ZeroHour
Huntresspublished ()ingested

The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT

mediumMalware exploited in the wildimportance 48
AI summary · glm-5.3-flash

Huntress found tampered Exodus crypto wallet installers delivering a modular RAT that steals credentials rather than wallet funds.

Huntress analysts analyzed tampered installers for the Exodus cryptocurrency wallet that bundle a modular remote access trojan. The implant focuses on harvesting credentials instead of draining wallet balances, suggesting broader access theft. The case highlights installer tampering as a supply-chain-style delivery vector for credential-stealing tooling.

  • Tampered Exodus wallet installers deliver a modular RAT
  • Implant prioritizes credential theft over wallet draining
  • Installer tampering acts as a supply-chain-style delivery vector
OrganizationsExodusHuntress
Full article

Exodus crypto wallet analysis by Huntress uncovered tampered installers hiding a modular RAT focused on stealing credentials, not coins.

This source does not provide full text. Read it at huntress.com.