OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
CYBERSECURITY FEATURED ANALYSIS

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

BY

The Hacker News

SOURCE

The Hacker News

DATE

READ

1 min read

A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes …

A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet’s own desktop software. Sometimes it waits until you plug the device in first. The page is malicious. The app around it is the real one you installed, and