OkoBot hardware-wallet phrase theft campaign
Campaign
Summary
Hide ▲
Show ▼
OkoBot is an active Windows malware campaign that has been running since April 2025 and now spans hundreds of victims across more than 25 countries. It uses ClickFix lures and trojanized GitHub software to deliver TookPS, then stages modules that steal cryptocurrency wallet seed phrases, credentials, cookies, and other sensitive data. SeedHunter injects fake recovery-phrase pages into Ledger Live, Ledger Wallet, and Trezor Suite, while telemetry shows the largest share of activity in Brazil, Vietnam, Canada, Mexico, and Türkiye. Kaspersky says the activity evolved from a longer-running TookPS campaign first observed in January as part of the same broader operation.
Related Happenings
OkoBot Windows malware framework with SeedHunter wallet phrase theft
Malware Activity
H score31
First: 15.07.2026 18:30
Last: 15.07.2026 18:30
Sources 1
How related:
SeedHunter: Injects into Trezor Suite, Ledger Wallet, and Ledger Live to display a fake seed-recovery screen designed to steal wallet recovery phrases from victims.
About this happening:
OkoBot is a Windows malware framework that uses SeedHunter to inject fake recovery-phrase screens into Trezor Suite, Ledger Wallet, and Ledger Live to steal ...
OkoBot Windows malware framework with SeedHunter wallet phrase theft
Malware ActivityHow related: SeedHunter: Injects into Trezor Suite, Ledger Wallet, and Ledger Live to display a fake seed-recovery screen designed to steal wallet recovery phrases from victims.
About this happening: OkoBot is a Windows malware framework that uses SeedHunter to inject fake recovery-phrase screens into Trezor Suite, Ledger Wallet, and Ledger Live to steal ...
Y2K Operators Millenium RAT social-engineering distribution campaign
Campaign
H score73
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Y2K Operators Millenium RAT social-engineering distribution campaign
CampaignAbout this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Ghost Networks crypto-clipper promotion campaign
Campaign
H score15
First: 17.06.2026 21:14
Last: 17.06.2026 21:14
Sources 1
About this happening:
Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
Ghost Networks crypto-clipper promotion campaign
CampaignAbout this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...
Rust-based clipboard hijacker that swaps wallet addresses
Malware Activity
H score10
First: 17.06.2026 21:14
Last: 17.06.2026 21:14
Sources 1
About this happening:
The Rust-based clipper is a Windows and macOS malware activity that replaces copied cryptocurrency wallet addresses with attacker-controlled destinations. It continuou...
Rust-based clipboard hijacker that swaps wallet addresses
Malware ActivityAbout this happening: The Rust-based clipper is a Windows and macOS malware activity that replaces copied cryptocurrency wallet addresses with attacker-controlled destinations. It continuou...
Timeline
-
15.07.2026 18:30 3 articles · 13d ago
Kaspersky details OkoBot seed-phrase theft against Ledger and Trezor users
Initial DisclosureKaspersky's GReAT team disclosed the OkoBot framework running on Windows machines since April 2025 and described SeedHunter, a module that injects fake recovery-phrase pages into Ledger Live, Ledger Wallet, and Trezor Suite to steal wallet recovery phrases. The telemetry covered hundreds of victims across more than 25 countries, with the largest share of attacked users in Brazil, Vietnam, Canada, Mexico, and Türkiye, and the delivery paths included ClickFix lures and trojanized GitHub software that deploy TookPS.
Show sources
- OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps — thehackernews.com — 15.07.2026 18:30
- OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps — thehackernews.com — 15.07.2026 18:30
- New OkoBot framework deploys 20 payloads to steal data, crypto — www.bleepingcomputer.com — 16.07.2026 22:09