A malicious installer disguised as the Exodus cryptocurrency wallet is being used to deploy a modular remote-access trojan (RAT) that steals browser data, enables hidden remote control, and converts infected Windows computers into SOCKS proxy relays.
Researchers observed four unrelated organizations compromised between late July and mid-August 2026. Three incidents occurred within 85 minutes on August 18, using an installer created only one day earlier.
The campaign delivers a genuine copy of Exodus Wallet version 24.33.4, but secretly modifies three files in the application package.
Although the wallet runs in the background and communicates with legitimate Exodus services, victims never see its interface.
The malware prevents the Electron application from displaying windows, focusing, or appearing in the taskbar. This makes the wallet look like it never launched while the hidden payload continues running.
Exodus Installer Hijacks PCs
One delivery method uses JavaScript files disguised as PDFs with names ending in .pdf.js. Because Windows commonly hides known file extensions, victims may only see what appears to be a normal PDF document.
When opened, the JavaScript displays a legitimate decoy PDF from trusted websites or content-delivery networks. At the same time, it silently downloads and installs a malicious MSI package using msiexec.

A second method uses ZIP archives containing JavaScript files. In one case, the archive pretended to be a software update. Victims who opened the file directly from Windows Explorer’s compressed-folder view triggered the same infection chain.
Researchers also discovered infrastructure capable of using the Windows search-ms: protocol.
This technique can redirect a browser to a Windows Explorer search window connected to an attacker-controlled WebDAV server. Users could then run malicious files that appear to be stored locally.
The oversized MSI installer places Exodus files in %APPDATA%\ExdBackupTool\, rather than the legitimate Exodus installation path under %LOCALAPPDATA%\exodus.
It launches Exodus.exe through explorer.exe, making the process look like a user manually opened the application. The trojanized wallet includes an encrypted, memory-resident payload loaded through JavaScript.
![The "Open Windows Explorer?" browser prompt served by us05[.]org (Source: huntress)](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcga2lEZxiFe2eRyCp2LKHmhusMxIqX_jkaoaQIFKnx_sqm-CKudbEvNuBb_BYONT3OsAAvuujFChivGkXu7Go3HZJMpqMd3JBYkl3nXPCTBfn71XQnUk2FoQg44rbhjIqm7i4x1VgEBRwrPtweH-S08ASO-FzSirScIJkkm_10qnzd4BQFYIJ_dTG3a0V/s1600/assets_3eb6f92aedf74f109c7b4b0897ec39a8_4c604435e1f2489fad4f0ecc506c9f10-1.webp)
The malware uses Windows APIs to allocate memory, write a Portable Executable into it, resolve imports, and start execution without dropping the final RAT to disk.
Command-and-control traffic uses Azure Table Storage as a dead-drop channel. The malware writes bot data, retrieves commands, sends results, and deletes completed tasking through Azure-hosted tables.
This approach can blend into legitimate cloud traffic and avoids reliance on a traditional attacker-controlled domain, huntress said.
Indicators of Compromise
| IOC | Type | Description |
|---|---|---|
jn0101.msi | Malicious installer | Fake Exodus Backup Tool MSI installer |
c513a7346484ee69a2931c4a89956ee50aa63e4366ef989315e669d8f10d7485 | SHA-256 |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Detect, investigate, and respond faster with in-browser data inspection from ANY.RUN-> Power your SOC with ANY.RUN