A campaign targeting four unrelated organizations used a trojanized Exodus Wallet 24.33.4 installer to deploy a modular, memory-resident remote-access trojan (RAT). Victims received disguised JavaScript lures—including fake .pdf.js files and ZIP-contained scripts—that displayed legitimate decoy PDFs while silently installing an unsigned MSI. The altered wallet suppressed its Electron application windows, operated from a per-user AppData directory, and reflectively loaded an encrypted RAT payload.
The RAT enabled remote command execution, browser-credential theft, hidden VNC access, SOCKS proxying, file management, and script execution. It used Azure Table Storage as an observed dead-drop command-and-control channel and established persistence through scheduled tasks; an earlier intrusion also repeatedly cleared user proxy settings, apparently to bypass corporate proxy controls. Affected endpoints should be treated as fully interactively compromised, requiring credential resets and session-cookie remediation alongside malware removal and persistence hunting.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
On August 18, 2026, three observed organizations were compromised within 85 minutes using the installer built the previous day. The trojanized wallet suppressed Electron windows, reflectively loaded a modular RAT, and established hourly scheduled-task persistence as ExdBackupTool.
An unsigned MSI impersonating Exodus Wallet 24.33.4 was built on August 17, 2026, with false Apple/Background Service metadata and installation under %APPDATA%\ExdBackupTool\. Its encrypted 10 MB PE32+ RAT payload was compiled six minutes before the installer.
From late July through mid-August 2026, Huntress observed the same malicious tooling compromise four unrelated organizations. Victims opened disguised JavaScript files, including .pdf.js lures and JavaScript in ZIP archives, which displayed decoy PDFs while silently installing a tampered Exodus Wallet installer.
Additional indicators were disclosed for the Exodus/ExodusHelper malware, including hashes, the jn0101.msi installer, 35[.]212[.]159[.]20, us05[.]org, Azure Table Storage endpoints, and numerous suspected C2-related domains. The malware's Dll4 modules indicate file-management, SOCKS proxy, command execution, scripting, browser-interaction, and VNC remote-control capabilities.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 55 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
itsecurityguru.org
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.