Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Exodus

Exodus Vendor Cyber Rating & Cyber Score

exodus.com

Exodus is a secure user-friendly crypto wallet where you can store, manage and swap all of your blockchain assets in one place. We are a one hundred percent remote company with people working for us across 44+ countries. We offer our team location autonomy and the option to choose their own hours. Come join us help half of the world exit the traditional financial system!


Exodus A.I CyberSecurity Scoring

Exodus
Company Information
Website:https://www.exodus.com
Employees number:285
Number of followers:16,291
NAICS:52
Industry Type:Financial Services
Homepage:exodus.com
Exodus Risk Score (AI oriented)
Between 650 and 699
logo
ExodusFinancial Services
Updated:
02/09/2026
665/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Exodus Global Score (TPRM)
xxxx
logo
ExodusFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

ExodusWeak
Current Score
665B (WEAK)
01000
4 incidents
-31.33 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
665Before Incident
AUGUST 2026
715Before Incident
Cyber Attack
18 Aug 2026Exodus
Exodus, Organization 3 and Organization 2: Trojanized Exodus Wallet Installer Deploys RAT to Steal Browser Credentials and Cookies

Sophisticated Malware Campaign Abuses Trojanized Exodus Wallet Installer to Deploy Modular RAT

664After Incident
CRITICAL-51
EXOWOR1788326823
Sophisticated Malware Campaign Abuses Trojanized Exodus Wallet Installer to Deploy Modular RAT A stealthy malware campaign has exploited a trojanized installer for the legitimate Exodus cryptocurrency wallet to distribute a modular remote access trojan (RAT) designed for long-term interactive access rather than immediate cryptocurrency theft. Discovered by Huntress between late July and mid-August 2026, the campaign compromised four unrelated organizations, with three victims infected within 85 minutes on August 18 using an installer created just a day prior. ### Attack Vectors and Execution The intrusion begins with JavaScript-based lures disguised as either: - A PDF document (with a `.pdf.js` double extension, appearing harmless when Windows hides file extensions). - A software update contained in a ZIP archive. In both cases, opening the file triggers Windows Script Host, displays a legitimate decoy document (hosted on trusted infrastructure), and silently installs a malicious MSI package via `msiexec`. A second observed method involved a ZIP file with a JavaScript "update," executed directly from Explorer’s compressed-folder view, leaving a temporary path with a `.zip.116\` fragment. ### Evasion and Payload Delivery The MSI masquerades as "Background Service" from "Apple Inc." and installs a real copy of Exodus Wallet (v24.33.4) under `%APPDATA%\ExdBackupTool\`. At the time of analysis, the 201 MB package had zero detections on VirusTotal, leveraging the wallet’s legitimacy to evade detection. Only three of the wallet’s 1,973 files were modified: - One patch prevents Electron windows from appearing, leaving the wallet running invisibly without a taskbar entry. - Another loads a 50 MB JavaScript component that decrypts and memory-maps a 10 MB Windows RAT without writing it to disk. ### RAT Capabilities and Command-and-Control The decrypted RAT includes six modules for: - Remote command execution - File operations - Script execution - SOCKS proxying - Hidden VNC access - Browser data theft (Chrome, Edge, Firefox targeting passwords, cookies, autofill, and extensions) Notably, the malware wipes cookies to force reauthentication, potentially enabling attackers to capture new sessions. Instead of traditional C2 infrastructure, it uses Azure Table Storage as a dead drop, blending malicious traffic with legitimate Microsoft cloud services to evade network blocking. ### Persistence and Defense Evasion Persistence is maintained via a scheduled task (`ExdBackupTool`) that relaunches the invisible `Exodus.exe` hourly. A related task (`INetHealth`) repeatedly clears Windows proxy settings, likely to bypass enterprise proxy inspection. The RAT retrieves the user’s Internet Explorer proxy configuration before initiating communications. ### Impact and Indicators of Compromise (IOCs) Organizations should treat detections as full interactive compromises, given the RAT’s ability to enable lateral movement, hidden VNC access, and SOCKS proxying. Key IOCs include: - Installer: `jn0101.msi` (SHA256: `c513a7346484ee69a2931c4a89956ee50aa63e4366ef989315e669d8f10d7485`) - Install directory: `%APPDATA%\ExdBackupTool\` - Trojanized files: Modified `app.asar` (3 of 1,973 files altered) - Scheduled tasks: `ExdBackupTool`, `INetHealth` - Artifacts: `%TEMP%\<guid>.tmp.node`, `debug.log` (attacker build artifact) The campaign’s rapid payload rebuilds and targeted delivery suggest an active, evolving operation rather than opportunistic malware reuse.
INCIDENT DETAILS -
TYPE
Malware Campaign
MOTIVATION
Long-term interactive access, lateral movement, data theft
IMPACT
Data Compromised: Browser data (passwords, cookies, autofill, extensions), potential session hijackingSystems Affected: Windows systems with Exodus Wallet installerOperational Impact: Full interactive compromise, potential lateral movement, hidden VNC access, SOCKS proxyingIdentity Theft Risk: High (browser data theft, session hijacking)
DATA BREACH
Type Of Data Compromised: Browser data (passwords, cookies, autofill, extensions), session dataSensitivity Of Data: High (personally identifiable information, authentication tokens)Personally Identifiable Information: Yes (browser data, session tokens)
Cyber Attack
18 Aug 2026Exodus
Exodus and Crypto.com: Operation ASTERIX Uses Vishing and Fake Crypto Wallet Apps to Steal Seed Phrases

Operation ASTERIX: AI-Powered Crypto Fraud Campaign

664After Incident
CRITICAL-51
CRYEXO1787041502
Operation ASTERIX: AI-Powered Crypto Fraud Campaign Exposed Researchers at Rapid7 uncovered Operation ASTERIX, a sophisticated cryptocurrency fraud campaign that combined account enumeration, branded phishing, vishing (voice phishing), and trojanized wallet software to steal victims’ recovery phrases. The operation, named after the Asterisk telephony platform found in its infrastructure, employed a multi-stage social-engineering pipeline to target users with precision. ### How the Attack Worked 1. Target Validation & Enrichment - The threat actor compiled 885,000 phone numbers from datasets linked to Germany, Hong Kong, Bulgaria, the UK, the US, Canada, Ledger users, and fintech services. - A Go-based checker validated 43,066 Crypto.com accounts from a German dataset of 316,002 numbers, achieving a 13.6% hit rate. - The attacker used residential proxies, retry logic, and lead databases to identify high-value targets those likely to own crypto wallets or exchange accounts. 2. Multi-Channel Phishing & Vishing - Victims received branded phishing emails impersonating platforms like Crypto.com and Binance, followed by automated voice calls (using Asterisk, 3CX, and custom scripts) citing personal details, support cases, and verification codes. - The callers referenced real verification codes sent via email, creating a false sense of legitimacy. - Victims were tricked into installing fake wallet updates or submitting recovery phrases under the guise of security checks. 3. Trojanized Wallet Software - The campaign distributed counterfeit versions of Trezor Suite, Ledger Live, and Exodus for macOS and Windows. - The fake Trezor Suite (packaged in Electron) killed the legitimate app, displayed a convincing replica, and prompted victims for 12-, 18-, 20-, or 24-word recovery phrases. - Stolen data including recovery phrases, passphrases, and IP addresses was exfiltrated to a Telegram bot. - The Ledger Live variant included clipboard hijacking, replacing copied crypto addresses with attacker-controlled ones. - The Exodus installer used a trojanized JavaScript component to fetch malicious payloads post-installation. 4. AI Integration in Malware Development - The exposed server revealed LLM session logs, shell history, and source code, showing the attacker used GitHub Copilot and Claude Code for: - Managing lead lists - Configuring validation scripts - Troubleshooting network issues - Packaging Electron apps - When models refused to assist with obfuscation or payload hosting, the operator switched to Kimi AI and attempted jailbreak prompts to bypass safeguards. - This marks one of the first documented cases of AI being actively integrated into a criminal malware-development pipeline. ### Infrastructure & Persistence - The attacker’s server hosted multiple ports for different functions: - Port 8000: Fake wallet archives - Port 8080: Installers and LaunchAgent files - Port 5000: Password-protected Flask panels - Port 9000: Installation telemetry - Port 8090: Auxiliary control - On macOS, persistence was achieved via LaunchAgents (`com.trezormovement.agent`, `io.trezor.agent`), ensuring the malware relaunched at login. ### Impact & Response - Rapid7 observed 20 successful lead lookups and six phishing emails over two weeks, indicating a targeted, operator-led campaign rather than mass phishing. - The company notified affected providers and authorities, including Apple’s security team, while parts of the infrastructure remained active. - Indicators of compromise (IOCs) including Telegram bot tokens, LaunchAgent labels, and malicious file hashes were published on Rapid7’s GitHub. Operation ASTERIX highlights the growing sophistication of crypto fraud, blending AI-driven development, multi-channel social engineering, and trojanized software to maximize success rates.
INCIDENT DETAILS -
TYPE
Cryptocurrency Fraud, Phishing, Vishing, Malware Distribution
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Recovery phrases, passphrases, IP addresses, crypto wallet credentialsmacOSWindowsOperational Impact: Installation of trojanized wallet software, clipboard hijacking, unauthorized access to crypto walletsBrand Reputation Impact: Potential reputational damage to Crypto.com, Binance, Trezor, Ledger, and Exodus due to impersonationIdentity Theft Risk: High (recovery phrases and passphrases stolen)Payment Information Risk: High (crypto wallet credentials and clipboard hijacking for crypto address replacement)
DATA BREACH
Recovery phrasesPassphrasesIP addressesCrypto wallet credentialsNumber Of Records Exposed: 43,066 validated accounts (potentially more)Sensitivity Of Data: High (direct access to crypto wallets)Data Exfiltration: Yes (to Telegram bot)Personally Identifiable Information: Recovery phrases, passphrases, IP addresses
JULY 2026
736Before Incident
Cyber Attack
28 Jul 2026Exodus
Exodus and Trezor: Hackers Are Using Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions

CastleLoader Campaign Expands with Crypto Wallet Spoofing and Browser Session Theft

714After Incident
CRITICAL-22
EXOTRE1785241575
CastleLoader Campaign Expands with Crypto Wallet Spoofing and Browser Session Theft Cybercriminals behind the CastleLoader malware campaign are escalating attacks by deploying sophisticated tools to steal cryptocurrency recovery phrases, login credentials, and active browser sessions. Researchers at Arctic Wolf identified the latest evolution of the campaign, which now targets digital asset holders with fake wallet interfaces and malicious browser extensions. ### How the Attack Works The operation begins with fake software installers and ClickFix-style prompts, tricking victims into executing harmful PowerShell commands. Once executed, the CastleLoader malware retrieves additional payloads including Python injectors and Rust-based stealers without leaving obvious traces, complicating early detection. Key components of the campaign include: - NeedleStealer (Rust-based wallet spoofer): Mimics popular wallet brands (Ledger, Trezor, Exodus) with polished fake interfaces designed to trick users into entering their recovery seed phrases. Unlike traditional exploits, this attack relies on social engineering rather than software vulnerabilities. - Golang-based malicious browser extensions: Disguised as legitimate tools (e.g., ad blockers), these extensions hijack active browser sessions, allowing attackers to bypass passwords and access accounts without triggering new login challenges. - Node.js-based injectors: Used in the Noidret campaign, these tools unpack malware in the ProgramData directory alongside legitimate binaries, blending in with normal system activity. ### Why This Matters - Irreversible wallet theft: Unlike passwords, recovery phrases cannot be reset once stolen, attackers gain permanent control of a victim’s cryptocurrency holdings. - Session hijacking risks: Stolen browser tokens enable attackers to access accounts without passwords, evading security measures like two-factor authentication. - Evolving tactics: The campaign reflects a shift from general credential theft to specialized crypto-targeting, leveraging social engineering (fake updates, misleading installers) to deceive users. ### Campaign Clusters & Infrastructure Arctic Wolf tracked multiple CastleLoader clusters, including: - Urutyka (PowerShell stagers, NetSupport RAT) - Garrigin (NSIS installers masquerading as Edge updates) - Noidret (Node.js-based wallet spoofers) Indicators of compromise (IoCs) include domains like pub-6728b11f74fd435f926ed25c5f2952bb.r2.dev (Urutyka download server) and IPs such as 91.92.33.167 (Lobshot C2). Malicious files, including walletspoofer.exe and traffic1.exe, were observed in ProgramData and AppData directories. ### Defensive Recommendations (For Security Teams) - Block listed infrastructure at DNS, firewall, and endpoint layers. - Monitor unusual activity from PowerShell, Node.js, and Python in user-writable locations. - Enable PowerShell logging and investigate Mark-of-the-Web (MOTW) removal. - Restrict unsigned binaries in sensitive directories. - Review browser extension permissions for unauthorized changes. The campaign underscores the growing threat of crypto-focused malware, where attackers exploit human trust rather than technical flaws to compromise digital assets.
INCIDENT DETAILS -
TYPE
Malware CampaignCryptocurrency TheftSession Hijacking
MOTIVATION
Financial gainCryptocurrency theft
IMPACT
Financial Loss: Irreversible wallet theft leading to permanent loss of cryptocurrency holdingsCryptocurrency recovery phrasesLogin credentialsBrowser session tokensUser systems with installed malwareBrowser extensionsIdentity Theft Risk: High (due to stolen recovery phrases and session tokens)Payment Information Risk: High (cryptocurrency wallets)
DATA BREACH
Cryptocurrency recovery phrasesLogin credentialsBrowser session tokensSensitivity Of Data: High (irreversible loss of cryptocurrency access)
JUNE 2026
756Before Incident
Cyber Attack
01 Jun 2026Exodus
Electrum, Exodus, Ledger and Trezor: Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft

New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain

735After Incident
CRITICAL-21
ELEEXOLEDTRE1784199019
New macOS Infostealer Targets Cryptocurrency Wallets with Offline Attack Chain Security researchers at SlowMist have uncovered a sophisticated macOS-focused infostealer designed to harvest credentials, wallet databases, and session data for offline cryptocurrency theft. Detected by the MistEye monitoring system, the malware casts a wide net, extracting sensitive information from Apple Keychain, Safari and Chromium browsers, Telegram Desktop, Apple Notes, and multiple wallet applications including Electrum, Exodus, Atomic, Wasabi, Monero, Bitcoin Core, Ledger Live, and Trezor Suite. The malware’s primary threat lies in its ability to pair stolen wallet databases with potential unlocking material, such as passwords from Keychain or browser stores. While most wallet apps encrypt data locally, attackers can test harvested credentials against exfiltrated wallet files in an isolated environment, bypassing the limitations of online password-guessing attacks. SlowMist demonstrated this by successfully decrypting Atomic Wallet data using a password obtained from the victim’s Keychain. Once a wallet’s recovery phrase or private key is extracted, simply reinstalling the app or changing its password offers no protection. The malware also employs social engineering tactics, including a fake "Google API Connector" update prompt to capture the victim’s macOS password. It validates credentials using the `dscl` authentication utility, ensuring attackers obtain the correct login details. Additionally, it targets Chrome Safe Storage secrets from Keychain, which can decrypt stored browser logins and cookies. Telegram users face a separate risk: the stealer copies the `tdata` directory, containing encryption keys and session state. In lab tests, restoring these files on a compatible Mac immediately granted access to the victim’s account without requiring SMS codes or two-factor authentication effectively hijacking an active session. Stolen `tdata` artifacts could also be converted into programmable Telegram API sessions, enabling full chat access. For Ledger Live and Trezor Suite users, the malware deploys phishing pages disguised as legitimate wallet applications. After removing the real software, it installs lookalike WebView loaders that connect to attacker-controlled sites, tricking victims into entering recovery phrases or PINs under the guise of trusted desktop apps. The campaign highlights how infostealers exploit the interplay between credentials, encrypted local stores, and user trust. While a stolen wallet database alone may be secure, pairing it with Keychain secrets and reused passwords creates a portable target for offline decryption. Indicators of compromise (IOCs) include malicious domains and IP addresses linked to the phishing infrastructure.
INCIDENT DETAILS -
TYPE
Infostealer Malware
MOTIVATION
Financial Gain
IMPACT
CredentialsWallet DatabasesSession DataEncryption KeysRecovery PhrasesPrivate KeysBrowser LoginsCookiesmacOSIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
CredentialsWallet DatabasesSession DataEncryption KeysRecovery PhrasesPrivate KeysBrowser LoginsCookiesSensitivity Of Data: HighLocal Wallet EncryptionChrome Safe StorageWallet DatabasesKeychain DataBrowser DataTelegram `tdata` DirectoryApple NotesRecovery PhrasesPrivate KeysBrowser LoginsCookies
MAY 2026
756Before Incident
APRIL 2026
756Before Incident
MARCH 2026
755Before Incident
FEBRUARY 2026
755Before Incident
JANUARY 2026
755Before Incident
DECEMBER 2025
755Before Incident
NOVEMBER 2025
755Before Incident
OCTOBER 2025
755Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Exodus ?
?
What was Exodus's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Exodus's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Exodus's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Exodus's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Exodus's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Exodus's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Exodus's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Exodus's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Exodus's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Exodus's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Exodus's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Exodus's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Exodus ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Exodus's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?