Particle.news
Download on the App Store

OkoBot Malware Injects Fake Seed Prompts into Ledger and Trezor Apps

Kaspersky's July 15 technical teardown finds Windows endpoint compromises allow attackers to display fake recovery prompts inside wallet companion apps, enabling seed theft.

Overview

  • Kaspersky published a detailed technical report on July 15 that says OkoBot is a modular Windows malware framework active since April 2025 and still running as of the report.
  • A module called SeedHunter hooks into Ledger Live, Ledger Wallet and Trezor Suite to draw bogus recovery‑phrase screens inside the real desktop apps and exfiltrate any typed seed words to attacker servers.
  • Operators deliver OkoBot by tricking users with ClickFix social‑engineering pages and trojanized GitHub downloads; the initial TookPS PowerShell downloader installs SSH, opens remote access and stages further payloads.
  • The framework carries more than 20 plugins, including OkoSpyware and MC Keylogger that record wallet and browser windows, capture keystrokes and install hidden Chromium extensions, and Kaspersky telemetry shows hundreds of victims in 25+ countries.
  • Hardware wallets themselves still protect keys but vendors warn that any unexpected prompt to enter a recovery phrase is a sign of endpoint compromise and users should avoid running pasted PowerShell commands, only install official software, and move funds from wallets whose seed may have been entered on an infected PC.