logo

OkoBot Malware Uses ClickFix and SeedHunter to Steal Ledger and Trezor Seed Phrases

ID: f7112bc5-fb11-55e0-b1da-075160cef6a8

STIX ID: report--f7112bc5-fb11-55e0-b1da-075160cef6a8

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

Author: Mayura Kathir

...
...

OkoBot is a modular criminal malware framework (with an upstream TookPS downloader) actively used to compromise crypto users by deploying SSH backdoors, RDP persistence, browser and wallet-stealing implants (Rilide, SeedHunter) and keylogging/screen-recording plugins; attackers distribute trojanized apps via GitHub and social-engineering pages to harvest Ledger/Trezor seed phrases, credentials, and wallet data and exfiltrate them to attacker infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.