[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7E-c_6Wp-VWcPd_waN4tD-_lZWCvYTvf-m0eTjaDy1o":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"f04ca0d9-1b0c-4aab-b9a7-77d8c3af1ae7","Fake Software Update Installs a Real Crypto Wallet – Rigged So It Can Never Open","fake-software-update-installs-a-real-crypto-wallet-rigged-so-it-can-never-open-66de62","Security researchers at Huntress have discovered a malware campaign that tricks victims into installing a real, fully functional copy of Exodus, a popular cryptocurrency wallet application, only to disable it so it can never actually be opened, using it instead as cover for a hidden spying tool. The firm said it identified four separate organisations […] The post Fake Software Update Installs a Real Crypto Wallet – Rigged So It Can Never Open appeared first on IT Security Guru.","A new malware campaign uses a tampered Exodus cryptocurrency wallet installer to deploy a sophisticated remote access trojan (RAT). The installer disguises itself as a legitimate software update or document, then installs a functional Exodus wallet that is rigged to never open, serving as camouflage for the hidden RAT. This RAT offers capabilities like remote command execution, VNC, proxying, and credential theft from major browsers.","Fake Exodus crypto wallet installer hides a RAT, stealing credentials and providing remote access.","Security researchers at Huntress have discovered a malware campaign that tricks victims into installing a real, fully functional copy of Exodus, a popular cryptocurrency wallet application, only to disable it so it can never actually be opened, using it instead as cover for a hidden spying tool. The firm said it identified four separate organisations compromised between late July and mid-August 2026, three of them within an 85-minute window on a single day, using a version of the malware built the day before it was deployed. According to Huntress, victims were lured into opening what appeared to be a work document or a routine software update. In practice, the files silently downloaded a Windows installer that presented itself, falsely, as an Apple “Background Service.” The installer placed a genuine, largely unmodified copy of the Exodus wallet, version 24.33.4, onto the victim’s machine. Of nearly 2,000 files bundled with the wallet, researchers found that only three had been altered. One of those changes prevented the wallet from ever displaying a window, meaning it never appeared in the taskbar and could not be closed or interacted with by the user. The other two altered files formed a loader that decrypted and ran a separate 10-megabyte payload directly in the computer’s memory, without ever writing it to disk. That hidden payload, researchers said, is a modular remote access trojan (RAT) with six separate capabilities: remote command execution, file browsing and transfer, a hidden virtual network connection (VNC) allowing an attacker to view and interact with the victim’s desktop unseen, a SOCKS proxy that could turn the infected computer into a relay for further attacks, a scripting engine, and a module built to steal saved passwords, cookies, and browser data from Chrome, Edge, and Firefox. Despite the crypto wallet disguise, Huntress said the malware does not target wallet data, seed phrases, or cryptocurrency funds directly. Researchers instead described the campaign as being built for broad, hands-on remote access and credential theft, with the wallet acting purely as camouflage. Because most of the installed software is genuine, unaltered Exodus code communicating with real Exodus servers, the tampered installer registered zero detections across 76 antivirus engines on VirusTotal at the time of testing, according to Huntress. The malware also avoided using attacker-owned servers to communicate. Instead, researchers found it checking in with Microsoft’s Azure Table Storage service, a technique that allowed its network traffic to blend in with ordinary, legitimate cloud activity rather than triggering alerts tied to suspicious domains. To maintain access, the malware created a scheduled task that silently relaunched the invisible wallet every hour. Huntress also identified a second, earlier-observed task that repeatedly reset a victim’s corporate proxy settings, a mechanism apparently built specifically to keep the malware’s outbound traffic from being blocked or inspected by network security controls. Huntress said the operation shows signs of a single toolchain behind both the delivery mechanism and the trojanised wallet, including a shared code-obfuscation technique and an npm software package impersonating Intel. Researchers recommended that any organisation identifying these artefacts treat the affected host as a full interactive compromise, revoke active browser sessions, and rotate credentials rather than only resetting passwords. Huntress’s full technical writeup, including indicators of compromise, is available at: The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT","https:\u002F\u002Fwww.itsecurityguru.org\u002F2026\u002F09\u002F02\u002Ffake-software-update-installs-a-real-crypto-wallet-rigged-so-it-can-never-open\u002F?utm_source=rss&utm_medium=rss&utm_campaign=fake-software-update-installs-a-real-crypto-wallet-rigged-so-it-can-never-open","https:\u002F\u002Fwww.itsecurityguru.org\u002Fwp-content\u002Fuploads\u002F2026\u002F09\u002FChatGPT-Image-Sep-2-2026-11_51_04-AM.png","2026-09-02T10:51:54+00:00","2026-09-02T18:00:21.857496+00:00",9,[18,21,24,27,29,31],{"name":19,"type":20},"Exodus","product",{"name":22,"type":23},"Huntress","vendor",{"name":25,"type":26},"RAT","technology",{"name":28,"type":26},"VNC",{"name":30,"type":26},"SOCKS proxy",{"name":32,"type":26},"Azure Table Storage","89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5",{"id":33,"icon":35,"name":36,"slug":37},null,"Malware","malware",[39,44,49,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":50},{"id":33,"icon":35,"name":36,"slug":37},{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57],{"type":37,"value":58,"context":59},"Exodus wallet version 24.33.4","The specific version of the Exodus wallet used as a disguise."]