Fileless Python InfoStealer Targeting Exodus
Jan. 28, 2025, 3:30 p.m.
Description
A new Python-based info stealer targeting the Exodus crypto wallet has been discovered. This malware employs fileless techniques, clipboard monitoring, and keylogging to capture wallet passwords and sensitive data. It checks for the existence of 'passphrase.json' and, if not found, uses a keylogger to capture the victim's password when the Exodus password prompt appears. The malware compresses and exfiltrates stolen data in memory via Discord webhooks. It also implements clipboard monitoring to intercept potentially stored passwords. The script's sophisticated design includes password validation checks and targeted window detection for Exodus-related activities.
Tags
Date
- Created: Jan. 28, 2025, 10:59 a.m.
- Published: Jan. 28, 2025, 10:59 a.m.
- Modified: Jan. 28, 2025, 3:30 p.m.
Indicators
- 160f9f71ff722c4bad8bd9108c579f1cc585f0811fa2e9525de95e0fb2ba2aa0
Additional Informations
- Finance