Exodus Wallet Malware Campaign Targets Organizations with Hidden Spying Tool
Security researchers at Huntress have uncovered a sophisticated malware campaign that disguises itself as a software update for the Exodus cryptocurrency wallet. The malicious code, which was deployed between late July and mid-August 2026, tricks victims into installing a genuine copy of version 24.33.4 of the Exodus wallet application.
The researchers found that nearly all files bundled with the wallet were unaltered, except for three key changes. One alteration prevented the wallet from ever displaying a window, while the other two introduced a loader that decrypted and ran a separate payload directly in the computer's memory.
This hidden payload is a modular remote access trojan (RAT) with six capabilities: remote command execution, file browsing and transfer, a hidden virtual network connection (VNC), a SOCKS proxy, a scripting engine, and a module for stealing saved passwords, cookies, and browser data from Chrome, Edge, and Firefox.
The malware does not target wallet data or cryptocurrency funds directly but uses the Exodus disguise as camouflage. The campaign's purpose is broad, hands-on remote access and credential theft. To maintain access, the malware creates a scheduled task that silently relaunches the invisible wallet every hour.