← Back to feed
Threat Actors & CampaignsEmerging1 sourceSep 2, 2026 · 10:51via IT Security Guru

Fake Software Update Installs a Real Crypto Wallet – Rigged So It Can Never Open

Brief

Security researchers at Huntress have discovered a malware campaign that tricks victims into installing a real, fully functional copy of Exodus, a popular cryptocurrency wallet application, only to disable it so it can never actually be opened, using it instead as cover for a hidden spying tool.

The firm said it identified four separate organisations compromised between late July and mid-August 2026, three of them within an 85-minute window on a single day, using a version of the malware built the day before it was deployed.

According to Huntress, victims were lured into opening what appeared to be a work document or a routine software update. In practice, the files silently downloaded a Windows installer that presented itself, falsely, as an Apple “Background Service.” The installer placed a genuine, largely unmodified copy of the Exodus wallet, version 24. 33.

Read more on IT Security Guru