Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Hardware cryptocurrency wallet users
Incident: Deployment of the OkoBot malware framework to steal seed phrases through application injection.
Impact: Full compromise and theft of cryptocurrency funds via stolen recovery phrases.
Attacker: Unidentified threat actors
Analysis: OkoBot utilizes a specialized module called SeedHunter to inject malicious phishing overlays directly into the Electron-based interfaces of Ledger and Trezor desktop applications. The malware can monitor USB connections to trigger the phishing page only when a physical device is detected, maximizing the deception. Initial access is achieved via ClickFix lures and trojanized software hosted on GitHub.
Recommendations: Never enter your recovery phrase into any desktop software or website; Avoid downloading utility software from unofficial GitHub repositories; Verify that any recovery request is initiated by the hardware device screen, not the computer
Source: The Hacker News / Kaspersky
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source