OkoBot Malware Framework Steals Crypto Wallets Across 25 Countries
The OkoBot malware framework is actively targeting cryptocurrency users through a sophisticated multi-stage intrusion chain. This framework is designed to steal wallet recovery phrases, credentials, browser data, and other sensitive information from compromised Windows systems. Researchers from Kaspersky’s Global Research and Analysis Team have identified hundreds of affected users across more than 25 countries, with the highest concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye.
The OkoBot framework comprises over 20 malicious payloads and implants. Its capabilities include remote command execution, credential theft, browser manipulation, cryptocurrency wallet targeting, keystroke capture, video recording, and the deployment of additional malware. Kaspersky reported that the campaign remained active as of July 2026 and continues to evolve, indicating ongoing maintenance by its operators.
While the technical evidence does not definitively attribute the operation to a known cybercrime group, researchers have identified techniques and code artifacts associated with Russian-speaking threat actors. These include Russian-language comments and infrastructure configured to restrict access from Russia and several Commonwealth of Independent States locations.
How the OkoBot Malware Framework Enters Systems
The OkoBot malware primarily infiltrates systems through ClickFix social-engineering attacks and malicious GitHub repositories that masquerade as legitimate software projects. ClickFix attacks typically present users with fabricated technical problems, verification requests, or installation errors. Victims are instructed to copy and execute commands that seem to resolve the issue but instead launch malicious scripts on their systems.
The GitHub distribution method relies on repositories designed to resemble trusted software downloads. During its investigation, Kaspersky identified a repository posing as a Microsoft SQL Server Management Studio package. The downloaded application was actually a modified version of the legitimate Audacity audio editor, containing a malicious implant. Because the repository was indexed by search engines and appeared prominently in relevant searches, users could easily mistake it for an authentic software source.
Both infection methods initiate TookPS, a malicious PowerShell downloader linked to earlier attack activity observed in 2025. TookPS installs components necessary to establish an encrypted SSH connection with attacker-controlled infrastructure. An automated SSH bot then connects to the compromised device, gathering information such as the username, operating system version, IP address, and installed security products. This bot can also collect cryptocurrency wallet files, browser profiles, cookies, and saved credentials. Attackers subsequently use the established connection to transfer additional modules to the infected machine.
This modular approach allows operators to deploy different tools based on the victim, available privileges, and information discovered during the initial compromise.
SeedHunter Targets Ledger and Trezor Applications
A significant component of the OkoBot framework is SeedHunter, a specialized implant designed to steal cryptocurrency wallet recovery phrases. SeedHunter monitors active processes and injects malicious code into legitimate applications used to manage hardware wallets, including Trezor Suite, Ledger Wallet, and Ledger Live.
When the malware detects a connected Ledger or Trezor device, it can display a fraudulent recovery interface within the trusted wallet application, prompting the user to enter the wallet’s seed phrase. A seed phrase is the recovery credential used to restore access to a cryptocurrency wallet. Anyone who obtains it can recreate the wallet and authorize transactions without possessing the physical device.
This attack does not require operators to break the cryptographic protection of the hardware wallet itself. Instead, it compromises the software environment surrounding the device and manipulates the user into surrendering the recovery information. SeedHunter sends captured phrases and device information to attacker-controlled infrastructure. Kaspersky’s analysis found that the malware could also store an encrypted copy of the stolen data temporarily on the compromised system before exfiltration.
This method underscores the importance of users never providing a seed phrase in response to unexpected prompts, even when the request appears within familiar wallet-management software. Legitimate support personnel, wallet providers, and hardware wallet manufacturers should not require users to disclose complete recovery phrases through unsolicited application prompts, email messages, or websites.
OkoSpyware Records Activity Across More Than 100 Applications
Another component, named OkoSpyware, provides attackers with extensive surveillance capabilities. This module maintains a list of over 100 applications that may contain sensitive information, including cryptocurrency wallets and password managers. Examples identified in the research include Exodus, Litecoin QT, KeePassXC, and 1Password.
OkoSpyware checks active processes to determine whether one of the targeted applications is running. When it detects a relevant program, the malware can record keystrokes entered into the application while simultaneously capturing video of its window. The recordings are created using an embedded FFmpeg component and stored temporarily before being transferred to attacker infrastructure.
The malware also monitors browser windows for titles associated with cryptocurrency services and wallet extensions, including MetaMask and Tonkeeper pages. This enables operators to capture passwords, wallet information, authentication details, and user activity that may not be recoverable through conventional file theft alone. A separate keylogging module within the framework can record clipboard contents, connected USB devices, and periodic screenshots, making clipboard monitoring particularly relevant to cryptocurrency theft.
Hidden Browser Extensions Expand the Attack Surface
OkoBot also includes a loader capable of silently installing malicious browser extensions within Chromium-based browsers. The loader injects code into browser processes and uses internal browser functions to register extensions without following the normal installation workflow. It can grant requested permissions and hide the extensions from the user’s visible extension list.
During the analyzed attacks, the framework installed Rilide, an information-stealing extension associated with credential, cookie, and financial data theft. Malicious extensions can observe browser sessions, modify displayed content, intercept authentication information, and interfere with cryptocurrency transactions. Because the extension is hidden, victims may not identify it during routine reviews of their installed browser add-ons. Its activity may continue until endpoint-security controls detect the injected code or investigators identify the underlying system compromise.
The framework’s architecture also includes a plugin dispatcher that allows operators to introduce new capabilities. Identified plugins supported command execution, PowerShell activity, system enumeration, payload downloading, and process injection. This modular design provides flexibility, allowing attackers to adapt their payload selection according to the value of the target or the access available on the compromised machine.
OkoBot Victim Activity Spans More Than 25 Countries
Kaspersky reported hundreds of detected victims across more than 25 countries, with Brazil, Vietnam, Canada, Mexico, and Türkiye accounting for the largest shares of identified affected users. The recorded distribution does not necessarily represent the complete scale of the operation, as security telemetry only reflects infections visible to the research organization, while undetected or unreported compromises may exist elsewhere.
The campaign’s focus on software developers and technically capable users may be linked to its distribution through GitHub repositories and development-related software packages. Developers often possess access to source-code repositories, cloud platforms, production systems, and privileged credentials. Compromising such users can provide attackers with opportunities extending beyond personal cryptocurrency theft. A developer’s workstation may also contain browser sessions, SSH credentials, API keys, password-manager databases, and access to corporate infrastructure.
This makes the infection chain relevant to both individual cryptocurrency holders and organizational security teams responsible for endpoint protection, identity governance, and software supply chain risk.
Defensive Priorities for Cryptocurrency Users and Developers
Users should download wallet applications, development tools, and administrative software only from official vendor websites or repositories independently verified through trusted channels. Search-engine placement should not be treated as proof of legitimacy for a GitHub repository or download page. Attackers can create convincing documentation, branding, and installation guides designed to imitate authentic projects.
Users should refrain from executing PowerShell commands or scripts supplied by websites, pop-up messages, technical guides, or unknown individuals unless the instructions have been independently reviewed and verified. Wallet recovery phrases should never be stored in screenshots, unencrypted notes, cloud photo libraries, or ordinary text files. Offline storage methods that minimize digital exposure remain safer than keeping recovery information on internet-connected devices.
Unexpected seed-phrase prompts should be treated as potential indicators of compromise. Users encountering such prompts should close the application, disconnect the device where appropriate, and verify the application’s integrity through the wallet provider’s official support channel. Operating systems, wallet software, browsers, and security applications should remain updated. Multi-factor authentication should be enabled wherever supported, although it cannot protect a wallet when an attacker obtains the complete seed phrase.
Organizations should monitor the execution of PowerShell, unauthorized SSH services, unexpected scheduled tasks, browser-process injection, and new local accounts with remote-access privileges. Endpoint-detection systems should also identify unusual access to browser profiles, wallet files, password-manager processes, and cryptocurrency applications.
The full technical investigation, including the infection chain and indicators of compromise, is available through Kaspersky Securelist. As reported by cyberwarriorsmiddleeast.com.
Explore the latest digital editions of FAME Delivered in the Magazine section: https://famedelivered.com/magazine/
Published on 2026-08-03 06:45:00 • By FAME Delivered News Desk
