OkoBot Malware Framework Targets Crypto Wallet Seed Phrases From Trezor and Ledger Users

A newly identified malware framework called OkoBot has been targeting cryptocurrency hardware wallet users by injecting seed phrase phishing prompts into legitimate wallet applications. The malware, discovered by Kaspersky researchers, has been operating on Windows machines since April 2025 and represents a sophisticated threat to cryptocurrency investors.

OkoBot operates by injecting malicious code into the desktop applications of popular hardware wallet brands, including Trezor and Ledger. When a user connects their hardware wallet to an infected computer, OkoBot displays a convincing but fake interface requesting the devices recovery seed phrase. Unsuspecting users who enter their seed phrase hand over complete control of their cryptocurrency funds to the attackers.

The malware framework is modular in design, allowing its operators to deploy different payload modules depending on the target. Beyond seed phrase theft, OkoBot can also capture screenshots, log keystrokes, and exfiltrate other sensitive data from infected systems. The framework uses social engineering tactics, including trojanized GitHub applications, to trick users into installing the malware voluntarily.

Kaspersky researchers said the OkoBot campaign has been active for over a year, with multiple versions of the malware detected in the wild. The malware authors have continuously updated the framework to evade antivirus detection and add support for new wallet applications.

Security experts recommend that cryptocurrency users verify the authenticity of any software they download, particularly wallet management tools. Hardware wallet users should always enter their seed phrase directly on the device itself, never on a computer screen, as legitimate wallet software never requests the seed phrase through a desktop interface.