logo

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

ID: 52c913c9-e6be-56c4-8a99-2f38bd2f2712

STIX ID: report--52c913c9-e6be-56c4-8a99-2f38bd2f2712

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

Author: [email protected] (The Hacker News)

...
...

Kaspersky GReAT analyzed OkoBot, a multi-module Windows malware framework active since April 2025 that includes SeedHunter — a module which injects fake recovery pages into legitimate Ledger and Trezor desktop apps to capture seed phrases — and a suite of implants for credential and file theft, remote access (SSH tunnels, RDP persistence), and surveillance; the report includes IOCs and observable artifacts for hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.