Trojanized Exodus Wallet Installer Deploys Remote Access Trojan

Trojanized Exodus Wallet Installer Deploys Remote Access Trojan

First seen 2 Sep 2026, 08:44 UTC HuntressGbhackersCybersecuritynewsItsecurityguru 68.0

Article Content

Browse articles
ThreatCluster

Between late July and mid-August 2026, multiple organizations were compromised by a malware campaign using a tampered installer for the legitimate Exodus cryptocurrency wallet. Victims were tricked into downloading a JavaScript file that installed a genuine but modified version of Exodus 24.33.4, which could never be opened. The malware, a modular remote access trojan (RAT), was hidden within the installer and capable of remote command execution, browser credential theft, and creating a SOCKS proxy. Researchers identified four organizations affected, with three attacks occurring within an 85-minute window. The RAT communicates with Microsoft Azure Table Storage to avoid detection, and the installer registered zero detections on VirusTotal. The campaign is focused on long-term access rather than direct cryptocurrency theft. Current investigations are ongoing to assess the full scope of the impact.

Key Points: • Malware campaign disguises a RAT within a legitimate Exodus wallet installer. • Four organizations were compromised, with three attacks occurring in a short time frame. • The RAT employs Azure Table Storage for communication to evade detection.

Ask AI about this cluster

Timeline

2026-07-01
Malware campaign begins
Attackers start distributing tampered Exodus wallet installers to lure victims.
Huntress
2026-08-01
Multiple organizations compromised
Four organizations reported being affected by the malware campaign during this period.
Itsecurityguru
2026-08-01
Three attacks in 85 minutes
Three of the four organizations were attacked within an 85-minute window on a single day.
Itsecurityguru
2026-09-01
Huntress reports findings
Huntress publishes details of the malware campaign, revealing the RAT's capabilities and methods.
Huntress
2026-09-02
Widespread awareness grows
Multiple cybersecurity outlets report on the findings, increasing awareness of the threat.
Gbhackers