Exodus A.I CyberSecurity Scoring
Exodus
Company Information
Website:https://www.exodus.com
Employees number:285
Number of followers:16,291
NAICS:52
Industry Type:Financial Services
Homepage:exodus.com
Exodus Risk Score (AI oriented)
Between 650 and 699
ExodusFinancial Services
Updated:
02/09/2026
02/09/2026
665/1000
Weak
B
Exodus Global Score (TPRM)
xxxx
ExodusFinancial Services
Score locked

ExodusWeak
Current Score
665B (WEAK)
01000
4 incidents
-31.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
665
AUGUST 2026
715
Cyber Attack
18 Aug 2026 • Exodus
Exodus, Organization 3 and Organization 2: Trojanized Exodus Wallet Installer Deploys RAT to Steal Browser Credentials and Cookies
Sophisticated Malware Campaign Abuses Trojanized Exodus Wallet Installer to Deploy Modular RAT
664
CRITICAL-51
EXOWOR1788326823
Sophisticated Malware Campaign Abuses Trojanized Exodus Wallet Installer to Deploy Modular RAT
A stealthy malware campaign has exploited a trojanized installer for the legitimate Exodus cryptocurrency wallet to distribute a modular remote access trojan (RAT) designed for long-term interactive access rather than immediate cryptocurrency theft. Discovered by Huntress between late July and mid-August 2026, the campaign compromised four unrelated organizations, with three victims infected within 85 minutes on August 18 using an installer created just a day prior.
### Attack Vectors and Execution
The intrusion begins with JavaScript-based lures disguised as either:
- A PDF document (with a `.pdf.js` double extension, appearing harmless when Windows hides file extensions).
- A software update contained in a ZIP archive.
In both cases, opening the file triggers Windows Script Host, displays a legitimate decoy document (hosted on trusted infrastructure), and silently installs a malicious MSI package via `msiexec`. A second observed method involved a ZIP file with a JavaScript "update," executed directly from Explorer’s compressed-folder view, leaving a temporary path with a `.zip.116\` fragment.
### Evasion and Payload Delivery
The MSI masquerades as "Background Service" from "Apple Inc." and installs a real copy of Exodus Wallet (v24.33.4) under `%APPDATA%\ExdBackupTool\`. At the time of analysis, the 201 MB package had zero detections on VirusTotal, leveraging the wallet’s legitimacy to evade detection. Only three of the wallet’s 1,973 files were modified:
- One patch prevents Electron windows from appearing, leaving the wallet running invisibly without a taskbar entry.
- Another loads a 50 MB JavaScript component that decrypts and memory-maps a 10 MB Windows RAT without writing it to disk.
### RAT Capabilities and Command-and-Control
The decrypted RAT includes six modules for:
- Remote command execution
- File operations
- Script execution
- SOCKS proxying
- Hidden VNC access
- Browser data theft (Chrome, Edge, Firefox targeting passwords, cookies, autofill, and extensions)
Notably, the malware wipes cookies to force reauthentication, potentially enabling attackers to capture new sessions. Instead of traditional C2 infrastructure, it uses Azure Table Storage as a dead drop, blending malicious traffic with legitimate Microsoft cloud services to evade network blocking.
### Persistence and Defense Evasion
Persistence is maintained via a scheduled task (`ExdBackupTool`) that relaunches the invisible `Exodus.exe` hourly. A related task (`INetHealth`) repeatedly clears Windows proxy settings, likely to bypass enterprise proxy inspection. The RAT retrieves the user’s Internet Explorer proxy configuration before initiating communications.
### Impact and Indicators of Compromise (IOCs)
Organizations should treat detections as full interactive compromises, given the RAT’s ability to enable lateral movement, hidden VNC access, and SOCKS proxying. Key IOCs include:
- Installer: `jn0101.msi` (SHA256: `c513a7346484ee69a2931c4a89956ee50aa63e4366ef989315e669d8f10d7485`)
- Install directory: `%APPDATA%\ExdBackupTool\`
- Trojanized files: Modified `app.asar` (3 of 1,973 files altered)
- Scheduled tasks: `ExdBackupTool`, `INetHealth`
- Artifacts: `%TEMP%\<guid>.tmp.node`, `debug.log` (attacker build artifact)
The campaign’s rapid payload rebuilds and targeted delivery suggest an active, evolving operation rather than opportunistic malware reuse.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Cyber Attack
18 Aug 2026 • Exodus
Exodus and Crypto.com: Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases
Operation ASTERIX: AI-Powered Crypto Fraud Campaign
664
CRITICAL-51
CRYEXO1787041502
Operation ASTERIX: AI-Powered Crypto Fraud Campaign Exposed
Researchers at Rapid7 uncovered Operation ASTERIX, a sophisticated cryptocurrency fraud campaign that combined account enumeration, branded phishing, vishing (voice phishing), and trojanized wallet software to steal victims’ recovery phrases. The operation, named after the Asterisk telephony platform found in its infrastructure, employed a multi-stage social-engineering pipeline to target users with precision.
### How the Attack Worked
1. Target Validation & Enrichment
- The threat actor compiled 885,000 phone numbers from datasets linked to Germany, Hong Kong, Bulgaria, the UK, the US, Canada, Ledger users, and fintech services.
- A Go-based checker validated 43,066 Crypto.com accounts from a German dataset of 316,002 numbers, achieving a 13.6% hit rate.
- The attacker used residential proxies, retry logic, and lead databases to identify high-value targets those likely to own crypto wallets or exchange accounts.
2. Multi-Channel Phishing & Vishing
- Victims received branded phishing emails impersonating platforms like Crypto.com and Binance, followed by automated voice calls (using Asterisk, 3CX, and custom scripts) citing personal details, support cases, and verification codes.
- The callers referenced real verification codes sent via email, creating a false sense of legitimacy.
- Victims were tricked into installing fake wallet updates or submitting recovery phrases under the guise of security checks.
3. Trojanized Wallet Software
- The campaign distributed counterfeit versions of Trezor Suite, Ledger Live, and Exodus for macOS and Windows.
- The fake Trezor Suite (packaged in Electron) killed the legitimate app, displayed a convincing replica, and prompted victims for 12-, 18-, 20-, or 24-word recovery phrases.
- Stolen data including recovery phrases, passphrases, and IP addresses was exfiltrated to a Telegram bot.
- The Ledger Live variant included clipboard hijacking, replacing copied crypto addresses with attacker-controlled ones.
- The Exodus installer used a trojanized JavaScript component to fetch malicious payloads post-installation.
4. AI Integration in Malware Development
- The exposed server revealed LLM session logs, shell history, and source code, showing the attacker used GitHub Copilot and Claude Code for:
- Managing lead lists
- Configuring validation scripts
- Troubleshooting network issues
- Packaging Electron apps
- When models refused to assist with obfuscation or payload hosting, the operator switched to Kimi AI and attempted jailbreak prompts to bypass safeguards.
- This marks one of the first documented cases of AI being actively integrated into a criminal malware-development pipeline.
### Infrastructure & Persistence
- The attacker’s server hosted multiple ports for different functions:
- Port 8000: Fake wallet archives
- Port 8080: Installers and LaunchAgent files
- Port 5000: Password-protected Flask panels
- Port 9000: Installation telemetry
- Port 8090: Auxiliary control
- On macOS, persistence was achieved via LaunchAgents (`com.trezormovement.agent`, `io.trezor.agent`), ensuring the malware relaunched at login.
### Impact & Response
- Rapid7 observed 20 successful lead lookups and six phishing emails over two weeks, indicating a targeted, operator-led campaign rather than mass phishing.
- The company notified affected providers and authorities, including Apple’s security team, while parts of the infrastructure remained active.
- Indicators of compromise (IOCs) including Telegram bot tokens, LaunchAgent labels, and malicious file hashes were published on Rapid7’s GitHub.
Operation ASTERIX highlights the growing sophistication of crypto fraud, blending AI-driven development, multi-channel social engineering, and trojanized software to maximize success rates.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
736
Cyber Attack
28 Jul 2026 • Exodus
Exodus and Trezor: Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions
CastleLoader Campaign Expands with Crypto Wallet Spoofing and Browser Session Theft
714
CRITICAL-22
EXOTRE1785241575
CastleLoader Campaign Expands with Crypto Wallet Spoofing and Browser Session Theft
Cybercriminals behind the CastleLoader malware campaign are escalating attacks by deploying sophisticated tools to steal cryptocurrency recovery phrases, login credentials, and active browser sessions. Researchers at Arctic Wolf identified the latest evolution of the campaign, which now targets digital asset holders with fake wallet interfaces and malicious browser extensions.
### How the Attack Works
The operation begins with fake software installers and ClickFix-style prompts, tricking victims into executing harmful PowerShell commands. Once executed, the CastleLoader malware retrieves additional payloads including Python injectors and Rust-based stealers without leaving obvious traces, complicating early detection.
Key components of the campaign include:
- NeedleStealer (Rust-based wallet spoofer): Mimics popular wallet brands (Ledger, Trezor, Exodus) with polished fake interfaces designed to trick users into entering their recovery seed phrases. Unlike traditional exploits, this attack relies on social engineering rather than software vulnerabilities.
- Golang-based malicious browser extensions: Disguised as legitimate tools (e.g., ad blockers), these extensions hijack active browser sessions, allowing attackers to bypass passwords and access accounts without triggering new login challenges.
- Node.js-based injectors: Used in the Noidret campaign, these tools unpack malware in the ProgramData directory alongside legitimate binaries, blending in with normal system activity.
### Why This Matters
- Irreversible wallet theft: Unlike passwords, recovery phrases cannot be reset once stolen, attackers gain permanent control of a victim’s cryptocurrency holdings.
- Session hijacking risks: Stolen browser tokens enable attackers to access accounts without passwords, evading security measures like two-factor authentication.
- Evolving tactics: The campaign reflects a shift from general credential theft to specialized crypto-targeting, leveraging social engineering (fake updates, misleading installers) to deceive users.
### Campaign Clusters & Infrastructure
Arctic Wolf tracked multiple CastleLoader clusters, including:
- Urutyka (PowerShell stagers, NetSupport RAT)
- Garrigin (NSIS installers masquerading as Edge updates)
- Noidret (Node.js-based wallet spoofers)
Indicators of compromise (IoCs) include domains like pub-6728b11f74fd435f926ed25c5f2952bb.r2.dev (Urutyka download server) and IPs such as 91.92.33.167 (Lobshot C2). Malicious files, including walletspoofer.exe and traffic1.exe, were observed in ProgramData and AppData directories.
### Defensive Recommendations (For Security Teams)
- Block listed infrastructure at DNS, firewall, and endpoint layers.
- Monitor unusual activity from PowerShell, Node.js, and Python in user-writable locations.
- Enable PowerShell logging and investigate Mark-of-the-Web (MOTW) removal.
- Restrict unsigned binaries in sensitive directories.
- Review browser extension permissions for unauthorized changes.
The campaign underscores the growing threat of crypto-focused malware, where attackers exploit human trust rather than technical flaws to compromise digital assets.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
756
Cyber Attack
01 Jun 2026 • Exodus
Electrum, Exodus, Ledger and Trezor: Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain
735
CRITICAL-21
ELEEXOLEDTRE1784199019
New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain
Security researchers at SlowMist have uncovered a sophisticated macOS-focused infostealer designed to harvest credentials, wallet databases, and session data for offline cryptocurrency theft. Detected by the MistEye monitoring system, the malware casts a wide net, extracting sensitive information from Apple Keychain, Safari and Chromium browsers, Telegram Desktop, Apple Notes, and multiple wallet applications including Electrum, Exodus, Atomic, Wasabi, Monero, Bitcoin Core, Ledger Live, and Trezor Suite.
The malware’s primary threat lies in its ability to pair stolen wallet databases with potential unlocking material, such as passwords from Keychain or browser stores. While most wallet apps encrypt data locally, attackers can test harvested credentials against exfiltrated wallet files in an isolated environment, bypassing the limitations of online password-guessing attacks. SlowMist demonstrated this by successfully decrypting Atomic Wallet data using a password obtained from the victim’s Keychain. Once a wallet’s recovery phrase or private key is extracted, simply reinstalling the app or changing its password offers no protection.
The malware also employs social engineering tactics, including a fake "Google API Connector" update prompt to capture the victim’s macOS password. It validates credentials using the `dscl` authentication utility, ensuring attackers obtain the correct login details. Additionally, it targets Chrome Safe Storage secrets from Keychain, which can decrypt stored browser logins and cookies.
Telegram users face a separate risk: the stealer copies the `tdata` directory, containing encryption keys and session state. In lab tests, restoring these files on a compatible Mac immediately granted access to the victim’s account without requiring SMS codes or two-factor authentication effectively hijacking an active session. Stolen `tdata` artifacts could also be converted into programmable Telegram API sessions, enabling full chat access.
For Ledger Live and Trezor Suite users, the malware deploys phishing pages disguised as legitimate wallet applications. After removing the real software, it installs lookalike WebView loaders that connect to attacker-controlled sites, tricking victims into entering recovery phrases or PINs under the guise of trusted desktop apps.
The campaign highlights how infostealers exploit the interplay between credentials, encrypted local stores, and user trust. While a stolen wallet database alone may be secure, pairing it with Keychain secrets and reused passwords creates a portable target for offline decryption. Indicators of compromise (IOCs) include malicious domains and IP addresses linked to the phishing infrastructure.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MAY 2026
756
APRIL 2026
756
MARCH 2026
755
FEBRUARY 2026
755
JANUARY 2026
755
DECEMBER 2025
755
NOVEMBER 2025
755
OCTOBER 2025
755
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Exodus ??
What was Exodus's A.I Rankiteo Cyber Score in August 2026 ??
What was Exodus's A.I Rankiteo Cyber Score in July 2026 ??
What was Exodus's A.I Rankiteo Cyber Score in June 2026 ??
What was Exodus's A.I Rankiteo Cyber Score in May 2026 ??
What was Exodus's A.I Rankiteo Cyber Score in April 2026 ??
What was Exodus's A.I Rankiteo Cyber Score in March 2026 ??
What was Exodus's A.I Rankiteo Cyber Score in February 2026 ??
What was Exodus's A.I Rankiteo Cyber Score in January 2026 ??
What was Exodus's A.I Rankiteo Cyber Score in December 2025 ??
What was Exodus's A.I Rankiteo Cyber Score in November 2025 ??
What was Exodus's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Exodus's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Exodus ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Exodus's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?