
Cybercriminals have been caught using a tampered installer for the Exodus cryptocurrency wallet to plant a full remote access trojan. The program looks close enough to the real wallet, but it is designed so its window never appears.
The campaign reached victims through disguised files. One route used a fake PDF ending in . pdf.
js, while another hid a JavaScript file in a ZIP archive. Opening the lure displayed a real decoy document while silently installing the altered wallet. Researchers at Huntress identified the activity across four unrelated protected organizations between late July and mid-August 2026.
Three compromises occurred within 85 minutes, showing how quickly the operation could be reused against targets. The risk goes well beyond stolen coins. The hidden payload can take browser passwords and cookies, run commands, move files, provide remote desktop access, and turn a compromised computer into a proxy.
That combination can support account takeover, surveillance,…
➪ Continue reading the full article on cybersecuritynews.com









