OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
ID: 52c913c9-e6be-56c4-8a99-2f38bd2f2712
STIX ID: report--52c913c9-e6be-56c4-8a99-2f38bd2f2712
Feed Name: The Hacker News
Threat Score
Kaspersky GReAT analyzed OkoBot, a multi-module Windows malware framework active since April 2025 that includes SeedHunter — a module which injects fake recovery pages into legitimate Ledger and Trezor desktop apps to capture seed phrases — and a suite of implants for credential and file theft, remote access (SSH tunnels, RDP persistence), and surveillance; the report includes IOCs and observable artifacts for hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
