hacker-news · Crawled Jul 15, 2026

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

9 IoCs 2 Malware
Read original article ↗

AI Summary

OkoBot is a malware framework targeting Windows users, active since April 2025, that injects phishing pages into legitimate cryptocurrency wallet applications like Ledger Live and Trezor Suite to steal recovery phrases. One of its modules, SeedHunter, hooks into Electron-based apps and waits for hardware wallet connections before displaying a malicious recovery page. The framework uses trojanized software and phishing lures to gain access, establishes persistent remote access via SSH and RDP, and deploys multiple surveillance and data-stealing plugins. Kaspersky attributes the campaign to an unknown actor but notes Russian-language artifacts and targeting patterns.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 9 extracted

Type Value Detail
Domain moonsand[[.]]store Details →
Filename go.bat Details →
Filename hwid.dat Details →
Filename HDUtil.exe Details →
Filename protobuf.dll Details →
Filename termsrv.dll Details →
Filename Apple Sync Details →
Package Rilide Details →
GitHub Repo SQL Server Management Studio Details →

MITRE ATT&CK TTPs 31 techniques