CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2616

As cited

Copy frozen at (site build).

threat intel

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

OkoBot is a malware framework active on Windows systems since April 2025 that includes a module designed to steal seed phrases from hardware wallet users. The malware injects phishing prompts into legitimate Ledger and Trezor desktop applications, exploiting user trust in the authentic software interface.

Why it matters: Cryptocurrency and hardware wallet users on Windows are at immediate risk of losing recovery phrases and funds if their machines are compromised. Security practitioners should alert clients to the threat and recommend endpoint protection, offline wallet management, and suspicious prompt verification.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps

OkoBot is a malware framework active on Windows systems since April 2025 that includes a module designed to steal seed phrases from hardware wallet users. The malware injects phishing prompts into legitimate Ledger and Trezor desktop applications, exploiting user trust in the authentic software interface.

Why it matters: Cryptocurrency and hardware wallet users on Windows are at immediate risk of losing recovery phrases and funds if their machines are compromised. Security practitioners should alert clients to the threat and recommend endpoint protection, offline wallet management, and suspicious prompt verification.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary