hacker-news · Crawled Jul 15, 2026
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
9 IoCs 2 Malware
Read original article ↗
AI Summary
OkoBot is a malware framework targeting Windows users, active since April 2025, that injects phishing pages into legitimate cryptocurrency wallet applications like Ledger Live and Trezor Suite to steal recovery phrases. One of its modules, SeedHunter, hooks into Electron-based apps and waits for hardware wallet connections before displaying a malicious recovery page. The framework uses trojanized software and phishing lures to gain access, establishes persistent remote access via SSH and RDP, and deploys multiple surveillance and data-stealing plugins. Kaspersky attributes the campaign to an unknown actor but notes Russian-language artifacts and targeting patterns.
AI-extracted · verify before operational use
Extracted Entities 2 found
Indicators of Compromise 9 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | moonsand[[.]]store | Details → |
| Filename | go.bat | Details → |
| Filename | hwid.dat | Details → |
| Filename | HDUtil.exe | Details → |
| Filename | protobuf.dll | Details → |
| Filename | termsrv.dll | Details → |
| Filename | Apple Sync | Details → |
| Package | Rilide | Details → |
| GitHub Repo | SQL Server Management Studio | Details → |
MITRE ATT&CK TTPs 31 techniques
T1003 OS Credential Dumping · Credential Access T1013 T1013 T1021.001 Remote Desktop Protocol · Lateral Movement T1027 Obfuscated Files or Information · Defense Evasion T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1070.004 File Deletion · Defense Evasion T1078.001 Default Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1136.001 Local Account · Persistence T1218.011 Rundll32 · Defense Evasion T1548.002 Bypass User Account Control · Privilege Escalation T1557 Adversary-in-the-Middle · Credential Access T1566 Phishing · Initial Access T1016 System Network Configuration Discovery · Discovery T1048 Exfiltration Over Alternative Protocol · Exfiltration T1056.001 Keylogging · Collection T1056.002 GUI Input Capture · Collection T1059.004 Unix Shell · Execution T1069.001 Local Groups · Discovery T1071.001 Web Protocols · Command And Control T1071.004 DNS · Command And Control T1083 File and Directory Discovery · Discovery T1204.002 Malicious File · Execution T1210 Exploitation of Remote Services · Lateral Movement T1485 Data Destruction · Impact T1499.004 Application or System Exploitation · Impact T1543.001 Launch Agent · Persistence