OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
OkoBot injects fake seed-phrase prompts directly into Ledger and Trezor desktop apps on infected machines — a social-engineering vector that bypasses traditional phishing defences entirely.
Summary written by editorial AI · Source link below
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase.
On an infected PC, the request comes from inside the wallet's own desktop software. Sometimes it waits until you plug the device in first. The page is malicious. The app around it is the real one you installed, and
Editorial Analysis
By hijacking trusted desktop wallet software, OkoBot turns endpoint compromise into credential theft that no email or web filter can catch — a model attackers may replicate for enterprise credentials.
Assess whether hardware-wallet desktop apps are installed on corporate endpoints and enforce application-whitelisting policies to prevent process injection.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at THN (Feedburner) in a new tab.
More from the Threat Intel Desk
- Attackers Combo Up Evasion Tactics for BEC Phishing20 Jul
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms20 Jul
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign20 Jul
- Hackers were inside South Korea's diplomat training system for 9 months20 Jul
- Romania races to restore land registry after cyberattack disrupts property market20 Jul