Cryptocurrency wallet owners are being targeted by OkoBot, a modular malware framework that steals seed phrases, login credentials, and clipboard data to drain crypto funds. Kaspersky's Securelist team disclosed the campaign, describing roughly 20 interchangeable components that work together to compromise Windows machines and empty wallets.
A seed phrase, also called a recovery phrase, is the string of words that unlocks a crypto wallet and controls its funds. OkoBot's core trick is to convince you to type that phrase into your own computer, where attackers can grab it. Once they have it and move your assets, recovery is essentially impossible.
Table of Contents
- What OkoBot is and how long it has been active
- How the fake recovery-phrase attack works
- The other modules watching your machine
- How OkoBot reaches victims
- How to protect yourself
- Frequently Asked Questions
What OkoBot is and how long it has been active
OkoBot is a "framework," meaning it is not a single virus but a toolkit of swappable modules that attackers mix and match per target. Kaspersky counted around 20 components, each handling a job such as key capture, wallet tracking, or code injection. According to Kaspersky's Securelist report, researchers first identified the campaign in January 2026.
The malware itself, however, has been quietly targeting Windows users since about April 2025 and remained active as of July 2026. That long runway means many victims were hit well before the public warning. The modular design matters for defenders. Attackers can update one piece — say, the phishing page or the delivery method — without rebuilding the whole toolkit, which makes signatures and takedowns harder to keep current.
How the fake recovery-phrase attack works
The most dangerous module is "SeedHunter," which waits patiently rather than attacking right away. It injects code into legitimate desktop wallet apps, including Trezor Suite, Ledger Live, and Ledger Wallet, as detailed in reporting by HackMag on the Kaspersky findings. The module sits idle until you plug in a hardware wallet.
At that moment it displays a fake recovery-phrase page that looks like it belongs to the genuine app. Because the prompt appears inside software you trust, at a moment you expect to interact with your wallet, it is convincing. Any phrase entered into that fake page is sent straight to the attackers. As SC Media reported, that hands over full control of the assets, and once funds are moved there is essentially no chance of getting them back.
The other modules watching your machine
SeedHunter is not the only threat inside OkoBot. According to BleepingComputer's breakdown, the framework also deploys an "MC Keylogger" that captures keystrokes and clipboard contents, plus "OkoSpyware" built to track wallet passwords.
These components broaden the damage beyond seed phrases. A keylogger can grab exchange logins and two-factor codes as you type them, while clipboard capture is aimed at the common habit of copying and pasting wallet addresses and passwords. Together the modules mean a single infection can expose several layers of your crypto security at once — the wallet itself, the accounts around it, and anything you copy while the malware runs.
How OkoBot reaches victims
Distribution leans on social engineering rather than exotic exploits. Kaspersky points to "ClickFix" tactics, which trick users into copying and running malicious commands themselves, often disguised as a fix for a fake error or verification step. The operators also plant trojanized tools on GitHub, dressing malware up as legitimate software.
The Securelist report cites fake builds of utilities such as SQL Server Management Studio, which lure developers and technical users who trust code repositories. The reach is wide. Coinedition, summarizing Kaspersky's telemetry, reports infection attempts in more than 25 countries with hundreds of victims, hardest hit in Brazil, Vietnam, Canada, Mexico, and Türkiye.
How to protect yourself
The single most useful rule is simple: a legitimate hardware wallet never asks you to type your recovery phrase into a computer. As HackMag notes from the Kaspersky research, any on-screen prompt to enter a seed phrase is a red flag that your machine may already be compromised.
Watch for these warning signs and habits: If you see a seed-phrase prompt, stop and disconnect the hardware wallet immediately. Do not enter the phrase. Treat the computer as infected: scan it, and if you may have exposed a phrase, move your funds to a new wallet with a freshly generated phrase from an uncompromised device.
- A wallet app suddenly asking you to type or "verify" your recovery phrase on screen
- Instructions to paste and run a command to fix an error or pass a check (ClickFix)
- Downloading developer tools or wallet software from unofficial GitHub repositories
- Wallet addresses that look different after pasting than what you copied
Frequently Asked Questions
Does OkoBot break the hardware wallet's encryption?
No. It does not crack the device. It waits for you to connect a wallet, then shows a fake page to trick you into typing your recovery phrase yourself.
Which wallets are named in the research?
Kaspersky's SeedHunter module injects into Trezor Suite, Ledger Live, and Ledger Wallet, according to HackMag's coverage of the findings.
I may have entered my seed phrase into a suspicious prompt. What now?
Assume the funds are at risk. Move them to a new wallet created from a fresh recovery phrase on a clean device, since attackers gain full control once they have the original phrase.
