Kaspersky Uncovers OkoBot Dangerous Malware Targeting Crypto Wallet Seed Phrases

Cybersecurity firm Kaspersky has identified a malware framework called OkoBot that has been operating on Windows machines since April 2025, with one of its modules specifically designed to steal recovery seed phrases from hardware cryptocurrency wallet applications, according to the company’s research.

The malware targets users of popular hardware wallets including Ledger and Trezor. It operates by injecting phishing pages into the legitimate desktop applications of these wallets, prompting users to enter their seed phrases under the pretense of a security verification or firmware update. The fake pages are designed to closely mimic the official wallet interfaces, making them difficult to distinguish from legitimate prompts.

OkoBot is deployed through a multi-stage infection chain that typically begins with a malicious download or email attachment. Once installed on a victim’s computer, the malware lies dormant until it detects that a hardware wallet has been connected via USB. At that point, it activates its wallet-targeting module and displays the phishing prompt.

Kaspersky said OkoBot is one of the most dangerous crypto-stealing malware frameworks currently in circulation due to its sophisticated evasion techniques and focus on hardware wallet users, who are typically considered more security-conscious than software wallet users. The malware can also capture screenshots, log keystrokes, and exfiltrate browser-stored passwords.

The security firm advised hardware wallet owners to always verify that any prompts appearing in their wallet software are legitimate by checking the application’s official website and support channels. Users should never enter their seed phrase into any digital form, as legitimate wallet software never requests it.

Ledger and Trezor have both published guidance on their websites warning users about phishing attacks and emphasizing that they will never ask for seed phrases through software prompts.

This article was adapted from U.Today. Read the original here.