The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT
Cybersecurity Classified by Officially
Between late July and mid August 2026, multiple Huntress-protected organizations were hit by the same modular RAT, three of which were hit within an 85-minute window. Victims were tricked into downloading a JavaScript file that quietly pulled down an installer for a real, working Exodus crypto wallet, with the RAT hidden inside.
The initial lures were disguised to trick people into running them: a fake PDF or a software update staged in a ZIP file, with content unrelated to cryptocurrency. Both fetch the same Windows Installer package (MSI), which declares itself a "Background Service" by "Apple Inc".
The "Background Service" installs a genuine Exodus 24.33.4 cryptocurrency wallet, missing one key function: any way for the user to interact with it. Only 3 of its 1,973 files differ from the real thing, and the package has no detections on VirusTotal.
One of those three files stops the wallet from ever drawing a window. Another turns a legitimate Exodus source file into a PE loader that decrypts a 10 MB payload and maps it into memory by hand, where it never touches disk. That payload is the RAT: a hidden VNC and SOCKS proxy enable remote access and browser credential theft.
While the RAT stealthily beacons to Azure Table Storage rather than a domain of its own, it returns every hour through a scheduled task, leaving behind detectable artifacts.
Acknowledgments: Special thanks to Tanner Filip for their contributions to this investigation and writeup.
You'd think an installer posing as a cryptocurrency wallet would be after your coins. This one installs a real version of Exodus Wallet version 24.33.4, a cryptocurrency wallet available on desktop and mobile platforms that allows users to manage digital assets and cryptocurrencies like Bitcoin, Ethereum, and Solana. The installer also takes considerable care to make sure nobody ever opens the application, and then goes after a whole lot more.
This is an extract. The publication continues at the source.
Read the original at the source: https://www.huntress.com/blog/exodus-crypto-wallet-installer-rat
Officially imported this from Huntress’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Huntress — imported from official source
- Official source
- https://www.huntress.com/blog/rss.xml RSS
- Imported
- September 20, 2026 19:52
- Versions
- 1 recorded
- Identity
https://www.huntress.com/blog/exodus-crypto-wallet-installer-rat