Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

OkoBot Malware Framework Deploys Sophisticated SeedHunter Module to Steal Hardware Wallet Recovery Phrases

Cahyo Dewo, July 15, 2026

A formidable new malware framework, dubbed OkoBot, has been actively compromising Windows machines since at least April 2024, deploying a highly specialized module known as SeedHunter designed to trick hardware wallet owners into divulging their critical recovery phrases. This insidious threat operates by injecting malicious code directly into the legitimate desktop applications of popular hardware wallets, presenting users with a convincing, yet entirely fake, prompt for their seed phrase. The discovery, detailed in a comprehensive report by Kaspersky’s Global Research and Analysis Team (GReAT) on Wednesday, July 15, reveals a sophisticated, multi-stage attack chain that has already claimed hundreds of victims across more than 25 countries.

The Unveiling of OkoBot: A New Frontier in Crypto Theft

Kaspersky’s GReAT team’s investigation peeled back the layers of OkoBot, exposing a robust and adaptable framework equipped with over 20 distinct payloads and implants. Active since at least April 2024, the malware has steadily grown its footprint, with telemetry data indicating significant victim clusters in Brazil, Vietnam, Canada, Mexico, and Türkiye. While the exact number of users who succumbed to the deception and entered their recovery phrases remains undisclosed, the widespread targeting underscores the significant risk posed to cryptocurrency holders globally. The core innovation of OkoBot’s SeedHunter module lies in its ability to compromise the user’s perception of security by operating within the trusted environment of the wallet’s own desktop software, making it exceptionally difficult for an average user to detect the fraud.

SeedHunter: The Art of Deception Within Trusted Applications

At the heart of OkoBot’s crypto-stealing capabilities is SeedHunter, a module engineered to specifically target the recovery phrases of hardware wallet users. Once the OkoBot framework establishes a foothold on a Windows PC, SeedHunter meticulously monitors for the presence of widely used hardware wallet companion applications, including Trezor Suite, Ledger Wallet, and Ledger Live. Upon detection, it stealthily injects itself into the chosen application, leveraging vulnerabilities within its Electron-based internals. Electron, a framework for building desktop applications with web technologies, often becomes a target for such injections due to its web-rendering capabilities that can be manipulated to display malicious content.

Following injection, SeedHunter communicates with its command-and-control (C2) server, identified as moonsand[.]store. This communication dictates its next move. A particularly cunning feature is the Wait flag. If this flag is enabled by the C2 server, SeedHunter enters a dormant state, patiently scanning USB ports for specific vendor and product IDs associated with genuine Ledger or Trezor devices. Only when a legitimate hardware wallet is detected and plugged in does SeedHunter spring to life, drawing a hard-coded, brand-specific recovery page directly within the running, authentic wallet application. If the Wait flag is off, the fake recovery prompt appears immediately, regardless of whether a device is connected.

The user, seeing what appears to be a legitimate prompt from their wallet software, is then tricked into entering their recovery phrase. This crucial information, once typed, is captured by the malicious page’s console, marked with an @:app:print identifier, and subsequently harvested by the hooked mal_LogConsoleMessage function. The stolen phrase is then exfiltrated as JSON data to the moonsand[.]store C2 server, with an RC4-encrypted copy also dropped into a temporary file on the compromised system as a fallback.

It is paramount to understand that the hardware wallet itself, the physical device designed for cryptographic security, remains uncompromised. These devices are built to perform one core function: to keep private keys securely isolated and to never expose the recovery phrase outside of the device’s secure enclave. The vulnerability exploited by OkoBot is not a flaw in the hardware wallet’s cryptography or firmware, but rather a sophisticated social engineering attack that leverages the companion software on the compromised PC to trick the user into voluntarily surrendering their phrase. The device itself cannot prevent its associated software from making a fraudulent request to the user.

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

Historical Precedents and Evolving Tactics

While OkoBot’s SeedHunter module presents a particularly insidious evolution, the underlying principles of compromising companion software or mimicking legitimate applications are not entirely new. Cybersecurity researchers have previously documented similar tactics. For instance, Moonlock Lab tracked macOS-based stealers that employed "swap" versions of legitimate applications, replacing them with malicious clones. TheHackersNews itself reported on instances where hackers distributed trojanized Ledger Live apps, often through platforms like TikTok, which would demand a user’s 24-word seed phrase after replacing the authentic application. The AMOS malware, for example, was known to kill the legitimate Ledger Live process and drop a trojanized clone into the /Applications directory, then prompt for the recovery words.

Another precursor to SeedHunter’s Wait flag mechanism was observed with the GlassWorm malware in March 2025 (or an earlier iteration of GlassWorm, assuming the date is a predictive or typo), which also utilized a USB trigger on Windows. GlassWorm employed Windows Management Instrumentation (WMI) to detect device connection, then killed the real application and launched its own malicious window. What distinguishes SeedHunter, however, is its refined stealth: it keeps the authentic application running and draws the malicious prompt inside it, making the deception even more seamless and difficult to detect by the user. This "living off the land" approach within the victim’s own trusted software signifies a significant advancement in evasion techniques.

Initial Compromise: The Path to Infection

OkoBot’s initial infection vectors demonstrate a dual approach, combining traditional social engineering with supply chain compromise tactics:

  1. ClickFix Lures: One primary method involves ClickFix lures. These typically entail malvertising campaigns, sophisticated phishing emails, or compromised websites that redirect users to malicious download sites. The lures are designed to entice users into downloading what they believe to be legitimate software or updates, which are in fact trojanized installers for OkoBot. These campaigns often exploit popular search terms or trending software to maximize their reach.

  2. Trojanized Software on GitHub: A more insidious vector involves the distribution of trojanized software through seemingly legitimate channels, such as GitHub repositories. Kaspersky’s analysis revealed a specific instance where a repository advertised SQL Server Management Studio (SSMS), a genuine Microsoft tool, but actually shipped a malicious version of Audacity, the open-source audio editor. This modified Audacity build contained a malicious implant hidden within one of its core libraries. This particular trojanized package ranked highly for SSMS searches on GitHub, remaining active from late March 2024 to June 2024, exposing countless potential victims to the threat. Such tactics exploit the trust users place in open-source platforms and popular software.

Both infection paths ultimately lead to the execution of TookPS, a PowerShell downloader that Kaspersky has been tracking since March 2024. TookPS is a versatile initial access tool, previously observed riding on fake DeepSeek AI pages and later leveraging fake business-software download sites. Once executed, TookPS installs SSH, establishes an attacker-controlled server connection, forwards the local SSH daemon port, and then patiently awaits further instructions. This establishes a persistent backdoor, creating an SSH tunnel through which an automated SSH bot can later connect back to the compromised system.

OkoBot’s Multi-Stage Post-Exploitation Framework

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

Once TookPS establishes the initial foothold, the automated SSH bot initiates a comprehensive reconnaissance and data exfiltration phase. It inventories the compromised system, meticulously gathering details about installed software, including antivirus solutions like Windows Defender. Crucially, it then proceeds to pilfer sensitive data, including cryptocurrency wallet files, browser cookies, browser profiles, and stored credentials. To maintain stealth, the bot actively silences Windows Defender notifications via a registry write, minimizing the chances of detection by the user. This initial phase is designed to establish a "desk" – a fully compromised environment ready for further module deployment.

Subsequent modules are delivered to the infected machine via SFTP (SSH File Transfer Protocol). These modules are then executed by a VMProtect-packed launcher known as HDUtil. This launcher is particularly dangerous as it can silently elevate its privileges using a Windows RPC UAC bypass, a vulnerability documented by Google’s Project Zero back in 2019. This UAC bypass allows the malware to gain elevated permissions without triggering user account control prompts, ensuring its operations remain undetected.

The final delivery mechanism involves Volume2, an open-source utility that has been weaponized. It ships with a malicious protobuf.dll library. This malicious DLL is responsible for decrypting and initiating the core OkoBot payload: a plugin dispatcher. This dispatcher continuously polls its C2 server every 20 seconds, awaiting instructions and new plugins. Kaspersky’s researchers successfully recovered five distinct plugins, one of which is a process injector. This process injector is the critical component responsible for placing the SeedHunter module into the legitimate hardware wallet applications, completing the sophisticated attack chain.

A Comprehensive Surveillance Kit

Beyond stealing recovery phrases, OkoBot is equipped with an extensive surveillance kit, designed for broad data exfiltration and monitoring:

  • OkoSpyware: This module is configured to monitor for over 100 specific executable files, including popular cryptocurrency wallets like Exodus and password managers like 1Password. When a matching window is detected, OkoSpyware leverages a bundled FFmpeg utility to record the window’s activity into an MP4 video file. Concurrently, it logs all keystrokes entered into that window, capturing sensitive information in real-time. The module also performs regex-matching on browser tab titles, specifically targeting terms like "MetaMask" or "Tonkeeper," ensuring that any browsing activity related to cryptocurrency management is recorded.
  • MC Keylogger: This dedicated keylogger provides comprehensive input monitoring. It records all keystrokes, captures clipboard contents (potentially revealing copied wallet addresses or passwords), monitors connected USB devices, and takes screenshots of the desktop every five minutes, providing a visual record of user activity.
  • Chromium Extension Loader (Rilide): OkoBot also includes a loader that installs hidden Chromium extensions, granting them extensive permissions. The specific stealer installed is Rilide, a notorious Chromium-based malware that has been used by Russian-speaking threat actors since April 2023. Rilide is highly effective at exfiltrating a wide array of browser data, including saved login credentials, autofill data, credit card information, and cryptocurrency wallet extensions.

This comprehensive suite of surveillance tools demonstrates OkoBot’s dual objective: direct financial theft through recovery phrase capture and long-term data exfiltration for potential future exploitation or sale on underground markets.

Geographic Targeting and Attribution Challenges

Kaspersky’s telemetry data highlights a global distribution of victims, with hundreds affected across more than 25 countries. The largest concentrations of attacked users are observed in Brazil, Vietnam, Canada, Mexico, and Türkiye. This diverse geographic targeting suggests either a broad, opportunistic campaign or a calculated strategy to target regions with growing cryptocurrency adoption or potentially less robust cybersecurity infrastructure among general users.

Despite the extensive technical analysis, Kaspersky has refrained from attributing the OkoBot campaign to any known crimeware actor, stating, "we can’t attribute this malicious campaign to any known crimeware actor." However, the report does point to several "soft signals" that could indicate the origin or primary operational sphere of the threat actors:

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
  • C2 Geo-fencing: The C2 servers hosting the first-stage PowerShell payload reportedly return an empty response to IP addresses originating from Russia and Commonwealth of Independent States (CIS) countries. This tactic is often employed by Russian-speaking cybercriminal groups to avoid attracting attention from domestic law enforcement.
  • Rilide Association: The Rilide stealer, a component of OkoBot’s toolkit, is known to be traded and utilized within invitation-only Russian-speaking forums in the cybercriminal underground.
  • Russian Comments: Analysis of the SeedHunter phishing pages revealed embedded Russian comments, another potential indicator of the developers’ native language.

While these signals are not definitive proof, they collectively suggest a possible link to Russian-speaking threat actor communities, a common characteristic of sophisticated crimeware operations.

Industry Response and Critical User Mitigation Strategies

A crucial aspect of the OkoBot threat is that it does not exploit a direct vulnerability (CVE) in hardware wallets or their official software that could be patched by vendors. Instead, it preys on the user’s endpoint security and their trust in the visual interface. This means there is no vendor patch that can directly close this social engineering route. The onus of defense primarily falls on the user and their endpoint security measures.

Hardware wallet manufacturers consistently reiterate core security principles:

  • Ledger: Explicitly states that the recovery phrase "never goes anywhere but the Ledger itself." Users should never enter their 24-word recovery phrase into any software application, website, or digital form.
  • Trezor: Emphasizes that Trezor Suite will "never ask you to type your backup." While a Trezor Model One’s standard recovery process does involve entering words into the Suite application, this is only done when explicitly prompted by the device screen itself. The critical tell for OkoBot’s deception is a recovery page appearing because the device was plugged in, with nothing indicating the prompt on the hardware device’s own screen.

Therefore, the primary defense lies in user vigilance and adherence to fundamental cybersecurity practices:

  1. Never Type Your Recovery Phrase into Software: The golden rule for hardware wallet security is to only enter your recovery phrase directly onto the hardware device itself, and only when the device’s screen explicitly prompts you to do so during setup or recovery. Any software prompt, even within an authentic application, is highly suspect.
  2. Verify All Device Prompts: Always cross-reference any on-screen prompts from your companion software with the display on your physical hardware wallet. If the hardware wallet’s screen does not display the same prompt, or if it doesn’t prompt you at all, do not proceed.
  3. Download Software from Official Sources Only: Always download hardware wallet companion applications and any other software directly from the official vendor’s website, never from third-party sites, GitHub repositories, or untrusted links.
  4. Exercise Extreme Caution with Downloads: Be highly suspicious of any unsolicited software, "cracks," or utilities. Even legitimate-looking software found on platforms like GitHub can be trojanized. Verify the source, check for community reviews, and look for official endorsements.
  5. Maintain Robust Endpoint Security: Implement and regularly update reputable antivirus or endpoint detection and response (EDR) solutions on all Windows machines. These tools can help detect and block the initial stages of OkoBot’s infection, such as TookPS and the trojanized installers.
  6. Regularly Back Up Data: While not directly preventing OkoBot, regular backups of non-crypto data can mitigate the damage from other OkoBot modules that steal files and credentials.
  7. Educate Yourself: Stay informed about common phishing tactics, social engineering schemes, and the latest malware threats. Understanding how these attacks work is the first line of defense.

The Evolving Threat Landscape

The analysis of OkoBot also points to its continuous development. The Kaspersky report notes a significant rebuild around March 2025. This evolution saw the removal of the TeviRAT component, and the entire HDUtil-to-extl-to-Rilide chain was streamlined and folded into a single dispatcher plugin that performs the same functions. Furthermore, Volume2 is now delivered directly by TookPS, bypassing some intermediate steps. This continuous pruning and refinement of the codebase strongly indicates that the threat actors behind OkoBot are not abandoning their operation but are actively investing in its development, seeking to enhance its stealth, efficiency, and resilience.

The OkoBot framework exemplifies the growing sophistication of crimeware operations targeting the cryptocurrency ecosystem. By combining traditional multi-stage malware delivery with highly specific social engineering tactics tailored for hardware wallet users, these threat actors are pushing the boundaries of endpoint compromise. The convergence of initial access brokers, extensive surveillance capabilities, and targeted crypto-theft modules presents a grave challenge to individual users and the broader digital asset community. The ongoing evolution of OkoBot underscores the critical need for multi-layered security defenses, constant user education, and unwavering vigilance in safeguarding digital assets against increasingly cunning adversaries. Security researchers and users alike must remain proactive in adapting to these evolving threats to protect the integrity of their digital wealth.

Cybersecurity & Digital Privacy CybercrimedeploysframeworkHackingHardwaremalwaremoduleokobotphrasesPrivacyrecoverySecurityseedhuntersophisticatedstealwallet

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes