Find notable cyber news and cases, enriched with sources, timelines, and signals.

OkoBot hardware-wallet phrase theft campaign

Campaign
First reported
Last updated
Happening score
H score 37
2 unique sources, 2 articles

Summary

Hide ▲

OkoBot is an active Windows malware campaign that has been running since April 2025 and now spans hundreds of victims across more than 25 countries. It uses ClickFix lures and trojanized GitHub software to deliver TookPS, then stages modules that steal cryptocurrency wallet seed phrases, credentials, cookies, and other sensitive data. SeedHunter injects fake recovery-phrase pages into Ledger Live, Ledger Wallet, and Trezor Suite, while telemetry shows the largest share of activity in Brazil, Vietnam, Canada, Mexico, and Türkiye. Kaspersky says the activity evolved from a longer-running TookPS campaign first observed in January as part of the same broader operation.

Related Happenings

OkoBot Windows malware framework with SeedHunter wallet phrase theft

Malware Activity
H score31 First: 15.07.2026 18:30 Last: 15.07.2026 18:30 Sources 1

How related: SeedHunter: Injects into Trezor Suite, Ledger Wallet, and Ledger Live to display a fake seed-recovery screen designed to steal wallet recovery phrases from victims.

About this happening: OkoBot is a Windows malware framework that uses SeedHunter to inject fake recovery-phrase screens into Trezor Suite, Ledger Wallet, and Ledger Live to steal ...

Y2K Operators Millenium RAT social-engineering distribution campaign

Campaign
H score73 First: 29.06.2026 17:30 Last: 29.06.2026 17:30 Sources 1

About this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
H score13 First: 18.06.2026 18:00 Last: 18.06.2026 18:00 Sources 1

About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...

Ghost Networks crypto-clipper promotion campaign

Campaign
H score15 First: 17.06.2026 21:14 Last: 17.06.2026 21:14 Sources 1

About this happening: Unknown threat actor is running an active June 2026 campaign that fakes legitimacy to distribute a Rust-based clipboard hijacker. The operation uses bogus GitHub sta...

Rust-based clipboard hijacker that swaps wallet addresses

Malware Activity
H score10 First: 17.06.2026 21:14 Last: 17.06.2026 21:14 Sources 1

About this happening: The Rust-based clipper is a Windows and macOS malware activity that replaces copied cryptocurrency wallet addresses with attacker-controlled destinations. It continuou...

Timeline

  1. 15.07.2026 18:30 3 articles · 13d ago

    Kaspersky details OkoBot seed-phrase theft against Ledger and Trezor users

    Initial Disclosure

    Kaspersky's GReAT team disclosed the OkoBot framework running on Windows machines since April 2025 and described SeedHunter, a module that injects fake recovery-phrase pages into Ledger Live, Ledger Wallet, and Trezor Suite to steal wallet recovery phrases. The telemetry covered hundreds of victims across more than 25 countries, with the largest share of attacked users in Brazil, Vietnam, Canada, Mexico, and Türkiye, and the delivery paths included ClickFix lures and trojanized GitHub software that deploy TookPS.

    Show sources