Security1 distinct publisher3 min readPublished
Huntress says one toolset hit four unrelated organisations between late July and mid-August 2026, three of them inside 85 minutes, using a build that delivers a real Exodus Wallet and then keeps it shut.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The installer keeps its promise. Exodus Wallet 24.33.4 lands on disk, and the same package then works to make sure the victim never opens it [1]. Any check that asks whether a download delivered the software it advertised returns a clean answer here. The wallet is the receipt. The modular RAT going after browser credentials is the reason the package exists [16].
Huntress dates the build to the day before the August 18 cluster [3], which puts compile to three separate victim estates inside 48 hours [17]. Within that window the three organisations sit about 42 minutes apart [18]. That spacing reads as one delivery run against a target list rather than drift from a wider spray.
The July 24 endpoint is where the investigation turned. There was no lure document. A scheduled task called INetHealth launched conhost.exe --headless powershell -e with a Base64 blob, on a machine that was infected before it was enrolled for monitoring [5]. Huntress read it as ClickFix at first [6]. The artifact is weak evidence: conhost --headless hides a window, it is a legitimate Windows function developers use, and it says nothing about how the command reached the host [7]. Decoding the blob showed it downloaded nothing at all, and that dead end is what Huntress calls the most useful clue in the case [8].
Two artifacts survive on disk and are cheap to hunt. The JavaScript tries to remove the dropper five seconds after launch using setTimeout, which Windows Script Host does not implement, so the call throws into an empty catch block and jn0101.msi stays in %TEMP% [13]. On the archive route, the user opened a .js file directly inside Update_GS_7G0N-254V38L2350.zip instead of extracting it, and Explorer's staging behaviour left a .zip.116 path fragment under %LOCALAPPDATA%\Temp [14].
The lures show preparation rather than volume. One victim got a real marketing ebook from a content platform; another got a genuine legal brief pulled live from law.georgetown.edu [12]. Both arrived while the MSI downloaded in the background [11]. The double-extension variant relied on Windows hiding known extensions, so a .pdf.js file looked like a document and ran under Windows Script Host when opened [9]. On two endpoints the parent process was chrome.exe, so the file executed straight out of the browser download flow with no save-and-inspect step in between [10].
Huntress states that the two delivery routes it observed should not be read as the actor's full inventory [15]. Detection content keyed to .pdf.js and one zip filename will hold for exactly as long as the operator keeps using them. The durable indicators in this set are the surviving dropper in %TEMP%, the Explorer staging fragment, and a wallet application that is installed and never run.
Ranked by verification strength, evidence, and original report placement.
A tampered installer analysed by Huntress installs a real version of Exodus Wallet 24.33.4, takes considerable care to ensure nobody ever opens the application, and then goes after more.
Between late July and mid August 2026, four unrelated Huntress-protected organizations were compromised by the same tooling.
Three of the four organizations were hit on August 18, within 85 minutes of each other, using an installer built the day before.
On three endpoints, someone opened what they thought was a work-related document and Windows handed it to the script host.
In an earlier intrusion on July 24 there was no document at all, just a scheduled task named INetHealth launching conhost.exe --headless powershell -e with a Base64 blob; the infection pre-dated endpoint enrollment.
Huntress initially misread the July detection, believing it to be a ClickFix intrusion.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain1 distinct publisher
security
ClickFix in the sidebar: Def Con follow-up phishing turns a real Google Doc into the payload2 distinct publishers
leadership
ClickFix scales by asking employees to paste the command themselves1 distinct publisher
security
ClickFix lures now paste an msiexec command that installs legitimate software to sideload a DLL1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Forensically specific, entirely first-party
The artefacts are the kind you can go and check: a named scheduled task, two full msiexec command lines, a staged path ending in .zip.116\, a serving IP, even a victim's browser search asking whether JavaScript files are Trojan horses. What is absent is anyone but Huntress — no second telemetry set, no sample hash, no named malware family, and a July timeline reconstructed from a machine that was compromised before the agent arrived.
Four victims, all inside one vendor's estate
The observed footprint is four organisations, and the sampling frame is whatever Huntress happens to monitor — a real campaign, not yet a demonstrably broad one. Huntress says as much itself, declining to present the routes it saw as the actor's full inventory, and the third delivery path it found on the serving infrastructure had no victims at all.
Headline hooks, body under-claims
The title promises a wallet that never opens and the text delivers something narrower and more useful. Huntress admits it first called the July detection ClickFix, warns that the hidden-window flag is ordinary developer behaviour, and points out that the MSI filenames are per-campaign labels rather than indicators. A vendor with a marketing motive had every opening to inflate this and mostly declined.
MDR vendor grading its own catch
The phrase 'Huntress-protected organizations' is doing quiet commercial work every time it appears: this is a detection company narrating four compromises its own agents surfaced, with an analyst credited by name. The self-correction and the refusal to overstate the delivery set pull against that pressure, but no version of this post ends badly for Huntress.
Credible, unchecked, and checkable
One publisher, one investigation, and the investigator is an interested party — that ceiling holds until someone else looks. What keeps confidence from sinking further is that the account is precise enough to be tested: anyone who finds a .zip.116 fragment or an orphaned MSI in %TEMP% either confirms Huntress or contradicts it.