Security researchers at Huntress have discovered a malware campaign that tricks victims into installing a real, fully functional copy of Exodus, a popular cryptocurrency wallet application, only to disable it so it can never actually be opened, using it instead as cover for a hidden spying tool.
Fake Software Update Installs a Real Crypto Wallet – Rigged So It Can Never Open
Security researchers at Huntress have discovered a malware campaign that tricks victims into installing a real, fully functional copy of Exodus, a popular cryptocurrency wallet application, only to disable it so it can never actually be…
IT Security Guru
Publisher
Sep 2, 2026 at 10:53 AM UTC · 2 분 소요

The firm said it identified four separate organisations compromised between late July and mid-August 2026, three of them within an 85-minute window on a single day, using a version of the malware built the day before it was deployed.
According to Huntress, victims were lured into opening what appeared to be a work document or a routine software update. In practice, the files silently downloaded a Windows installer that presented itself, falsely, as an Apple “Background Service.” The installer placed a genuine, largely unmodified copy of the Exodus wallet, version 24.33.4, onto the victim’s machine. Of nearly 2,000 files bundled with the wallet, researchers found that only three had been altered.
One of those changes prevented the wallet from ever displaying a window, meaning it never appeared in the taskbar and could not be closed or interacted with by the user. The other two altered files formed a loader that decrypted and ran a separate 10-megabyte payload directly in the computer’s memory, without ever writing it to disk.
Article Intelligence
Topics
Regulation Signal
in progressUpdated 한 달 전
SEC Crypto Asset Market Structure RulemakingRelated Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
