C&CMembers
C&C

woody_rat Stealer Drains Exodus and ElectronCash Wallets via Telegram Log Market

A woody_rat operation tracked by CTX Team is harvesting cryptocurrency wallet files and messenger credentials from technology-sector victims in Egypt and Hungary in a single automated sweep. Stolen data is packaged into dated log archives and distributed through a Telegram bot channel, while a self-signed ten-year wildcard TLS certificate issued by 'PureCrack' anchors the campaign's purpose-built C2 relay infrastructure.

Jun 13, 2026, 14:32 (UTC+9)Last seenJun 13, 2026Severity100ByCTX TeamIOC73MITRE62RegionsEGHU

##Wallet Vaults Cracked Open: How a woody_rat Infostealer Pipeline Drains Exodus and ElectronCash in a Single Pass A woody_rat operation tracked by CTX Team has been systematically dismantling the cryptocurrency holdings of technology-sector victims in Egypt and Hungary, harvesting the full wallet store of both Exodus and ElectronCash installations in a single automated sweep — then packaging the stolen files into dated log archives and routing them through a Telegram bot channel for downstream…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence