New OkoBot Malware Framework Steals Crypto Wallet Seed Phrases Through Infected Apps

A new malware framework called OkoBot has been discovered delivering more than 20 payloads designed to steal cryptocurrency wallet seed phrases, credentials, and other sensitive data from infected Windows machines. The threat has been active since April 2025.

Security researchers at Kaspersky identified OkoBot as one of the most dangerous crypto-stealing threats currently active. The malware operates by injecting malicious code into legitimate applications, including hardware wallet software from Ledger and Trezor, to trick users into revealing their recovery phrases.

On an infected PC, the malware can display fake prompts that appear to come from the wallet’s own desktop software, asking users to enter their seed phrase. Because the prompt appears within a legitimate-looking interface, victims may not realize their data is being compromised.

The OkoBot framework is modular, allowing attackers to deploy specific payloads depending on their target. In addition to cryptocurrency theft, it can steal browser passwords, session cookies, and other credentials stored on the infected machine.

The malware spreads through various distribution methods, including trojanized software downloads, phishing emails, and malicious advertisements. Kaspersky warns that the operators behind OkoBot are actively updating the malware to evade detection.

To protect against OkoBot and similar threats, security experts recommend never entering seed phrases into any software interface, using hardware wallets that require physical confirmation of transactions, keeping antivirus software updated, and downloading wallet software only from official sources.

This article was adapted from Kaspersky and Bleeping Computer. Read the original here.