OkoBot Malware Framework Injects Seed-Phrase Phishing Pages Into Ledger and Trezor Wallet Apps — Threadlinqs Intelligence
As of 2026-07-15, OkoBot Malware Framework Injects Seed-Phrase Phishing Pages Into Ledger and Trezor Wallet Apps is a high-severity malware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 42 indicators of compromise.
Threat ID: TL-2026-1383 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
OkoBot is a modular crimeware framework active since April 2025, comprising 20+ payloads for cryptocurrency theft and surveillance. Its SeedHunter module hooks Ledger Live, Ledger Wallet, and Trezor
OkoBot is a modular malware platform first observed via its TookPS PowerShell downloader in March 2025 and formally profiled by Kaspersky's Global Research and Analysis Team (GReAT) in a July 15, 2026 Securelist report. The framework has evolved through two distinct infection-chain generations. In the original chain (January-April 2025), TookPS - delivered via ClickFix social-engineering lures or trojanized GitHub repositories (e.g., a repo advertised as SQL Server Management Studio that actually shipped a backdoored Audacity build) - installed a reverse SSH tunnel maintained by a scheduled task named 'Apple Sync', then deployed the VMProtect-packed HDUtil launcher, which in turn dropped extl.exe to inject malicious unpacked browser extensions, the TeviRAT backdoor, and the Rilide Chromium-stealer extension. In the updated chain (March 2026 onward), TeviRAT was removed and HDUtil was replaced by Volume2, a hijacked open-source plugin dispatcher that polls its C2 every 20 seconds over a custom protobuf.dll/version.dll loader and directly deploys ext_daemon, SeedHunter, MC Keylogger, and OkoSpyware as plugins exporting RegisterPlugin/PluginDispatch.
The centerpiece module, SeedHunter, monitors for USB attachment of genuine Ledger or Trezor hardware wallets by vendor/product ID and, once detected, hooks Electron internals in Ledger Live, Ledger Wallet, or Trezor Suite to render a hard-coded, brand-specific fake recovery-phrase entry screen. Captured seed phrases are exfiltrated to the dedicated C2 domain moonsand[.]store as a JSON payload containing App, Build, DeviceName, DeviceHardwareId, and SeedData fields. Persistence and lateral-access tradecraft include patching termsrv.dll to permit concurrent RDP sessions, adding accounts to the Remote Desktop Users group, opening inbound RDP through the Windows Firewall, and an hourly-rebuilt reverse SSH tunnel. A UAC bypass abuses auto-elevated msconfig.exe via Windows RPC from JavaScript (a technique documented by Google Project Zero in 2019). Anti-analysis measures include VMProtect obfuscation on HDUtil/extl.exe, AES-GCM (256-bit key/96-bit nonce) payload encryption, AES-CBC C2 traffic encryption (with insecure 0xFF-byte default keys/IVs when not reconfigured), RC4 keyed by a per-victim hardware ID (HWID) for exfiltrated data, MurmurHash3-based export-table function resolution for stripped binaries, and geoblocking of Russian/CIS IP ranges on first-stage PowerShell infrastructure. Complementary modules OkoSpyware (video/keystroke capture) and MC Keylogger (keystrokes, clipboard including copied images/files, USB device logs, five-minute screenshots) stage output locally with timestamp/format-coded filenames (bf_, sc_, sh_, oko_, media_) before exfiltrating via an ir-post.php endpoint and clearing PowerShell command history afterward. Beyond hardware wallets, the framework also targets the Exodus and Litecoin-QT desktop wallets, MetaMask and Tonkeeper browser-extension wallets, and the KeePassXC and 1Password password managers, installing malicious browser extensions into a non-standard 'Local Extension Settings' directory with a custom_args manifest field carrying the victim HWID and browser name to evade the standard extensions list. Kaspersky's telemetry shows hundreds of victims concentrated in Brazil, Vietnam, Canada, Mexico, and Turkiye across more than 25 countries, with the earliest TookPS activity in March 2025 and continuous framework evolution through March 2026. Kaspersky explicitly declines attribution to any known crimeware actor, though it notes soft signals - Russian-language comments embedded in the SeedHunter phishing page source and distribution of the Rilide stealer on Russian-speaking cybercrime forums - that it treats as inconclusive given the deliberate CIS-region geoblocking on the operators' own infrastructure.
Weaknesses (CWE)
CWE-506, CWE-494, CWE-350, CWE-311, CWE-522
Target sectors: cryptocurrency, finance, consumer individuals
Target regions: brazil, vietnam, canada, mexico, Turkiye, 005 - South America, North America, Southeast Asia, Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 42 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1195, T1199, T1059, T1204, T1053, T1053, T1176, T1136, T1133