OkoBot Malware Framework Steals Crypto Wallet Data from Users in 25 Countries
The OkoBot malware framework has emerged as a significant threat to cryptocurrency users, employing a multi-stage intrusion strategy aimed at extracting sensitive information such as wallet recovery phrases, credentials, and browser data from compromised Windows systems. Researchers from Kaspersky’s Global Research and Analysis Team have identified hundreds of affected users across more than 25 countries, with the highest concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye.
The OkoBot framework is equipped with over 20 malicious payloads and implants, enabling capabilities that include remote command execution, credential theft, browser manipulation, cryptocurrency wallet targeting, keystroke capture, video recording, and the deployment of additional malware. As of July 2026, Kaspersky reported that the campaign remains active and continues to evolve, indicating ongoing maintenance by its operators.
Intrusion Methods of OkoBot
The OkoBot malware primarily infiltrates systems through ClickFix social-engineering attacks and malicious GitHub repositories that mimic legitimate software projects. ClickFix attacks typically present users with fabricated technical issues, prompting them to execute commands that appear to resolve the problem but instead deploy malicious scripts.
In addition, the GitHub distribution method relies on repositories designed to resemble trusted software downloads. Kaspersky identified a repository masquerading as a Microsoft SQL Server Management Studio package, which actually contained a modified version of the legitimate Audacity audio editor embedded with malicious code. This repository’s visibility on search engines could mislead users into believing it was a legitimate source.
Both infection methods initiate TookPS, a malicious PowerShell downloader linked to earlier attack activities observed in 2025. TookPS installs components necessary for establishing an encrypted SSH connection with attacker-controlled infrastructure. An automated SSH bot then connects to the compromised device, gathering information such as the username, operating system version, IP address, and installed security products. The bot can also collect cryptocurrency wallet files, browser profiles, cookies, and saved credentials, allowing attackers to transfer additional modules to the infected machine.
SeedHunter: Targeting Hardware Wallets
A critical component of the OkoBot framework is SeedHunter, a specialized implant designed to steal cryptocurrency wallet recovery phrases. SeedHunter monitors active processes and injects malicious code into legitimate applications used for managing hardware wallets, including Trezor Suite and Ledger Live.
When the malware detects a connected Ledger or Trezor device, it can display a fraudulent recovery interface within the trusted wallet application, prompting the user to enter the wallet’s seed phrase. A seed phrase is the recovery credential that allows access to a cryptocurrency wallet, and anyone who obtains it can recreate the wallet and authorize transactions without needing the physical device.
This attack does not require breaking the cryptographic protection of the hardware wallet itself. Instead, it compromises the software environment surrounding the device and manipulates the user into surrendering the recovery information. SeedHunter transmits captured phrases and device information to attacker-controlled infrastructure, and Kaspersky’s analysis revealed that the malware could also temporarily store an encrypted copy of the stolen data on the compromised system before exfiltration.
OkoSpyware: Comprehensive Surveillance
Another component, referred to as OkoSpyware, provides attackers with extensive surveillance capabilities. This module maintains a list of over 100 applications that may contain sensitive information, including cryptocurrency wallets and password managers. Examples identified in the research include Exodus, Litecoin QT, KeePassXC, and 1Password.
When OkoSpyware detects a relevant application, it can record keystrokes entered into the application while simultaneously capturing video of its window. The recordings are created using an embedded FFmpeg component and stored temporarily before being sent to attacker infrastructure. The malware also monitors browser windows for titles associated with cryptocurrency services and wallet extensions, enabling operators to capture passwords, wallet information, authentication details, and user activity that may not be recoverable through conventional file theft.
Hidden Browser Extensions and Attack Surface Expansion
OkoBot also features a loader capable of silently installing malicious browser extensions within Chromium-based browsers. This loader injects code into browser processes and uses internal functions to register extensions without following the standard installation workflow, granting requested permissions and hiding the extensions from the user’s visible list.
During analyzed attacks, the framework installed Rilide, an information-stealing extension associated with credential, cookie, and financial data theft. These malicious extensions can observe browser sessions, modify displayed content, intercept authentication information, and interfere with cryptocurrency transactions. Because the extension is hidden, victims may not identify it through routine reviews, allowing its activity to continue until endpoint security controls detect the injected code or investigators uncover the underlying compromise.
Global Impact and Recommendations
Kaspersky reported hundreds of detected victims across more than 25 countries, with Brazil, Vietnam, Canada, Mexico, and Türkiye accounting for the largest shares of identified users. This distribution does not necessarily reflect the complete scale of the operation, as security telemetry only captures infections visible to the research organization.
The campaign’s focus on software developers and technically capable users may be linked to its distribution through GitHub repositories and development-related software packages. Developers often have access to source-code repositories, cloud platforms, and privileged credentials, making them valuable targets for attackers.
To mitigate risks, users are advised to download wallet applications and administrative software only from official vendor websites or independently verified repositories. Search-engine placement should not be considered proof of legitimacy, as attackers can create convincing documentation and branding. Users should avoid executing PowerShell commands or scripts from unverified sources and should store wallet recovery phrases securely, minimizing digital exposure.
Unexpected prompts for seed phrases should be treated as potential compromise indicators. Users encountering such prompts should close the application and verify its integrity through official support channels. Regular updates to operating systems, wallet software, and security applications are essential, as is the implementation of multi-factor authentication wherever supported.
For ongoing coverage and breaking updates, visit our Latest News section.
Published on 2026-08-03 06:45:00 • By the Editorial Desk

