@LevelBlueCyber #OpsIntel recently identified a new campaign exploiting trusted Electron applications. Victims were lured into executing a JavaScript file that silently downloaded a MSI installer containing a tampered
#Exodus Wallet.
The MSI contains a modified
#ASAR (Atom Shell Archive), a custom archive format designed specifically for
#Electron applications to bundle application resources.
The initial payload is an encrypted PE loader that can be decrypted using AES-256-CBC. Once decrypted, the loader reflectively loads the RAT payload directly into memory.
🧐 IOC:
hXXp://35.212.159[.]20/setup2026.msi
e9e5b8e5aa3bf03eca0bda9d1c08f11a70e4d03bbd9e8ac27b2cc7de4f4000c2 (setup2026.msi)
a4e1513e58a5b70389a08714d97c4eb2e22f052856c1471d068451451bfe7840 (exodus_patch.js)
15836a5ab798a5955be566c0322aa9a4140662b91cdda60714ffbe5e57bfcb43 (keystorage.js)
8fa059c30b75233d1e2d1f9b289c899a112a9964a216f0ebc35514ace152a23a (index.js)
eb2d09773e5cb6eecad4bf14ed05b0c885465610a354ea0c9665ffcf56aced18 (app.asar)
56ec5bfb62e9b615b8bb949a76e1d4f6bb3f34983139f0c48cfc73b350961f1c (decrypted buffer)
lgapistorage123.table.core.w…[.]net
🔎AES-256-CBC parameters:
Key: KlABCwCvW5oplWMsSxjTlKb0o+iOK6OsxCGZZ0td/1U=
IV: 4b44GYeQwOVmpFKlbWdPVw==