A trojanized Exodus wallet installer is being used to drop a modular RAT that focuses on credentials, cookies, and live operator access rather than a quick hit on crypto balances.
A fake Exodus installer is being tied to a modular RAT that steals browser data, hides operator access, and repurposes Windows machines as SOCKS relays.
A custom implant written in Go is notable not for noise, but for control: command execution, SOCKS tunneling, and a cleaner route into internal networks.
A Linux-born backdoor has reappeared in Windows form, and the shift suggests a more portable, harder-to-trace malware toolkit aimed at public-sector targets.
The Webworm campaign shows how collaboration tools, cloud APIs, and proxy layers can become part of an intrusion chain without looking overtly malicious on the wire.