The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT
A tampered Exodus Wallet 24.33.4 installer delivers a modular RAT while installing a functional but UI-suppressed wallet. The RAT uses memory-resident reflective PE loading via JavaScript FFI using the koffi library, with an AES-256-CBC encrypted 10 MB payload. C2 runs over Azure Table Storage as a dead drop mechanism. Six plugin DLLs provide remote command execution, file management, browser credential and cookie theft, SOCKS proxy, hidden VNC, and LuaJIT script execution. Persistence is maintained via Task Scheduler COM API with an INetHealth task clearing proxy settings to ensure direct C2 egress.
- domainapi[.]27inbarbadostours[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapi[.]504guaratv[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapi[.]b2compages[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapi[.]elcaminodesermadre[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapi[.]ideasnation[.]netConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapi[.]jyfgarriga[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapi[.]onemkscleaningsolutions[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapi[.]rezperfect[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapi[.]shopfoora[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapi[.]shuyinla[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapp[.]bcntextilrep[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapp[.]conviertenoensi[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapp[.]geutex[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapp[.]micheladafestelpaso[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapp[.]rtpsenior4djp[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapp[.]sentiented[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapp[.]shuchipharmacy[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapp[.]springstore[.]netConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainapp[.]stateyatra[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainauth[.]auravp3[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainauth[.]clubvp3[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainauth[.]esalesrep[.]netConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainauth[.]h-dsf1034[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainauth[.]nailedbynakole[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainauth[.]SecureSwallow[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainauth[.]shuchimed[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainauth[.]SpeakToWinClients[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domaincdn[.]baraldes[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domaincdn[.]cobraporganardinero[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domaincdn[.]estudiod2[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domaincdn[.]jiyaoglass[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domaincdn[.]planningportfolioweek[.]orgConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domaincdn[.]ShinoZen[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domaincdn[.]snsafirieik[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domaincdn[.]SpeakToGrowBiz[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domaincdn[.]yenoox[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainlgapistorage123[.]table[.]core[.]windows[.]netAzure Table Storage C2 dead drop. Table ftable434, PartitionKey is bot ID, T_ rows are tasking, R_ rows are results, tasks deleted after reading
- domainstatic[.]AriesGlobalSoft[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainstatic[.]cistecca360[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainstatic[.]emialvarez[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainstatic[.]gompl-rggsrve[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainstatic[.]metodorace[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainstatic[.]premios-king[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainstatic[.]suplenation[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainstatic[.]TryTheCrowdMakers[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainstatic[.]TurboLeadSlab[.]comConfigured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- domainus05[.]orgDelivery domain that 302-redirects to a search-ms URI, serving WebDAV-hosted payload files
- domainwinapi[.]table[.]core[.]windows[.]netSecond Azure Table Storage C2 account, same dead drop scheme, minimal activity observed
- filename%APPDATA%\ExdBackupTool\Per-user install directory for the tampered Exodus bundle; genuine Exodus installs to %LOCALAPPDATA%\exodus
- filenameC:\123\exodusUpdaterAttacker build path leaked in debug.log, a genuine Chromium log from the attacker's test run dated 2026-06-10, shipped by mistake in the installer
- filenameC:\Users\root\node_modules\@intelcorp\wmi-native-module\build\Release\wmi_native_module.pdbPDB path leaked in a second file, revealing attacker build user is root on Windows with the @intelcorp npm scope
- filenameC:\Windows\Installer\SourceHash{4046AD2B-3831-4011-AEAD-D98C5C9FD1EF}MSI source-hash file that survives removal of the install directory
- filename%TEMP%\jg0384.msiMalicious MSI written to TEMP by the JavaScript dropper in the second campaign
- filename%TEMP%\jn0101.msiMalicious MSI written to TEMP by the JavaScript dropper in the first campaign; cleanup attempt fails because setTimeout does not exist in WSH
- ip35[.]212[.]159[.]20Delivery server hosting the MSI and resolving us05.org, used by both delivery paths
- mutexExodusHelperNamed mutex created by the in-memory payload as a single-instance guard to prevent duplicate execution
- npm_package@intelcorp/wmi-native-moduleNPM scope impersonating Intel, used for COM and WMI host reconnaissance; imports ole32, OLEAUT32, PROPSYS
- registry_keyHKCU:\Software\Microsoft\Windows\CurrentVersion\InternetSettingsProxy settings registry key cleared by INetHealth scheduled task (ProxyEnable, ProxyServer, AutoConfigURL) to force direct C2 egress
- sha2562f47cfbb13f7a8a2d30d287f4ddd974fabea6762ad9781d438eb53da41b4582ddll4_socks.dll, RAT SOCKS proxy module turning host into a network relay, 553,984 bytes in memory
- sha2565274e93e35586a341d14b50cdf8413d59c51fd94f32bdc70bfdfb77198367603dll4_script.dll, RAT LuaJIT engine enabling Lua code execution, injection, registry CRUD, DPAPI, raw sockets, token queries, 3,547,136 bytes in memory
- sha2565fe753945da0eaac2c2ef3845cba603dea6c3e8529fa581d7e0192f8af60391adll4_vnc.dll, RAT hidden VNC module creating a second invisible desktop and relaunching Chrome or Edge against victim profile copy, 2,277,376 bytes in memory
- sha2567e74f6e2eb7a17a8d25bb322a14c392c9d92c6ab29fc66b50221da134a1bdba8dll4_browser.dll, RAT browser credential stealer targeting Chrome, Edge, Firefox; steals passwords, cookies, autofill plus cookie wiper to force re-login, 2,125,824 bytes in memory
- sha25684437d4239d2a3d90c4faad0a3c0630b2f61a40f7bbd12109bef74d7613b8756dll4_cmd.dll, RAT remote shell module with STDIN/STDOUT pipes over WinHTTP, 319,488 bytes in memory
- sha2568c3b41ea5a85778145a6e5772bfee2eb0f8b027d0af199fb71a76dfb8bb29e5aDecrypted modular RAT payload hash, 10,021,392 bytes PE32+, compiled 2026-08-17 15:18:13 UTC, memory-resident only, not on VirusTotal
- sha256c513a7346484ee69a2931c4a89956ee50aa63e4366ef989315e669d8f10d7485Malicious MSI installer hash, 210,767,872 bytes, unsigned, 0/76 on VirusTotal at time of analysis
- sha256fdd376562aac4be64fb635546a61e1912ff2c353360db73d2c553dcbb5a44f54dll4_fileman.dll, RAT file manager module enabling browse, move, delete, mkdir, and HTTP transfer for upload/download, 352,256 bytes in memory
- urlhxxp://35[.]212[.]159[.]20/jn0101[.]msiMSI download location used by the JavaScript dropper in the first campaign
Detection / Hunteropenrouter
What Happened
A modified installer for the Exodus cryptocurrency wallet was used to secretly install a remote access tool on computers at four organizations. The installer places a real, working copy of the wallet on the computer but prevents its window from ever opening, so the user never knows it is there. The hidden tool can steal saved browser passwords and login sessions, remotely view and control the desktop, route internet traffic through the compromised computer, and run commands remotely. Organizations should check for the specific file paths, scheduled task names, and other indicators listed in this report. Anyone who finds these indicators should treat the computer as fully compromised, revoking all active login sessions rather than just changing passwords, since stolen session tokens survive password changes.
Key Takeaways
- Tampered Exodus Wallet 24.33.4 installer delivers a modular RAT with six capabilities: remote shell, file management, browser credential theft, SOCKS proxy, hidden VNC, and LuaJIT script execution
- Payload is memory-resident only, loaded via reflective PE loading in JavaScript using koffi FFI library with AES-256-CBC encrypted 10 MB blob; the decrypted PE32+ never touches disk
- C2 uses Azure Table Storage as a dead drop mechanism (lgapistorage123.table.core.windows.net), making network-level blocking difficult as table.core.windows.net is legitimate Microsoft infrastructure not on blocklists
- Persistence via Task Scheduler COM API with ExdBackupTool task launching Exodus.exe hourly and INetHealth task clearing proxy settings to bypass corporate web proxies that could inspect or block C2 traffic
- Three delivery methods observed: .pdf.js double extension, ZIP archive containing .js file, and search-ms WebDAV protocol handler; attacker launches Exodus.exe through explorer.exe to make the process tree appear user-initiated
Affected Systems
- Windows endpoints with Windows Script Host, Msiexec, and Task Scheduler
- Exodus Wallet 24.33.4 (tampered installer)
- Google Chrome, Microsoft Edge, Mozilla Firefox (browser credential theft targets)
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: User opens .pdf.js file or ZIP archive containing JavaScript, delivered via browser download or WebDAV search-ms protocol handler
- Execution: JavaScript downloads MSI to %TEMP% and runs it via msiexec /quiet /norestart; a real decoy PDF opens simultaneously from a legitimate CDN or university site
- Installation: MSI installs to %APPDATA%\ExdBackupTool\ with genuine Exodus 24.33.4 plus three modified files; exodus_patch.js suppresses all windows, keystorage.js contains the encrypted in-memory payload
- Persistence: Scheduled task ExdBackupTool created via Task Scheduler COM API launches Exodus.exe hourly; INetHealth task clears proxy settings to ensure direct C2 egress
- C2: In-memory modular RAT communicates via Azure Table Storage dead drop using WebSocket/WinHTTP; tasking rows prefixed T_, results prefixed R_, tasks deleted after reading
- Impact: Browser credential and cookie theft, hidden VNC for interactive desktop access, SOCKS proxy for network pivoting, file exfiltration, remote command execution, and LuaJIT script execution with DPAPI and token access
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
The article provides behavioral indicators and structural detection guidance (deobfuscation methodology, process tree patterns, registry modifications, network indicators) but no formal YARA, Sigma, Snort, Suricata, KQL, SPL, or EQL rules.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | Process creation, file write, and scheduled task creation events are visible to EDR. The payload is memory-resident and never writes to disk. The process tree appears normal with Exodus.exe parented to explorer.exe. The wallet generates legitimate traffic to genuine Exodus API endpoints. |
| Network Visibility | Medium | Outbound HTTPS to Azure Table Storage endpoints (*.table.core.windows.net) is visible in network logs but may appear as legitimate Azure usage. WebSocket C2 over WinHTTP may be visible in proxy logs. The 45 configured C2 hosts were not contacted during detonation, so no network signatures for those. |
| Detection Difficulty | Hard | The payload is memory-resident with no disk artifacts. C2 uses legitimate Azure Table Storage infrastructure that is not on blocklists. The process tree appears normal with explorer.exe as parent. The scheduled task is created via Task Scheduler COM API rather than schtasks.exe, avoiding command-line detection. String obfuscation splits all strings into five-character chunks in a shuffled array with hex arithmetic indices, defeating grep and off-the-shelf deobfuscators. The wallet generates legitimate Exodus API traffic to real infrastructure. |
Required Log Sources
- Sysmon Event ID 1 (Process Create)
- Sysmon Event ID 3 (Network Connect)
- Sysmon Event ID 7 (Image Load)
- Sysmon Event ID 11 (File Create)
- Windows Task Scheduler Operational log
- Windows Application log (MSI installer events)
- EDR process telemetry with command-line capture
- Proxy or firewall logs for Azure Table Storage traffic
- DNS resolution logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Hunt for Exodus.exe running from a per-user AppData path rather than the legitimate install location under LocalAppData | Process creation events showing Exodus.exe with an executable path under %APPDATA%\ExdBackupTool\ | Execution | Low - legitimate Exodus installs to %LOCALAPPDATA%\exodus, not %APPDATA%\ExdBackupTool |
| Hunt for scheduled tasks created via the Task Scheduler COM API rather than schtasks.exe, which would appear as task creation events without a corresponding schtasks.exe process | Task Scheduler operational log showing task creation events correlated with process creation telemetry to identify tasks created without schtasks.exe on the command line | Persistence | Medium - legitimate administrative tools and group policy may use the COM API for task creation |
| Hunt for processes modifying Internet Settings registry keys to clear proxy configuration on a recurring schedule, indicating an operator working against Group Policy enforcement | Registry modification events targeting HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings with ProxyEnable set to 0 and ProxyServer or AutoConfigURL cleared | Persistence | Medium - proxy configuration changes may occur during legitimate IT administration or VPN client operation |
| Hunt for outbound connections to Azure Table Storage endpoints from workstation hosts that do not have a business need for Azure access, particularly connections using PUT and DELETE methods consistent with a dead drop pattern | Network connection logs and proxy logs showing HTTPS traffic to *.table.core.windows.net from non-server endpoints, with HTTP methods POST, PUT, GET, and DELETE matching the dead drop pattern | Command and Control | Medium - some legitimate applications use Azure Table Storage for data storage; correlation with the specific table name ftable434 and the PUT/DELETE pattern reduces false positives |
| Hunt for Electron applications running with active network connections but no visible window handle, which would indicate the BrowserWindow show method has been overridden as described in exodus_patch.js | Process telemetry showing Electron-based processes with established network connections but no corresponding window handle or visible UI element in the window station | Execution | High - many Electron applications run background services or tray applications without visible windows |
Control Gaps
- Hash-based detection (AV/EDR signatures) will not catch rebuilt variants as the builder produces new MSIs with different hashes; VirusTotal shows multiple zero-detection builds from the same builder
- Network-based detection may not flag Azure Table Storage C2 traffic in environments with legitimate Azure usage since table.core.windows.net is not on any blocklist
- Command-line-based detection for scheduled task creation will miss tasks created via the Task Scheduler COM API, which produces no schtasks.exe process to alert on
- The in-memory payload has no disk artifacts for file-scanning-based detection; the 10 MB PE32+ is decrypted and loaded entirely in process memory via reflective loading
- String-based detection fails because the obfuscator splits every string into five-character chunks stored in a shuffled array with hex arithmetic index expressions averaging 460 constants per lookup
Key Behavioral Indicators
- Exodus.exe running from %APPDATA%\ExdBackupTool\ with parent explorer.exe and no visible window
- Scheduled task named ExdBackupTool launching Exodus.exe hourly via svchost.exe at 42 minutes past the hour
- Scheduled task named INetHealth clearing Internet Settings proxy keys via PowerShell
- Mutex named ExodusHelper created by an Exodus.exe process
- MSI with ProductCode {4046AD2B-3831-4011-AEAD-D98C5C9FD1EF} and false metadata (Manufacturer: Apple Inc, Product: Background Service)
- msiexec.exe running from %TEMP% with /quiet /norestart flags
- JavaScript files with .js extension executed from %TEMP% or user download folders by Windows Script Host (wscript.exe)
- Exodus.exe making WebSocket connections to Azure Table Storage endpoints (*.table.core.windows.net)
- koffi npm package present in an Exodus Wallet installation bundle, as genuine Exodus does not bundle it
- Browser download (chrome.exe) directly launching .js files from the Downloads folder
False Positive Assessment
Low - The combination of artifacts (Exodus.exe from %APPDATA%\ExdBackupTool, no visible window, ExodusHelper mutex, ExdBackupTool and INetHealth scheduled tasks, MSI with false Apple Inc metadata) is highly specific and unlikely to match legitimate activity. The install path alone separates this from the real Exodus product, which installs to %LOCALAPPDATA%\exodus.
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Isolate affected hosts; hidden VNC and SOCKS proxy modules indicate full interactive access and potential lateral movement.
- Search all endpoints for scheduled tasks named ExdBackupTool and INetHealth and remove them; deleting files alone leaves an hourly task pointing at a path that no longer exists.
- Revoke active browser sessions and rotate credentials, not just passwords; the browser credential theft module steals session cookies that survive password changes.
- Search %TEMP% for MSI files matching the jn*.msi or jg*.msi pattern; the JavaScript dropper attempts cleanup via setTimeout which does not exist in Windows Script Host, so the MSI likely remains on disk.
Infrastructure Hardening
- Consider disabling the WebClient service where WebDAV is not required; this prevents the search-ms protocol handler from mounting remote shares as local search results.
- Evaluate blocking or alerting on Windows Script Host (wscript.exe or cscript.exe) execution from user download folders and %TEMP%.
- Consider alerting on outbound connections to Azure Table Storage endpoints (*.table.core.windows.net) from workstation hosts that do not have a documented business need for Azure access.
- Enable file extension visibility in Windows Explorer via Group Policy to defeat the .pdf.js double-extension technique.
- Consider monitoring for msiexec.exe executing from %TEMP% or %APPDATA% locations, particularly with /quiet /norestart flags.
User Protection
- Train users to treat any browser prompt asking to open Windows Explorer as suspicious; the search-ms protocol handler presents remote files as local search results.
- Educate users that legitimate software updates come from official vendor websites, not from documents or archives received via email or download.
- Remind users to verify file extensions before opening downloaded files; enabling extension visibility in Explorer is a system-level control that supports this.
Security Awareness
- Incorporate the .pdf.js double-extension technique into existing phishing awareness training; Windows hiding known extensions by default is the enabling condition.
- Consider adding the search-ms WebDAV social engineering technique to security awareness materials; it bypasses file download warnings by mounting remote content as local search results with no file copy required.
MITRE ATT&CK Mapping
Execution
Stealth
Defense Impairment
Credential Access
Command and Control
Additional IOCs
- Domains:
api[.]27inbarbadostours[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapi[.]504guaratv[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapi[.]b2compages[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapi[.]elcaminodesermadre[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapi[.]ideasnation[.]net- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapi[.]jyfgarriga[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapi[.]onemkscleaningsolutions[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapi[.]rezperfect[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapi[.]shopfoora[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapi[.]shuyinla[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapp[.]bcntextilrep[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapp[.]conviertenoensi[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapp[.]geutex[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapp[.]micheladafestelpaso[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapp[.]rtpsenior4djp[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapp[.]sentiented[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapp[.]shuchipharmacy[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapp[.]springstore[.]net- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainapp[.]stateyatra[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainauth[.]SecureSwallow[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainauth[.]SpeakToWinClients[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainauth[.]auravp3[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainauth[.]clubvp3[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainauth[.]esalesrep[.]net- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainauth[.]h-dsf1034[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainauth[.]nailedbynakole[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainauth[.]shuchimed[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domaincdn[.]ShinoZen[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domaincdn[.]SpeakToGrowBiz[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domaincdn[.]baraldes[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domaincdn[.]cobraporganardinero[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domaincdn[.]estudiod2[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domaincdn[.]jiyaoglass[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domaincdn[.]planningportfolioweek[.]org- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domaincdn[.]snsafirieik[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domaincdn[.]yenoox[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainstatic[.]AriesGlobalSoft[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainstatic[.]TryTheCrowdMakers[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainstatic[.]TurboLeadSlab[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainstatic[.]cistecca360[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainstatic[.]emialvarez[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainstatic[.]gompl-rggsrve[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainstatic[.]metodorace[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainstatic[.]premios-king[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domainstatic[.]suplenation[.]com- Configured C2 host in payload .rdata, not contacted during detonation; may be a compromised legitimate domain
- Urls:
hxxp://35[.]212[.]159[.]20/jn0101.msi- MSI download location used by the JavaScript dropper in the first campaignsearch-ms://displayname=Search Results in update (\\us05.org@8080)&crumb=&crumb=location:\\us05.org@8080\update- search-ms protocol handler URI served via HTTP 302 redirect from us05.org, mounts remote WebDAV share as local Windows Search Results
- File Hashes:
fdd376562aac4be64fb635546a61e1912ff2c353360db73d2c553dcbb5a44f54(SHA256) - dll4_fileman.dll, RAT file manager module enabling browse, move, delete, mkdir, and HTTP transfer for upload/download, 352,256 bytes in memory2f47cfbb13f7a8a2d30d287f4ddd974fabea6762ad9781d438eb53da41b4582d(SHA256) - dll4_socks.dll, RAT SOCKS proxy module turning host into a network relay, 553,984 bytes in memory84437d4239d2a3d90c4faad0a3c0630b2f61a40f7bbd12109bef74d7613b8756(SHA256) - dll4_cmd.dll, RAT remote shell module with STDIN/STDOUT pipes over WinHTTP, 319,488 bytes in memory5274e93e35586a341d14b50cdf8413d59c51fd94f32bdc70bfdfb77198367603(SHA256) - dll4_script.dll, RAT LuaJIT engine enabling Lua code execution, injection, registry CRUD, DPAPI, raw sockets, token queries, 3,547,136 bytes in memory7e74f6e2eb7a17a8d25bb322a14c392c9d92c6ab29fc66b50221da134a1bdba8(SHA256) - dll4_browser.dll, RAT browser credential stealer targeting Chrome, Edge, Firefox; steals passwords, cookies, autofill plus cookie wiper to force re-login, 2,125,824 bytes in memory5fe753945da0eaac2c2ef3845cba603dea6c3e8529fa581d7e0192f8af60391a(SHA256) - dll4_vnc.dll, RAT hidden VNC module creating a second invisible desktop and relaunching Chrome or Edge against victim profile copy, 2,277,376 bytes in memory
- Registry Keys:
HKCU:\Software\Microsoft\Windows\CurrentVersion\Internet Settings- Proxy settings registry key cleared by INetHealth scheduled task (ProxyEnable, ProxyServer, AutoConfigURL) to force direct C2 egress{C4A1D8F2-3E5B-4C72-9A6D-1B8F0E27A3C9}- MSI UpgradeCode present in reversed-GUID form under HKLM\SOFTWARE\Classes\Installer\UpgradeCodes
- File Paths:
%APPDATA%\ExdBackupTool\- Per-user install directory for the tampered Exodus bundle; genuine Exodus installs to %LOCALAPPDATA%\exodus%TEMP%\jn0101.msi- Malicious MSI written to TEMP by the JavaScript dropper in the first campaign; cleanup attempt fails because setTimeout does not exist in WSH%TEMP%\jg0384.msi- Malicious MSI written to TEMP by the JavaScript dropper in the second campaignC:\123\exodusUpdater- Attacker build path leaked in debug.log, a genuine Chromium log from the attacker's test run dated 2026-06-10, shipped by mistake in the installerC:\Users\root\node_modules\@intelcorp\wmi-native-module\build\Release\wmi_native_module.pdb- PDB path leaked in a second file, revealing attacker build user is root on Windows with the @intelcorp npm scopeC:\Windows\Installer\SourceHash{4046AD2B-3831-4011-AEAD-D98C5C9FD1EF}- MSI source-hash file that survives removal of the install directory
- Command Lines:
- Purpose: Install malicious MSI payload silently without prompts or restart | Tools:
msiexec.exe| Stage: Execution |msiexec /i ... /quiet /norestart - Purpose: Execute encoded PowerShell payload via hidden console window | Tools:
conhost.exe,powershell.exe| Stage: Persistence |conhost.exe --headless powershell -e - Purpose: Gather system information with UTF-8 console encoding for clean output parsing | Tools:
cmd.exe| Stage: Reconnaissance |cmd.exe /c chcp 65001 >nul 2>&1 & systeminfo - Purpose: Clear Windows Internet proxy settings to force direct C2 egress bypassing corporate proxies | Tools:
powershell.exe| Stage: Persistence |Set-ItemProperty -path ... ProxyEnable -value 0 - Purpose: Launch Exodus.exe via explorer.exe to re-parent the process and drop the elevated msiexec token | Tools:
explorer.exe| Stage: Execution |explorer.exe ... Exodus.exe
- Purpose: Install malicious MSI payload silently without prompts or restart | Tools:
- Other:
SXD9WPcPiVBt76Y09wg/YLDTk/uOOrKWbSmMSrystI8=- Hardcoded AES-256-CBC encryption key used to decrypt the 10 MB in-memory payload, stored in the same file as the ciphertext3ssyBCFqLnkYA2aJ70rxRw==- Hardcoded AES-256-CBC initialization vector paired with the key above\\us05.org@8080\update- WebDAV share presented to victims via the search-ms protocol handler as a Windows Search Results windowExdBackupTool- Scheduled task name created via Task Scheduler COM API, launches Exodus.exe from %APPDATA% hourly at 42 minutes past the hourINetHealth- Scheduled task name that clears proxy settings on a schedule to keep C2 egress direct, persists against Group Policy proxy enforcementManufacturer=Apple Inc; ProductName=Background Service; ProductVersion=43.4.30- False MSI metadata, all fields are fiction; real manufacturer and product unknown