
CrashStealer Tricks Users to Bypass macOS Gatekeeper
Researchers found a macOS info‑stealing malware, CrashStealer, delivered through a signed and Apple‑notarized installer so it looks legitimate and passes…
Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet files/credentials and can show a fake hardware-wallet recovery page to capture seed phrases.
Researchers describe an active campaign delivering OkoBot malware to Windows users who manage cryptocurrency. The malware steals wallet files, recovery phrases, passwords, and browser data, and it can record activity inside financial applications. Two main delivery paths are used to reach victims: fake website error or verification pages known as ClickFix scams, and malicious software promoted through GitHub repositories.
In the ClickFix path, a fake error or verification prompt persuades the user to copy and run a command in PowerShell or the Windows Run dialog. In the GitHub path, a repository mimicked the style of official Microsoft installation guides while advertising a fake version of Microsoft SQL Server Management Studio, and it appeared near the top of search results for SSMS. The download it offered instead contained a modified build with malware embedded in one of its libraries.
A notable part of the campaign is a component that targets hardware wallets. When a connected hardware wallet is detected, the malware displays a fake recovery page designed for that specific device and sends any entered seed phrase to its command server. This step is dangerous because it can happen even when everything else about the wallet software appears normal.
The campaign also reportedly uses hidden Chromium browser extensions to monitor browser activity while suppressing warnings and hiding the extension from the user, extending the malware's reach beyond the initial infection.
The attack relies on habits that feel routine to technical users: pasting a command to fix an error, downloading a tool from a search result, or entering a recovery phrase during what looks like a normal wallet workflow. Each of these actions is common enough that a fake version does not stand out unless the user pauses to question the source of the instruction.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
OkoBot is malware that targets Windows users who manage cryptocurrency, stealing wallet files, recovery phrases, passwords, and browser data, and it can record activity inside financial applications.
ClickFix attacks show fake errors or verification instructions that persuade users to copy and run commands in PowerShell or the Windows Run dialog, which leads to the malware being installed.
When a connected hardware wallet is detected, the malware displays a fake recovery page designed for the relevant device and sends any entered seed phrase to its command server.
They should use a clean device to create a new wallet and transfer the funds immediately, since changing the wallet application password will not protect assets once the recovery phrase has already been stolen.
If you manage crypto on Windows, OkoBot is hunting for one thing: your wallet and seed phrase. Here’s the trick: a fake ClickFix error page pops up and calmly tells you, “To fix this, copy this command and run it in PowerShell or Windows Run.” Or you search GitHub for SSMS, click a top result that looks like a Microsoft guide, run the installer, and behind the scenes OkoBot is stealing wallet files and popping up a fake Ledger or Trezor recovery page to grab your seed. Here’s your rule: if any website or “support” message tells you to paste commands into PowerShell or Windows Run, stop, close it, and report it, never run what a web page tells you.

Researchers found a macOS info‑stealing malware, CrashStealer, delivered through a signed and Apple‑notarized installer so it looks legitimate and passes…

A real malware campaign called OkoBot is infecting Windows PCs and then showing a fake “recovery phrase” prompt inside legitimate Ledger and Trezor desktop…

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale…

Kaspersky reports an active malware campaign (“OkoBot”) that tricks people into running malicious scripts via a ClickFix-style prompt or by downloading a fake…

AI firm ORO says a suspected North Korean attacker hijacked a real conference contact’s Telegram account and lured an employee into joining a fake Microsoft…

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims…