You plug your crypto wallet into the computer, open the app you always use, and it shows you a recovery screen asking for the 24 words. The layout is right, the timing is right, it appears the moment you connect the device. That is not your wallet talking to you, it is a module called SeedHunter, described on 15 July by Kaspersky's GReAT research team in a report on OkoBot, a set of more than twenty malicious programs working together on a Windows machine.
What matters here is not the theft, it is where it happens. The hardware wallet was not defeated, nobody broke the cryptography or opened the device, and the private key stayed exactly where it has always been. The attacker simply changed the screen on which you read the request, and that is where these campaigns win, in the window you trust without thinking.
The request shows up inside the genuine app
SeedHunter watches running processes and injects itself into Trezor Suite, Ledger Wallet and Ledger Live. Because those apps are built on Electron, the technology that assembles desktop software out of browser parts, the implant can hook the internal functions that draw the windows and add a page the app never had, with a different layout for each wallet it identifies. When it is set to wait, it runs periodic USB scans filtered by vendor and product identifiers, and only fires the prompt once it sees the device connected, which is the exact moment you are expecting to interact with it. The device's own screen shows nothing, because no legitimate request ever reached it.
Ledger support has been saying the same thing for years, it never asks for your 24 words and there is never a good reason to type your recovery phrase into a computer. It reads like boilerplate until the day the window doing the asking is the official one.
Taking your savings is only half the job
The wallet module is one of more than twenty. The same toolkit takes a screenshot every five minutes, copies whatever passes through the clipboard, and watches a list of over 100 programs, among them software wallets such as Exodus and password managers such as KeePassXC and 1Password, recording video of the window and logging keystrokes when it recognises one of them. It also installs hidden browser extensions and creates an account in the remote desktop group, keeping an SSH tunnel, an encrypted remote administration channel, that forwards that port every hour. Once it has your crypto, it still owns the house.
Entry comes through two unremarkable routes. One is ClickFix, the scam that shows you a fake error and talks you into pasting a command into the Windows console to "fix" it. The other is tampered software on GitHub, and the report's example is a cruel one, a repository posing as Microsoft's SQL Server Management Studio that ranked at the top of the results for the query "SSMS" and delivered the genuine Audacity with an implant buried in one of its libraries.
Kaspersky's telemetry counts hundreds of victims across more than 25 countries, concentrated in Brazil, Vietnam, Canada, Mexico and Türkiye. Dmitry Galov, who heads the Russia and CIS unit of the research team, says the campaign has been running for more than a year and was still under way in July 2026.
Portugal is not on that list, which means very little. On 23 June the Leiria district command of the Portuguese public security police warned about two victims in Caldas da Rainha who lost roughly 140,000 euros between them to crypto investment fraud, and one step of the scheme was a request for remote access to their computers. Same move, asked for by hand instead of installed by malware.
How to protect yourself
- The recovery phrase is written once, on the device itself. If the request appears on your computer screen it is fraud, with no exceptions and regardless of how the window looks.
- Always confirm the operation on the device's small screen, the one surface the attacker does not control.
- Never paste a command a web page told you to copy, however convincing the error it showed you.
- Download software only from the vendor's official site, never from the first search result.
- If you suspect the machine, treat it as compromised and move the funds from different hardware, with a new phrase.
- Look for OkoBot's traces, a scheduled task named "Apple Sync", the file
hwid.datunder%PROGRAMDATA%, unknown accounts in the Remote Desktop Users group, and SSH connections leaving an ordinary workstation.
A recovery phrase is like evidence in a case, it is only worth something while nobody has touched it, and the chain of custody breaks at the weakest point it passed through. The device you bought still does its job and shows you the truth on a tiny screen nobody can redraw. Get used to believing that one, rather than the one where it is more comfortable to read.
Sources: Securelist, Kaspersky GReAT, The Hacker News, Diário de Notícias.
#StaySafe
🙏🖖