OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps 5%

By Swati Khandelwal12%

7/15/2026, 3:30:00 PM

BS Summary: This article contains 24 faulty reasoning types, including Ambiguity (Equivocation), Biased Writer Voice, and Appeal to Authority, with Overconfidence Bias as the most egregious example at 14.4% saturation with 144 hits. Analysis detected 1,215 faulty-reasoning hits from 1,003 analyzed words, generating a BS Score of 19.1% and a BS Rank of 5% (20,259 of 21,145 articles). This article is better (less manipulative) than 95.80% of the article peer group.

A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. 
On an infected PC, the request comes from inside the wallet's own desktop software. 
Sometimes it waits until you plug the device in first. 
The page is malicious. 
The app around it is the real one you installed, and the phrase is the wallet. 
Kaspersky's GReAT team published the teardown on Wednesday, counting hundreds of victims in its telemetry across more than 25 countries. 
The largest share of attacked users is in Brazil, Vietnam, Canada, Mexico, and Türkiye. 
How many of them typed a phrase in, the report does not say. 
OkoBot carries more than 20 payloads and implants and was still active as of the July 15 report. 
SeedHunter Waits for the Device 
SeedHunter is the OkoBot module that steals the phrase. 
Once the framework lands, it watches for Trezor Suite, Ledger Wallet, and Ledger Live, injects into whichever it finds, and hooks the app's Electron internals. 
Then it asks its C2 at moonsand[.]store. 
If the server sets a Wait flag, SeedHunter scans USB by vendor and product ID and sits still until a real Ledger or Trezor is plugged in. 
Only then does it draw a hard-coded recovery page, one layout per brand. 
With the flag off, the page appears immediately. 
The typed phrase goes to the page's own console behind an @:app:print marker, and the hooked mal_LogConsoleMessage picks it up. 
It leaves as JSON, with an RC4 copy dropped in a temp file. 
The hardware wallet is not what gets broken. 
It does the one thing it was built for, which is to refuse to give up the key, and it cannot stop its companion software from asking you for the phrase instead. 
Neither half of the trick is new. 
Moonlock Lab tracked macOS stealers doing the swap version, and THN covered those cloned Ledger Live apps: AMOS killed Ledger Live and dropped a trojanized clone in /Applications demanding the 24 words. 
GlassWorm did the USB trigger on Windows in March, using WMI to spot a device going in, then throwing its own window up after killing the real app. 
What SeedHunter changes is where the page gets drawn. 
It leaves the app running and draws inside it. 
The SSMS That Was Actually Audacity 
Two main ways in: a ClickFix lure, and trojanized software on GitHub. 
The repo Kaspersky pulled apart advertised SQL Server Management Studio. 
What it shipped was Audacity, the audio editor, rebuilt with a malicious implant inside one of its libraries. 
It ranked top for SSMS. 
It lived from late March 2025 to June. 
Both paths execute TookPS, a PowerShell downloader Kaspersky has tracked since March 2025, when it rode fake DeepSeek pages, then fake business-software download sites. 
It installs SSH, dials an attacker-controlled server, forwards the local SSH daemon port, and waits. 
Later, an automated SSH bot connects back through the tunnel. 
The bot inventories the box down to the installed AV, then drags wallet files, cookies, browser profiles, and credentials out through the tunnel. 
It silences Defender notifications with a registry write and builds itself a desk: 
Opens the firewall for inbound RDP 
Adds an account to the Remote Desktop Users group 
Replaces termsrv.dll with a patched build that permits concurrent RDP sessions 
Registers a scheduled task called Apple Sync that rebuilds a reverse SSH tunnel for the local RDP port every hour 
Modules arrive over SFTP after that. 
A VMProtect-packed launcher called HDUtil runs them and can elevate them silently through a Windows RPC UAC bypass that Project Zero documented in 2019. 
The last delivery is Volume2, an open-source utility carrying a malicious protobuf.dll that decrypts and starts the real payload: a plugin dispatcher polling its C2 every 20 seconds. 
Kaspersky recovered five plugins. 
One is a process injector, and that is what puts SeedHunter in place. 
The rest of the kit is surveillance. 
OkoSpyware watches for 100-plus executables, Exodus, and 1Password among them. 
It films the matching window to MP4 with a bundled FFmpeg and logs keystrokes into it. 
Browser titles get regex-matched, so a MetaMask or Tonkeeper tab gets recorded. 
MC Keylogger covers input, clipboard, USB devices, and takes a screenshot every five minutes. 
A loader installs hidden Chromium extensions with every permission granted; Rilide, a Chromium stealer used by Russian-speaking threat actors since April 2023, is what it installed. 
Whose Framework Is It? 
Kaspersky will not name an actor: "we can't attribute this malicious campaign to any known crimeware actor." 
The servers hosting the first-stage PowerShell return an empty response to Russian and CIS IPs. 
Rilide moves on invitation-only Russian-speaking forums. 
The SeedHunter phishing pages carry Russian comments. 
Those are soft signals, and the report treats them as such. 
There is no wallet CVE and no vendor patch that closes this route. 
It lands on the endpoint instead, and the artifacts are specific enough to hunt: 
A scheduled task named Apple Sync 
%PROGRAMDATA%\hwid.dat, %PROGRAMDATA%\HDVideo\HDUtil.exe, %USERPROFILE%\.ssh\go.bat 
termsrv.dll altered from its shipped build 
Accounts in Remote Desktop Users that nobody added 
Outbound SSH from user endpoints 
Extensions in Local Extension Settings that never appear in the browser's extension list 
Kaspersky's post has the hashes and C2 domains. 
The vendors draw the line at the device. 
Ledger says the phrase never goes anywhere but the Ledger itself. 
Trezor Suite says it will never ask you to type your backup, though a Model One's standard recovery does take the words in Suite, and only when the device asks. 
A page that appears because you plugged in, with nothing on the device screen behind it, is the tell. 
Then the March 2026 rebuild. 
TeviRAT is gone. 
The HDUtil to extl to Rilide chain is gone, folded into a single dispatcher plugin that does the same job. 
Volume2 now comes straight from TookPS. 
Nobody prunes a codebase they are about to walk away from. 
Article reasoning-pattern comparisonThis article: 6.7%Swati Khandelwal: 2.5%The Hacker News: 2.0%Confirmation Bias6.7%This article: 1.4%Swati Khandelwal: 1.5%The Hacker News: 1.2%Anchoring Bias1.4%This article: 7.9%Swati Khandelwal: 3.6%The Hacker News: 3.3%Availability Heuristic7.9%This article: 4.9%Swati Khandelwal: 1.4%The Hacker News: 1.4%Representativeness Heuristic4.9%This article: 2.8%Swati Khandelwal: 0.6%The Hacker News: 0.6%Hindsight Bias2.8%This article: 14.4%Swati Khandelwal: 2.5%The Hacker News: 2.5%Overconfidence Bias14.4%This article: 6.0%Swati Khandelwal: 2.9%The Hacker News: 2.9%Framing Effect6.0%This article: 0.0%Swati Khandelwal: 0.9%The Hacker News: 1.1%Loss Aversion0.0%This article: 0.0%Swati Khandelwal: 0.6%The Hacker News: 0.6%Status Quo Bias0.0%This article: 2.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Sunk Cost Effect2.0%This article: 1.4%Swati Khandelwal: 1.2%The Hacker News: 1.3%Optimism Bias1.4%This article: 3.2%Swati Khandelwal: 1.9%The Hacker News: 1.6%Pessimism Bias3.2%This article: 8.1%Swati Khandelwal: 6.5%The Hacker News: 6.8%Negativity Bias8.1%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.8%Self-Serving Bias0.0%This article: 1.1%Swati Khandelwal: 0.4%The Hacker News: 0.4%Fundamental Attribution Error1.1%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Actor-Observer Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%In-Group Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.4%Out-Group Homogeneity Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 0.6%Halo Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Horn Effect0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Dunning-Kruger Effect0.0%This article: 5.5%Swati Khandelwal: 1.4%The Hacker News: 1.4%Recency Bias5.5%This article: 1.2%Swati Khandelwal: 0.2%The Hacker News: 0.2%Primacy Effect1.2%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Blind-Spot Bias0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Ad Hominem0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.1%Straw Man0.0%This article: 9.5%Swati Khandelwal: 3.9%The Hacker News: 4.0%Appeal to Authority9.5%This article: 1.2%Swati Khandelwal: 1.4%The Hacker News: 1.6%False Dilemma1.2%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.5%Slippery Slope0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Circular Reasoning0.0%This article: 6.3%Swati Khandelwal: 3.8%The Hacker News: 4.3%Hasty Generalization6.3%This article: 0.0%Swati Khandelwal: 0.2%The Hacker News: 0.1%Red Herring0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.2%Bandwagon0.0%This article: 0.0%Swati Khandelwal: 0.9%The Hacker News: 1.1%Appeal to Emotion0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.5%Begging the Question0.0%This article: 3.3%Swati Khandelwal: 2.0%The Hacker News: 1.9%Post Hoc (False Cause)3.3%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Tu Quoque0.0%This article: 0.0%Swati Khandelwal: 0.7%The Hacker News: 0.6%Burden of Proof0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Appeal to Nature0.0%This article: 0.0%Swati Khandelwal: 0.3%The Hacker News: 0.3%Composition/Division0.0%This article: 0.0%Swati Khandelwal: 1.1%The Hacker News: 1.0%Anecdotal0.0%This article: 1.9%Swati Khandelwal: 0.0%The Hacker News: 0.1%No True Scotsman1.9%This article: 13.6%Swati Khandelwal: 2.6%The Hacker News: 2.3%Ambiguity (Equivocation)13.6%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Gambler’s Fallacy0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Middle Ground0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Personal Incredulity0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Special Pleading0.0%This article: 0.0%Swati Khandelwal: 0.1%The Hacker News: 0.1%Genetic Fallacy0.0%This article: 2.1%Swati Khandelwal: 1.1%The Hacker News: 1.4%Unattributed Quote2.1%This article: 2.0%Swati Khandelwal: 0.8%The Hacker News: 1.0%Quote-first Misdirection2.0%This article: 12.5%Swati Khandelwal: 2.8%The Hacker News: 2.4%Biased Writer Voice12.5%This article: 2.5%Swati Khandelwal: 4.8%The Hacker News: 4.4%Indoctrination2.5%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Left Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.0%The Hacker News: 0.0%Politically Right Leaning Bias0.0%This article: 0.0%Swati Khandelwal: 0.4%The Hacker News: 3.0%Attempt to Sell a Product or S…0.0%

1003 words analyzed.

Speakers

6speakers13%attributed speech871writer words
Voice mapSelect a segment to jump to its words
Writer's voice • 12 words • 100.0% coverageWriter's voice • 31 words • 100.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 4 words • 100.0% coverageWriter's voice • 16 words • 100.0% coverageKaspersky's GReAT team • 20 words • 100.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 5 words • 100.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 25 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 27 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 32 words • 100.0% coverageWriter's voice • 7 words • 0.0% coverageMoonlock Lab • 32 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 6 words • 100.0% coverageWriter's voice • 12 words • 0.0% coverageKaspersky • 10 words • 0.0% coverageWriter's voice • 18 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 23 words • 0.0% coverageWriter's voice • 13 words • 100.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 9 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 24 words • 0.0% coverageWriter's voice • 28 words • 0.0% coverageKaspersky • 4 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 10 words • 0.0% coverageWriter's voice • 16 words • 0.0% coverageWriter's voice • 12 words • 0.0% coverageWriter's voice • 14 words • 0.0% coverageWriter's voice • 26 words • 0.0% coverageWriter's voice • 4 words • 100.0% coverageKaspersky • 17 words • 100.0% coverageWriter's voice • 15 words • 0.0% coverageWriter's voice • 6 words • 100.0% coverageWriter's voice • 7 words • 0.0% coverageWriter's voice • 11 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageWriter's voice • 14 words • 100.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 13 words • 0.0% coverageKaspersky's post • 8 words • 0.0% coverageWriter's voice • 8 words • 0.0% coverageLedger • 11 words • 0.0% coverageTrezor Suite • 30 words • 0.0% coverageWriter's voice • 19 words • 0.0% coverageWriter's voice • 5 words • 0.0% coverageWriter's voice • 3 words • 0.0% coverageWriter's voice • 20 words • 0.0% coverageWriter's voice • 6 words • 0.0% coverageWriter's voice • 11 words • 100.0% coverage
Selected voice

Moonlock Lab

100%flagged-word coverage
32 attributed words24% of attributed speech68% writer coverage
0%7.5%15.0%Biased Writer Voice-14.4 ptsWriter: 14.4%Moonlock Lab: 0.0%0.0%Indoctrination-2.9 ptsWriter: 2.9%Moonlock Lab: 0.0%0.0%Unattributed Quote-0.5 ptsWriter: 0.5%Moonlock Lab: 0.0%0.0%

Attribution is sentence-level. Pattern percentages are calculated only from words assigned to that voice.

Loading…
Loading…
Loading…
Loading…

Analysis

Hover over highlighted words in the article to view the associated bias or fallacy analysis.