social engineering campaign has been identified that uses the Obsidian note-taking application to deliver a remote access trojan (RAT) called PHANTOMPULSE. The campaign targets individuals in the financial and cryptocurrency sectors, and the attack relies on tricking the user into enabling a community plugin that executes code to deploy the RAT. The PHANTOMPULSE RAT demonstrates advanced capabilities, including using the Ethereum blockchain to dynamically resolve its command-and-control server address. The attack highlights the importance of being cautious when enabling third-party plugins and the need for improved security measures in applications like Obsidian.