A malware framework called OkoBot has been running on Windows systems since April 2025, featuring a module called SeedHunter that injects fake recovery seed phrase pages directly into legitimate Ledger and Trezor desktop applications. Kaspersky’s GReAT team has tracked hundreds of victims across more than 25 countries.
SeedHunter monitors for Trezor Suite, Ledger Wallet, and Ledger Live processes. Once detected, it hooks into the app’s Electron internals and waits for C2 instructions. If the server sets a USB flag, SeedHunter scans for connected hardware wallets by vendor and product ID, drawing the phishing page only when a real device is plugged in. The typed recovery phrase is captured via JavaScript console logging and exfiltrated as JSON with an RC4 copy saved to a temporary file.
The malware gains initial access through ClickFix lures and trojanized software on GitHub. One repository advertised SQL Server Management Studio but shipped a trojanized version of Audacity. Both paths execute TookPS, a PowerShell downloader that establishes SSH tunnels for remote access.
OkoBot carries over 20 payload modules including OkoSpyware for video recording of targeted applications and a keylogger that captures clipboard data, USB events, and screenshots every five minutes.
