phishing
OkoBot Fakes Ledger and Trezor Recovery Prompts From Inside
2026-07-16

A Windows malware framework called OkoBot has been quietly working the crypto wallet crowd since April 2025, and its cleverest move is asking you for your recovery phrase from inside the wallet app you actually installed.
Here is how it plays out. Once OkoBot lands on the machine, a module called SeedHunter watches for Trezor Suite, Ledger Wallet, or Ledger Live and hooks into the app's Electron internals. When its command server gives the nod, it draws a hard-coded recovery page over the real app, with a bespoke layout per brand. Sometimes it waits until you plug the hardware wallet in over USB, which makes the prompt feel like a legitimate part of setup. Type the 24 words and they leave as JSON, with an RC4-encrypted copy stashed in a temp folder for good measure.
Hundreds of victims, 25+ countries
Kaspersky's GReAT team published the teardown this week and counted hundreds of victims across more than 25 countries. Brazil, Vietnam, Canada, Mexico and T\u00fcrkiye are taking the biggest share.
The framework is not a one-trick tool. It carries more than 20 payloads, including:
- OkoSpyware, which films wallet windows to MP4
- A keylogger
- Hidden Chromium extensions loaded with the Rilide stealer
Delivery is through ClickFix lures and trojanised software on GitHub. One standout was a fake SQL Server Management Studio repo that actually shipped a tampered Audacity build, and it ranked top in search results from late March to June.
The hardware wallet is not the problem
The device itself does exactly what it was built to do, which is refuse to hand over the key. What it cannot do is stop the companion app on your PC from asking you for the phrase instead.
Ledger has always said the phrase never leaves the device. Trezor Suite says it will never prompt you to type your backup. So a recovery page that appears because you plugged the device in, while the device screen shows nothing, is the giveaway.
No patch is coming
There is no CVE here and no vendor fix on the way, because the compromise sits on the endpoint long before the wallet software opens. The malware is already home by the time you double-click the app.
Which puts the whole thing back where these stories usually end up. On whoever is sitting at the keyboard, and whether they recognise a prompt that should never have appeared. Twenty-four words is a lot to type into a screen you weren't expecting. It is also a lot to lose.