Tampered Exodus Wallet Installer Distributes Remote Access Trojan
Article Content
Between late July and mid-August 2026, multiple organizations protected by Huntress were targeted by a modular Remote Access Trojan (RAT) hidden within a tampered installer of the Exodus cryptocurrency wallet. Victims were deceived into downloading a JavaScript file that fetched a legitimate-looking but non-functional version of the Exodus wallet, which lacked user interaction capabilities. The malicious installer masqueraded as a 'Background Service' from 'Apple Inc.' and contained only three altered files among 1,973. One of these files prevented the wallet's window from appearing, while another acted as a loader for a 10 MB payload containing the RAT. This RAT facilitated remote access and browser credential theft, communicating with Azure Table Storage rather than a dedicated domain. The attack was characterized by its stealthy nature, with the RAT returning hourly through a scheduled task, leaving detectable artifacts. The campaign's scope included at least three victims within a short time frame, highlighting its rapid spread.
Key Points: • A modular RAT was embedded in a tampered Exodus wallet installer. • Victims were tricked via disguised files, including fake PDFs. • The RAT enables remote access and credential theft without user interaction.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.