
OkoBot Tricks Crypto Users Into Running Commands
Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that…
A real malware campaign called OkoBot is infecting Windows PCs and then showing a fake “recovery phrase” prompt inside legitimate Ledger and Trezor desktop apps. Victims are tricked into typing their wallet seed phrase into a malicious page that looks like it came from the trusted app, allowing attackers to steal cryptocurrency. Kaspersky reports hundreds of victims across more than 25 countries, with notable concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye.
OkoBot is a Windows malware framework that has been active since April 2025. Once it infects a machine, it uses a module called SeedHunter that waits for a real Ledger or Trezor hardware wallet to be plugged in. Only then does it draw a hard-coded recovery phrase page styled to match that specific wallet brand, displayed inside the legitimate desktop app the victim already trusts. Because the surrounding app is genuine, the fake page can blend in convincingly and prompt victims to type their 12 or 24 word recovery phrase directly into attacker-controlled infrastructure.
Kaspersky observed two main ways OkoBot reaches victims: a ClickFix-style lure that convinces someone to run a script, and trojanized software hosted on GitHub. In one documented case, a repository advertised as SQL Server Management Studio actually shipped a modified build of Audacity with a malicious library implanted inside it, and it ranked highly for SSMS searches for several months in 2025. Both infection paths lead to a PowerShell downloader that sets the stage for later modules, including remote access capability such as SSH tunneling and enabling RDP.
The core of this attack's effectiveness is that the request for a recovery phrase does not come from a suspicious website or an obvious phishing email. It comes from inside the wallet's own desktop software, an app the user installed intentionally and has learned to trust. Victims have no reason to doubt a screen that appears to be part of the software they already rely on to manage their crypto assets. The GitHub distribution path adds another layer of misdirection: users searching for a legitimate, well-known admin tool land on a repository that appears credible and popular.
Teams handling corporate or personal crypto wallets should be trained to treat any unexpected recovery phrase request as suspicious, even when it appears inside familiar software. The key rule to reinforce: a hardware wallet's recovery flow should be confirmed on the physical device screen itself, not solely inside the desktop app. Encouraging staff, especially IT, developers, and database administrators, to download tools only from official vendor sources reduces exposure to trojanized packages. Awareness training should also cover ClickFix-style lures that push users toward running scripts, since that pattern was a primary entry point in this campaign.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
OkoBot is a Windows malware framework active since April 2025 that includes a module called SeedHunter, designed to trick hardware wallet owners into typing their recovery phrase into a fake page shown inside the real Ledger or Trezor desktop app.
Kaspersky identified two main infection paths: a ClickFix-style lure that convinces users to run a script, and trojanized software distributed on GitHub, including a repository that advertised SQL Server Management Studio but actually delivered a modified version of Audacity.
A legitimate hardware wallet recovery flow is driven by the physical device itself. If a recovery phrase request appears inside the desktop app right after plugging in the device, with nothing shown on the device's own screen, that mismatch is a strong sign of a scam.
Kaspersky reports hundreds of victims across more than 25 countries, with the largest concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye.
You plug in your Ledger, open the app, and suddenly a window says: “Type your 24-word recovery phrase to continue.” Looks legit, right? That’s OkoBot. OkoBot sneaks in from a fake GitHub repo that claims to be SQL Server Management Studio but actually installs a trojanized Audacity, or from a ClickFix-style email that makes you run a PowerShell “fix.” Once it’s on your PC, its SeedHunter module waits until you plug in a real Ledger or Trezor, then pops that fake recovery screen inside the real app. Here’s the trap: the fake page appears right inside Ledger or Trezor on Windows, and it only shows up after you plug in your device, so it feels normal. But on a real recovery, your hardware wallet’s own screen walks you through the words. If the desktop app is asking and your device screen is quiet, that’s your red flag. Your move: if any app on your PC ever asks for your full seed phrase and your Ledger or Trezor screen isn’t also guiding you, stop typing immediately and report it to security, assume OkoBot until proven otherwise.

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Victims say they downloaded a fake “Sparrow Wallet” app from Apple’s App Store that impersonated a legitimate desktop-only crypto wallet. The app tricked users…

This threat trend report describes multiple real-world APT campaigns that rely on social engineering (job offers, fake recruiters, code reviews, and…