OkoBot Malware Framework Injects Seed-Phrase Phishing Pages Into Ledger and Trezor Wallet Apps
OkoBot Malware Framework Injects Seed-Phrase Phishing Pages (TL-2026-1383), also tracked as OkoBot Framework, is a high-severity malware campaign, first published 2026-07-15. It has no confirmed attribution, affects Ledger Ledger Live, maps to 33 MITRE ATT&CK techniques (T1021, T1027, T1041), and is covered by 9 detection rules and 42 indicators of compromise.
Key facts for TL-2026-1383
- Threat ID
- TL-2026-1383
- Also known as
- OkoBot Framework, SeedHunter Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-15
- Last reviewed
- 2026-07-15
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, finance, consumer individuals
- Target regions
- brazil, vietnam, canada, mexico, Turkiye, 005 - South America, North America, Southeast Asia, Europe
- Detection rules
- 9
- Indicators of compromise
- 42
Malware and tooling in OkoBot Malware Framework Injects Seed-Phrase Phishing Pages
Malware and tooling: HDUtil, MC Keylogger, OkoBot, OkoSpyware, Rilide, SeedHunter, TeviRAT, TookPS, Volume2
OkoBot is a modular crimeware framework active since April 2025, comprising 20+ payloads for cryptocurrency theft and surveillance. Its SeedHunter module hooks Ledger Live, Ledger Wallet, and Trezor Suite Electron internals to inject hard-coded seed-phrase phishing pages, while companion modules (OkoSpyware, MC Keylogger, Rilide) exfiltrate credentials, keystrokes, and browser data. Kaspersky GReAT reports hundreds of victims across 25+ countries as of July 2026, with no attribution to a known crimeware actor.
How OkoBot Malware Framework Injects Seed-Phrase Phishing Pages works
OkoBot is a modular malware platform first observed via its TookPS PowerShell downloader in March 2025 and formally profiled by Kaspersky's Global Research and Analysis Team (GReAT) in a July 15, 2026 Securelist report. The framework has evolved through two distinct infection-chain generations. In the original chain (January-April 2025), TookPS - delivered via ClickFix social-engineering lures or trojanized GitHub repositories (e.g., a repo advertised as SQL Server Management Studio that actually shipped a backdoored Audacity build) - installed a reverse SSH tunnel maintained by a scheduled task named 'Apple Sync', then deployed the VMProtect-packed HDUtil launcher, which in turn dropped extl.exe to inject malicious unpacked browser extensions, the TeviRAT backdoor, and the Rilide Chromium-stealer extension. In the updated chain (March 2026 onward), TeviRAT was removed and HDUtil was replaced by Volume2, a hijacked open-source plugin dispatcher that polls its C2 every 20 seconds over a custom protobuf.dll/version.dll loader and directly deploys ext_daemon, SeedHunter, MC Keylogger, and OkoSpyware as plugins exporting RegisterPlugin/PluginDispatch.
The centerpiece module, SeedHunter, monitors for USB attachment of genuine Ledger or Trezor hardware wallets by vendor/product ID and, once detected, hooks Electron internals in Ledger Live, Ledger Wallet, or Trezor Suite to render a hard-coded, brand-specific fake recovery-phrase entry screen. Captured seed phrases are exfiltrated to the dedicated C2 domain moonsand[.]store as a JSON payload containing App, Build, DeviceName, DeviceHardwareId, and SeedData fields. Persistence and lateral-access tradecraft include patching termsrv.dll to permit concurrent RDP sessions, adding accounts to the Remote Desktop Users group, opening inbound RDP through the Windows Firewall, and an hourly-rebuilt reverse SSH tunnel. A UAC bypass abuses auto-elevated msconfig.exe via Windows RPC from JavaScript (a technique documented by Google Project Zero in 2019). Anti-analysis measures include VMProtect obfuscation on HDUtil/extl.exe, AES-GCM (256-bit key/96-bit nonce) payload encryption, AES-CBC C2 traffic encryption (with insecure 0xFF-byte default keys/IVs when not reconfigured), RC4 keyed by a per-victim hardware ID (HWID) for exfiltrated data, MurmurHash3-based export-table function resolution for stripped binaries, and geoblocking of Russian/CIS IP ranges on first-stage PowerShell infrastructure. Complementary modules OkoSpyware (video/keystroke capture) and MC Keylogger (keystrokes, clipboard including copied images/files, USB device logs, five-minute screenshots) stage output locally with timestamp/format-coded filenames (bf_, sc_, sh_, oko_, media_) before exfiltrating via an ir-post.php endpoint and clearing PowerShell command history afterward. Beyond hardware wallets, the framework also targets the Exodus and Litecoin-QT desktop wallets, MetaMask and Tonkeeper browser-extension wallets, and the KeePassXC and 1Password password managers, installing malicious browser extensions into a non-standard 'Local Extension Settings' directory with a custom_args manifest field carrying the victim HWID and browser name to evade the standard extensions list. Kaspersky's telemetry shows hundreds of victims concentrated in Brazil, Vietnam, Canada, Mexico, and Turkiye across more than 25 countries, with the earliest TookPS activity in March 2025 and continuous framework evolution through March 2026. Kaspersky explicitly declines attribution to any known crimeware actor, though it notes soft signals - Russian-language comments embedded in the SeedHunter phishing page source and distribution of the Rilide stealer on Russian-speaking cybercrime forums - that it treats as inconclusive given the deliberate CIS-region geoblocking on the operators' own infrastructure.
MITRE ATT&CK techniques used in TL-2026-1383
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1564 Hide Artifacts
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1204 User Execution
Persistence
T1053 Scheduled Task/Job; T1133 External Remote Services; T1136 Create Account; T1176 Software Extensions
Privilege Escalation
T1053 Scheduled Task/Job; T1548 Abuse Elevation Control Mechanism
Credential Access
T1056 Input Capture; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Command and Control
T1071 Application Layer Protocol; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling; T1573 Encrypted Channel
Collection
T1074 Data Staged; T1113 Screen Capture; T1115 Clipboard Data; T1125 Video Capture
Discovery
T1087 Account Discovery; T1120 Peripheral Device Discovery; T1518 Software Discovery
defense-impairment
T1112 Modify Registry; T1685 Disable or Modify Tools
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1566 Phishing
Impact
Affected products and versions in OkoBot Malware Framework Injects Seed-Phrase Phishing Pages
- Ledger — Ledger Live
Vulnerable versions: all versions targeted via Electron internals hooking, not a code vulnerability - Ledger — Ledger Wallet
Vulnerable versions: all versions targeted via Electron internals hooking, not a code vulnerability - Trezor — Trezor Suite
Vulnerable versions: all versions targeted via Electron internals hooking, not a code vulnerability - Exodus — Exodus Wallet
Vulnerable versions: all versions, targeted by credential-stealing modules - Litecoin Project — Litecoin-QT
Vulnerable versions: all versions, targeted by credential-stealing modules - Consensys — MetaMask
Vulnerable versions: all versions, browser-extension credentials targeted - Tonkeeper — Tonkeeper Wallet
Vulnerable versions: all versions, browser-extension credentials targeted - KeePassXC — KeePassXC
Vulnerable versions: all versions, local vault credentials targeted - AgileBits — 1Password
Vulnerable versions: all versions, local credentials/session data targeted
Remediation for OkoBot Malware Framework Injects Seed-Phrase Phishing Pages
Immediate actions
- Block C2 domains moonsand[.]store, 2baserec2[.]guru, recavb22[.]online, kbeautyreviews[.]com, coffeesaloon[.]online, livewallpapers[.]online, and thatwascringe[.]com at DNS/proxy layer
- Block SSH-bot IPs 104.243.43[.]16, 104.243.32[.]213, and 62.210.188[.]209 at perimeter firewalls
- Hunt for scheduled task 'Apple Sync' on endpoints as a high-confidence persistence indicator
- Audit Remote Desktop Users group membership and inbound RDP firewall rules for unauthorized additions
- Verify termsrv.dll integrity/hash against known-good vendor baseline on Windows hosts
- Search for artifact files: %PROGRAMDATA%\hwid.dat, %PROGRAMDATA%\HDVideo\HDUtil.exe, %PROGRAMDATA%\oko_ver, %USERPROFILE%\.ssh\go.bat, %APPDATA%\Local Extension Settings
Workarounds
- Only enter hardware-wallet recovery/seed phrases on the physical device screen, never inside a desktop companion application window
- Disable inbound RDP unless explicitly required and monitored
Longer-term hardening
- Deploy EDR behavioral detection for termsrv.dll modification and concurrent-RDP-session tampering
- Enforce hardware-wallet PIN/passphrase verification directly on device screen, never trusting host-rendered recovery prompts
- Block execution of unsigned/unexpected browser extensions installed outside standard extension directories
- Restrict or monitor GitHub repository downloads and PowerShell execution policy for consumer/enterprise endpoints
- User awareness training on ClickFix-style 'paste this command to fix an error' social-engineering lures
Weaknesses (CWE) in OkoBot Malware Framework Injects Seed-Phrase Phishing Pages
CWE-506, CWE-494, CWE-350, CWE-311, CWE-522
Timeline of OkoBot Malware Framework Injects Seed-Phrase Phishing Pages
- Google Project Zero (Issue 1988) publicly documents the Windows RPC-servers-from-JavaScript technique for auto-elevated msconfig.exe abuse, later reused by OkoBot's UAC-bypass component
- First TookPS campaign observed, delivering a Python-based infostealer and an SSH-tunnel installer as the earliest known OkoBot-linked activity
- Trojanized GitHub repository advertised as SQL Server Management Studio (actually a backdoored Audacity build) created; TookPS PowerShell downloader campaign begins
- Second TookPS wave emerges with the TeviRAT backdoor payload substituted in, expanding the OkoBot infection chain
- Complete attack chain redesign at end of April: TookPS narrowed to initial infection only, automated SSH bot added for payload delivery, HDUtil launcher and extl.exe extension injector introduced alongside the Rilide stealer
- Malicious trojanized GitHub repository taken down after roughly two to three months of active distribution
- Kaspersky identifies multiple additional attacks using the OkoBot framework, including malware capturing cryptocurrency-wallet window contents, across new victim geographies
- Framework rebuilt: TeviRAT backdoor removed, Volume2 plugin dispatcher installed directly via TookPS and replaces HDUtil for direct plugin deployment (ext_daemon, SeedHunter, MC Keylogger, OkoSpyware); protobuf.dll loader renamed to version.dll while retaining the modified ProtoBuf library contents
- Kaspersky GReAT publishes full technical teardown on Securelist; The Hacker News and other outlets report hundreds of victims across 25+ countries, concentrated in Brazil, Vietnam, Canada, Mexico, and Turkiye
Sources cited for OkoBot Malware Framework Injects Seed-Phrase Phishing Pages
- OkoBot Malware Framework Injects Seed Phrase Phishing Pages Into Ledger Wallets and Trezor Suite
- OkoBot framework targets cryptocurrency wallets
- OkoBot: new sophisticated malware framework targets cryptocurrency users
- Cryptohack Roundup: Malware Targets Wallets via Photos
- Issue 1988: Windows RPC servers from JavaScript (UAC bypass technique)
Threats related to OkoBot Malware Framework Injects Seed-Phrase Phishing Pages
- OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter)
- macOS Info-Stealer Chains Fake Password Prompt, Telegram Session Theft, and Crypto Wallet App Replacement
- Fake Roblox Xeno Script Launcher Pushes Multi-Stage Java-Based Infostealer and RAT Malware (Powercat Campaign)
- MacSync Stealer v1.1.2 ("claude1"): Malicious Google Ad Impersonates Claude Code Installer to Hijack macOS Systems
- SHub Reaper - macOS Stealer Variant Bypasses Tahoe 26.4 Terminal Mitigation via applescript:// URL Scheme, Spoofs Apple/Google/Microsoft (SentinelOne)
- macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain, Browser Credentials, Apple Notes, and 16 Crypto Wallets
Detection coverage for TL-2026-1383
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1383 across Splunk SPL, Microsoft KQL and Sigma, covering 42 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.