Find notable cyber news and cases, enriched with sources, timelines, and signals.

OkoBot Windows malware framework with SeedHunter wallet phrase theft

Malware Activity
First reported
Last updated
Happening score
H score 31
2 unique sources, 2 articles

Summary

Hide ▲

OkoBot is a Windows malware framework that uses SeedHunter to inject fake recovery-phrase screens into Trezor Suite, Ledger Wallet, and Ledger Live to steal hardware wallet recovery phrases. Kaspersky says the campaign also delivers more than 20 payloads through ClickFix lures and malicious GitHub repositories, including chains that install TookPS, set up an SSH bot, and collect credentials, wallet files, browser data, and system details. The activity has been ongoing for more than a year, was first observed in January as an evolution of the TookPS campaign that has run since March 2025, and remained active as of the July 15 analysis. Telemetry shows hundreds of victims in more than 25 countries, with the largest share in Brazil, Vietnam, Canada, Mexico, and Türkiye.

Related Happenings

Dolphin X Windows infostealer and RAT with AI victim profiling

Malware Activity
H score29 First: 23.07.2026 13:19 Last: 23.07.2026 13:19 Sources 1

About this happening: Dolphin X is a newly identified Windows infostealer and RAT that uses an AI Profiler to score, categorize, and rank infected users so attackers can prioritize higher...

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

OkoBot hardware-wallet phrase theft campaign

Campaign
H score37 First: 15.07.2026 18:30 Last: 15.07.2026 18:30 Sources 1

How related: OkoBot activity was first observed in January as an evolution of the TookPS campaign that has been running since March 2025.

About this happening: OkoBot is an active Windows malware campaign that has been running since April 2025 and now spans hundreds of victims across more than 25 countries. It uses ...

Y2K Operators Millenium RAT social-engineering distribution campaign

Campaign
H score73 First: 29.06.2026 17:30 Last: 29.06.2026 17:30 Sources 1

About this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...

Rust-based clipboard hijacker spreading via fake crypto tools

Malware Activity
H score13 First: 18.06.2026 18:00 Last: 18.06.2026 18:00 Sources 1

About this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...

Timeline

  1. 15.07.2026 18:30 3 articles · 13d ago

    OkoBot SeedHunter steals hardware wallet recovery phrases on Windows

    Initial Disclosure

    Kaspersky's GReAT team detailed OkoBot on Windows, describing SeedHunter as a module that injects fake recovery-phrase pages into Trezor Suite, Ledger Wallet, and Ledger Live to steal hardware wallet recovery phrases. Telemetry tied to the malware shows hundreds of victims across more than 25 countries, with the largest share in Brazil, Vietnam, Canada, Mexico, and Türkiye, and the framework remained active as of July 15, 2026.

    Show sources