A tampered Exodus Wallet 24.33.4 installer delivers a modular RAT while installing a functional but UI-suppressed wallet. The RAT uses memory-resident reflective PE loading via JavaScript FFI using the koffi library, with an AES-256-CBC encrypted 10 MB payload. C2 runs over Azure Table Storage as a dead drop mechanism. Six plugin DLLs provide remote command execution, file management, browser credential and cookie theft, SOCKS proxy, hidden VNC, and LuaJIT script execution. Persistence is maintained via Task Scheduler COM API with an INetHealth task clearing proxy settings to ensure direct C2 egress.
Modular RAT
2 posts
The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT Abyssos Modular RAT Analysis | ThreatLabz Abyssos is a modular remote administration tool written in C++ identified by Zscaler ThreatLabz in late June 2026. It uses LLVM-based obfuscation, anti-analysis checks, and a custom AES-GCM encrypted TCP protocol for C2 communication. The RAT supports a wide range of capabilities including VNC, keylogging, clipboard interception, file exfiltration, process management, UAC bypass, browser session hijacking, and a modular plugin system for credential harvesting and network scanning.