Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

OkoBot malware targets hardware wallet users with recovery phrase phishing

The OkoBot malware framework targets Windows users with a module designed to steal cryptocurrency wallet recovery phrases by injecting malicious code into legitimate wallet applications like Trezor Suite and Ledger Live. It displays a convincing fake interface to phish the recovery phrase when a hardware wallet is connected, while also deploying additional modules for data exfiltration, keylogging, and surveillance. The malware is distributed via phishing and trojanized software, utilizing a PowerShell downloader to establish a C2 channel.
Read Full Article →

Malware OkoBot malware targets hardware wallet users with recovery phrase phishing July 16, 2026 Share By SC Staff A malware framework known as OkoBot has been actively targeting Windows users since April 2025, with a specific module designed to steal recovery phrases from hardware cryptocurrency wallet owners. The attack involves injecting malicious code into legitimate wallet software, tricking users into revealing their sensitive recovery information, as reported by The Hacker News. The OkoBot framework, particularly its SeedHunter module, targets popular hardware wallets like Ledger and Trezor. Once a user's PC is infected, OkoBot monitors for the launch of wallet applications such as Trezor Suite, Ledger Wallet, or Ledger Live. It then injects itself into these applications and can either immediately display a fake recovery phrase input page or wait until a hardware wallet device is connected. The fake page mimics the legitimate wallet interface, prompting users to enter their recovery phrase, which is then captured by the malware. The hardware wallet itself remains secure, but the companion software is exploited to trick the user. The malware is distributed through various methods, including phishing lures and trojanized software disguised as legitimate applications like SQL Server Management Studio on GitHub. After initial infection, a PowerShell downloader called TookPS is executed, which establishes an SSH connection to an attacker-controlled server. This allows for the exfiltration of sensitive data, including wallet files, browser profiles, and credentials. OkoBot also deploys other modules for surveillance, keylogging, and installing malicious browser extensions, such as Rilide. While the specific threat actor remains unknown, indicators of compromise include specific scheduled tasks, altered system files, and hidden browser extensions. Source: The Hacker News SC Staff Related Malware MacOS ‘CrashStealer’ malware poses as crash reporter to steal credentials Laura French July 15, 2026 The malware is written in C++ and uses a signed and notarized dropper to evade Gatekeeper. Malware New Rust-based RAT named LabubaRAT impersonates NVIDIA software SC Staff July 14, 2026 LabubaRAT operates by impersonating NVIDIA's container runtime toolkit, using an executable named "nvidia-sysruntime.exe." Malware Silver Fox group uses new Rust-based MODBEACON RAT SC Staff July 10, 2026 QiAnXin, a Chinese cybersecurity company, reported that while the group's operations may appear unsophisticated due to the use of SEO poisoning and counterfeit software installers, their organizational structure is more complex, involving multiple distributors. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article