Surge in Malware and Phishing Attacks via n8n Webhooks: Analysis of Cloud Workflow Automation Abuse (2025-2026) – Rescana

The core of the attack involves the abuse of n8n‘s webhook feature, which allows users to create unique, publicly accessible URLs that trigger automated workflows. Attackers register accounts on the n8n cloud service, generating subdomains in the format .app.n8n.cloud. These subdomains host webhook endpoints that are embedded in phishing emails sent to potential victims.

Upon clicking a malicious n8n webhook link, the victim is typically redirected to a web page that may display a CAPTCHA or other benign-looking content to evade automated analysis. Interaction with the page triggers the download of a malicious payload, often an executable or MSI installer, from an external server. The payloads observed in these campaigns are frequently modified versions of legitimate Remote Monitoring and Management (RMM) tools, such as Datto RMM and ITarian Endpoint Management. These tools are abused to establish persistence, enable remote access, and facilitate lateral movement within the victim’s environment.

In addition to malware delivery, some campaigns use n8n webhooks to perform device fingerprinting and victim tracking. This is achieved by embedding invisible images or tracking pixels in phishing emails, which, when loaded, send HTTP GET requests to the attacker’s webhook endpoint. These requests leak metadata such as the victim’s email address, IP address, and user agent, enabling targeted follow-up attacks.

The technical sophistication of these campaigns is further demonstrated by the use of short-lived or obfuscated domains for payload delivery, dynamic command-and-control (C2) infrastructure, and the chaining of multiple SaaS services to complicate attribution and takedown efforts.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *