news.mlab.sh
Back to the feed
threat-intel

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

High
Summary

OkoBot, a malware framework, has been actively targeting hardware wallet users since April 2025, primarily through phishing attacks leveraging a module called SeedHunter. SeedHunter intercepts the wallet's desktop software when a Ledger or Trezor device is connected, presenting a malicious recovery page within the existing wallet application. The framework utilizes a complex chain of tools, including a PowerShell downloader (TookPS), a Chromium stealer (Rilide), and a surveillance component (OkoSpyware) to steal user credentials and monitor activity. Kaspersky has identified numerous artifacts and C2 domains associated with the campaign, and both Ledger and Trezor have confirmed that the stolen seed phrases are never transmitted outside of the device itself.

A new malware framework, OkoBot, has been targeting hardware wallet users since April 2025, primarily through sophisticated phishing attacks. The core of the attack revolves around a module called SeedHunter, which intercepts the wallet's desktop software when a Ledger or Trezor device is connected. Instead of prompting the user to enter their recovery phrase directly, SeedHunter presents a malicious recovery page within the existing wallet application. This page is designed to trick users into typing their seed phrase, which is then sent to a remote attacker.

Kaspersky's GReAT team has documented hundreds of victims across more than 25 countries, with a significant portion located in Brazil, Vietnam, Canada, Mexico, and Türkiye. The campaign utilizes a complex chain of tools, including TookPS, a PowerShell downloader, and Rilide, a Chromium stealer. The framework also incorporates OkoSpyware for surveillance, monitoring over 100 executables, including Exodus and 1Password, and recording keystrokes and browser activity.

Ledger and Trezor have both confirmed that the stolen seed phrases are never transmitted outside of the device itself. The process begins with a malicious recovery page appearing within the wallet’s desktop software when a device is connected, even if the device screen is blank. The framework is designed to be difficult to detect, with artifacts like a scheduled task named Apple Sync and a modified termsrv.dll.

Kaspersky has been unable to attribute the campaign to a specific threat actor, noting that the servers hosting the first-stage PowerShell return an empty response to Russian and CIS IPs. The Rilide stealer operates on invitation-only Russian-speaking forums. The framework has been streamlined, with the previous TeviRAT and HDUtil chains now consolidated into a single dispatcher plugin.

Ledger states that the phrase never goes anywhere but the device itself, while Trezor Suite will never ask the user to type their backup, although a Model One's standard recovery process does take the words in Suite. The campaign’s success relies on luring users into a false sense of security, presenting a familiar interface to steal their recovery words.

Read the full article at The Hacker News