OkoBot Windows malware framework with SeedHunter wallet phrase theft
Malware Activity
Summary
Hide ▲
Show ▼
OkoBot is a Windows malware framework that uses SeedHunter to inject fake recovery-phrase screens into Trezor Suite, Ledger Wallet, and Ledger Live to steal hardware wallet recovery phrases. Kaspersky says the campaign also delivers more than 20 payloads through ClickFix lures and malicious GitHub repositories, including chains that install TookPS, set up an SSH bot, and collect credentials, wallet files, browser data, and system details. The activity has been ongoing for more than a year, was first observed in January as an evolution of the TookPS campaign that has run since March 2025, and remained active as of the July 15 analysis. Telemetry shows hundreds of victims in more than 25 countries, with the largest share in Brazil, Vietnam, Canada, Mexico, and Türkiye.
Related Happenings
Dolphin X Windows infostealer and RAT with AI victim profiling
Malware Activity
H score29
First: 23.07.2026 13:19
Last: 23.07.2026 13:19
Sources 1
About this happening:
Dolphin X is a newly identified Windows infostealer and RAT that uses an AI Profiler to score, categorize, and rank infected users so attackers can prioritize higher...
Dolphin X Windows infostealer and RAT with AI victim profiling
Malware ActivityAbout this happening: Dolphin X is a newly identified Windows infostealer and RAT that uses an AI Profiler to score, categorize, and rank infected users so attackers can prioritize higher...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
OkoBot hardware-wallet phrase theft campaign
Campaign
H score37
First: 15.07.2026 18:30
Last: 15.07.2026 18:30
Sources 1
How related:
OkoBot activity was first observed in January as an evolution of the TookPS campaign that has been running since March 2025.
About this happening:
OkoBot is an active Windows malware campaign that has been running since April 2025 and now spans hundreds of victims across more than 25 countries. It uses ...
OkoBot hardware-wallet phrase theft campaign
CampaignHow related: OkoBot activity was first observed in January as an evolution of the TookPS campaign that has been running since March 2025.
About this happening: OkoBot is an active Windows malware campaign that has been running since April 2025 and now spans hundreds of victims across more than 25 countries. It uses ...
Y2K Operators Millenium RAT social-engineering distribution campaign
Campaign
H score73
First: 29.06.2026 17:30
Last: 29.06.2026 17:30
Sources 1
About this happening:
The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Y2K Operators Millenium RAT social-engineering distribution campaign
CampaignAbout this happening: The Y2K Operators are running a social-engineering distribution campaign that spreads Millenium RAT through booby-trapped downloads, exposing users to remote compr...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware Activity
H score13
First: 18.06.2026 18:00
Last: 18.06.2026 18:00
Sources 1
About this happening:
A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Rust-based clipboard hijacker spreading via fake crypto tools
Malware ActivityAbout this happening: A Rust-based clipboard hijacker is spreading through fake crypto tools and silently replacing copied wallet addresses, putting Windows and macOS users at risk of theft...
Timeline
-
15.07.2026 18:30 3 articles · 13d ago
OkoBot SeedHunter steals hardware wallet recovery phrases on Windows
Initial DisclosureKaspersky's GReAT team detailed OkoBot on Windows, describing SeedHunter as a module that injects fake recovery-phrase pages into Trezor Suite, Ledger Wallet, and Ledger Live to steal hardware wallet recovery phrases. Telemetry tied to the malware shows hundreds of victims across more than 25 countries, with the largest share in Brazil, Vietnam, Canada, Mexico, and Türkiye, and the framework remained active as of July 15, 2026.
Show sources
- OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps — thehackernews.com — 15.07.2026 18:30
- OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps — thehackernews.com — 15.07.2026 18:30
- New OkoBot framework deploys 20 payloads to steal data, crypto — www.bleepingcomputer.com — 16.07.2026 22:09