A malware framework called OkoBot has been targeting Windows machines since April 2025, with a module named SeedHunter designed to steal cryptocurrency wallet recovery phrases from Ledger and Trezor users. The malware injects into legitimate wallet applications like Trezor Suite, Ledger Wallet, and Ledger Live, displaying a fake recovery page within the app itself. It can wait for a hardware wallet to be plugged in before showing the page, making the phishing attempt more convincing. Kaspersky’s GReAT team identified hundreds of victims across more than 25 countries, with the largest numbers in Brazil, Vietnam, Canada, Mexico, and Turkey.
OkoBot is delivered through ClickFix lures and trojanized software on GitHub, such as a fake SQL Server Management Studio installer that actually contained a modified version of Audacity. The initial payload, TookPS, is a PowerShell downloader that establishes SSH tunnels and deploys additional modules. The framework includes over 20 payloads, including surveillance tools like OkoSpyware, which records screens and logs keystrokes, and a keylogger. It also installs hidden Chromium extensions, including the Rilide stealer used by Russian-speaking threat actors.
Kaspersky could not attribute the campaign to a specific actor, but noted that the C2 servers block Russian and CIS IPs, and the phishing pages contain Russian comments. The attack does not exploit any vulnerability in the hardware wallets themselves; instead, it relies on social engineering to trick users into entering their recovery phrase into a fake interface within the legitimate app. Indicators of compromise include a scheduled task named Apple Sync, specific files in %PROGRAMDATA%, and outbound SSH connections from user endpoints.
Malware: OkoBot, SeedHunter, TookPS, Rilide, OkoSpyware, MC Keylogger, GlassWorm, AMOS
Companies: Kaspersky, Ledger, Trezor, Moonlock Lab
Products: Trezor Suite, Ledger Wallet, Ledger Live, SQL Server Management Studio, Audacity, Volume2, FFmpeg, 1Password, Exodus, MetaMask, Tonkeeper
Original source: thehackernews.com