VMTech
Discuss a project

OkoBot hides phishing recovery phrases inside Ledger and Trezor apps

OkoBot hides phishing recovery phrases inside Ledger and Trezor apps

Colleagues, I want to flag a cyberthreat update.

I reviewed Kaspersky’s analysis: since April 2025, OkoBot has been infecting Windows systems and replacing seed phrase prompts inside Ledger Live, Ledger Wallet, and Trezor Suite.

It spreads via ClickFix and GitHub-hosted trojanized software. Telemetry points to hundreds of victims across more than 25 countries.

For hunting, I would look for Apple Sync, a modified termsrv.dll, anomalous SSH activity, and hidden Chromium extensions.

Why it matters: this is phishing embedded in a legitimate application, not a device request. To protect a crypto wallet, verify the recovery phrase only on the device itself.

Have you already implemented this control in your environment?

#cybersecurity #malware #phishing #Windows

Open analytics
On the site 5 views
min read 1 15.07.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

OkoBot hides phishing recovery phrases inside Ledger and Trezor apps

Open the post on Instagram ↗