SeedHunter Campaign Exploits Ledger, Trezor Users in Global Crypto Wallet Attack

July 16, 2026
SeedHunter Campaign Exploits Ledger, Trezor Users in Global Crypto Wallet Attack
  • The campaign has infected hundreds of victims across more than 25 countries, with Brazil, Vietnam, Canada, Mexico, and Türkiye reporting the largest shares, according to a mid-2026 teardown.

  • The operation comprises over 20 malicious payloads across four stages, affecting hundreds of users in numerous countries, with attribution remaining inconclusive though some Russian-language artifacts are noted.

  • TookPS PowerShell script installs SSH access and connects hosts to attacker servers, enabling automated collection of user and system data along with wallet and browser data theft.

  • SeedHunter targets cryptocurrency wallets by injecting fake recovery pages into Ledger and Trezor software, designed to exfiltrate seed phrases entered by users.

  • The campaign injects malicious pages into Ledger Live, Ledger Wallet, and Trezor Suite, delaying execution until a device connection or immediately, with stolen phrases sent to the attackers’ C2 server moonsand.store.

  • OkoBot is a sophisticated malware framework identified in early 2026, employing a multi-stage infection chain delivered via TookPS scripts over an SSH tunnel and orchestrating more than 20 modules from a central framework.

  • Security teams receive comprehensive IoCs and exhaustive details on domains, IPs, file paths, and plugin hashes to aid threat detection and response.

  • Kaspersky notes uncertainty in attribution, citing Russian/CIS IP usage and Russian-language indicators in phishing pages, while refraining from naming a specific actor.

  • The overall conclusion highlights a tightly integrated, evolving, and obfuscated framework capable of data theft, remote command execution, browser-extension manipulation, and wallet targeting, with ongoing activity at publication time.

  • C2 communications use an HTTP-based protocol with a custom binary header and AES-GCM encrypted payloads; plugins manage tasks via RegisterPlugin and PluginDispatch, and a defined set of plugins and corresponding implants exist.

  • Infections span more than 25 countries, with a concentration in Brazil, Vietnam, Canada, Mexico, and Türkiye, and while some Russian-language indicators exist, attribution remains uncertain.

  • Post-infection, attackers escalate persistence by disabling Defender alerts, opening firewall ports for RDP, creating new remote users, and modifying files to permit multiple RDP sessions, including an hourly scheduled task named “Apple Sync.”

Summary based on 3 sources


Get a daily email with more Tech stories

Sources



OkoBot Malware Uses ClickFix and Hidden Browser Extensions to Steal Crypto Data

Hackread - Cybersecurity News, Data Breaches, AI and More • Jul 16, 2026

OkoBot Malware Uses ClickFix and Hidden Browser Extensions to Steal Crypto Data

More Stories