SeedHunter is a cryptocurrency-theft component of the OkoBot malware framework that targets users of hardware-wallet companion applications on Windows. It is designed to steal wallet recovery phrases by injecting into Trezor Suite, Ledger Wallet, and Ledger Live, hooking internal Electron functions, and presenting wallet-brand-specific fake recovery screens inside the legitimate application context. In observed operations, SeedHunter monitored for launches of supported wallet applications and could also watch for connected Ledger or Trezor devices before triggering the phishing prompt, increasing the plausibility of the lure and the likelihood of successful theft.
SeedHunter operates as a post-compromise implant rather than an initial access tool. It has been deployed in a broader OkoBot campaign that used ClickFix social-engineering lures and trojanized software distributed through GitHub to infect victims, then established remote access and delivered additional modules. Within that framework, SeedHunter was delivered by a process-injection plugin and used to capture seed phrases that grant full control over victims' cryptocurrency assets. Reporting on the wider campaign linked it to hundreds of victims across more than 25 countries, with notable impact in Brazil, Vietnam, Canada, Mexico, and Türkiye. The broader activity also included credential theft, browser abuse, keylogging, and surveillance modules.
Available reporting did not conclusively attribute the campaign to a known threat group, but several indicators were assessed as consistent with a suspected Russian-speaking operator, including Russian-language comments in SeedHunter phishing-page code and overlap with tooling associated with Russian-speaking cybercrime ecosystems. SeedHunter does not compromise the hardware wallet device itself; it compromises the endpoint and abuses trust in the companion wallet software interface to obtain recovery phrases.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The fake page mimics the legitimate wallet interface, prompting users to enter their recovery phrase, which is then captured by the malware.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A wallet-focused theft module that injects into wallet applications, monitors for connected hardware wallets, and displays phishing pages to capture recovery phrases.
Компонент OkoBot, отслеживающий запуск приложений аппаратных кошельков и показывающий поддельные страницы восстановления для кражи seed-фраз пользователей.
A campaign component targeting hardware-wallet users by injecting malicious code into wallet software, displaying fake recovery pages, and exfiltrating entered seed phrases to the attackers' command server.
A module that injects into cryptocurrency wallet applications and presents fake recovery prompts to steal wallet seed phrases.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.