
WoodyRAT Stealer Harvests Complete Exodus Wallet Secrets Across AS214351
Thirty-five new file indicators from a WoodyRAT-tagged campaign reveal systematic theft of Exodus wallet seeds, Telegram session tokens, FileZilla credentials, and Pidgin accounts from victims in Algeria, Ethiopia, and India. The operator's single autonomous system, registered October 2024, now hosts both a disposable PHP panel and a purpose-built decade-long internal PKI — signalling deliberate infrastructure hardening rather than commodity panel abuse.
Thirty-five new file indicators have joined the WoodyRAT-tagged campaign CTX Team first documented in earlier coverage, and almost none of them are malware. They are the stolen goods themselves — wallet seeds, two-factor secrets, session tokens, FTP credential stores, and instant-messenger account files pulled from victim machines and packaged into structured log bundles before being uploaded to a PHP panel sitting on a German IP address inside a single autonomous system registered less than…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read