The OkoBot malware framework is targeting cryptocurrency users through a multi-stage intrusion chain designed to steal wallet recovery phrases, credentials, browser data and other sensitive information from compromised Windows systems.
Researchers from Kaspersky’s Global Research and Analysis Team identified hundreds of affected users across more than 25 countries, with the highest concentrations recorded in Brazil, Vietnam, Canada, Mexico and Türkiye.
The framework contains more than 20 malicious payloads and implants. Its capabilities include remote command execution, credential theft, browser manipulation, cryptocurrency-wallet targeting, keystroke capture, video recording and the deployment of additional malware.
Kaspersky said the campaign remained active as of July 2026 and continued to evolve, indicating that the framework was being maintained while its operators pursued further distribution.
The available technical evidence does not attribute the operation to a known cybercrime group with high confidence. Researchers nevertheless identified techniques and code artefacts associated with Russian-speaking threat actors, including Russian-language comments and infrastructure configured to restrict access from Russia and several Commonwealth of Independent States locations.
How the OkoBot Malware Framework Enters Systems
The OkoBot malware framework primarily reaches victims through ClickFix social-engineering attacks and malicious GitHub repositories that impersonate legitimate software projects.
ClickFix attacks typically present users with a fabricated technical problem, verification request or installation error. Victims are instructed to copy and execute commands that appear to resolve the issue but instead launch malicious scripts on their systems.
The GitHub distribution method relies on repositories designed to resemble trusted software downloads. During its investigation, Kaspersky identified a repository posing as a Microsoft SQL Server Management Studio package.
The downloaded application was actually a modified version of the legitimate Audacity audio editor containing a malicious implant. Because the repository had been indexed by search engines and appeared prominently for relevant searches, users could mistake it for an authentic software source.
Both infection methods initiate TookPS, a malicious PowerShell downloader connected to earlier attack activity observed during 2025. TookPS installs components required to establish an encrypted SSH connection with attacker-controlled infrastructure.
An automated SSH bot then connects to the compromised device and gathers information such as the username, operating-system version, IP address and installed security products.
The bot can also collect cryptocurrency-wallet files, browser profiles, cookies and saved credentials. Attackers subsequently use the established connection to transfer additional modules to the infected machine.
This modular approach allows the operators to deploy different tools depending on the victim, available privileges and information discovered during the initial compromise.
SeedHunter Targets Ledger and Trezor Applications
One of the framework’s most consequential components is SeedHunter, a specialised implant designed to steal cryptocurrency-wallet recovery phrases.
SeedHunter monitors active processes and injects malicious code into legitimate applications used to manage hardware wallets, including Trezor Suite, Ledger Wallet and Ledger Live.
When the malware detects a connected Ledger or Trezor device, it can display a fraudulent recovery interface within the trusted wallet application. The page asks the user to enter the wallet’s seed phrase.
A seed phrase is the recovery credential used to restore access to a cryptocurrency wallet. Anyone who obtains it may be able to recreate the wallet and authorise transactions without possessing the physical device.
The attack therefore does not require the operators to break the cryptographic protection of the hardware wallet itself. Instead, it compromises the software environment surrounding the device and manipulates the user into surrendering the recovery information.
SeedHunter sends captured phrases and device information to attacker-controlled infrastructure. Kaspersky’s analysis found that the malware could also store an encrypted copy of the stolen data temporarily on the compromised system before exfiltration.
This method demonstrates why users should never provide a seed phrase in response to an unexpected prompt, even when the request appears inside familiar wallet-management software.
Legitimate support personnel, wallet providers and hardware-wallet manufacturers should not require users to disclose complete recovery phrases through unsolicited application prompts, email messages or websites.
OkoSpyware Records Activity Across More Than 100 Applications
Another component, named OkoSpyware by Kaspersky, provides the attackers with detailed surveillance capabilities.
The module maintains a list of more than 100 applications that may contain sensitive information. The targets include cryptocurrency wallets, password managers and other commonly used programs.
Examples identified in the research include Exodus, Litecoin QT, KeePassXC and 1Password. OkoSpyware checks active processes to determine whether one of the targeted applications is running.
When it detects a relevant program, the malware can record keystrokes entered into the application while simultaneously capturing video of its window. The recordings are created using an embedded FFmpeg component and stored temporarily before being transferred to attacker infrastructure.
The malware also monitors browser windows for titles associated with cryptocurrency services and wallet extensions, including MetaMask and Tonkeeper pages.
This enables the operators to capture passwords, wallet information, authentication details and user activity that may not be recoverable through conventional file theft alone.
A separate keylogging module within the framework can record clipboard contents, connected USB devices and periodic screenshots. Clipboard monitoring is particularly relevant to cryptocurrency theft because users frequently copy wallet addresses, transaction information and access credentials between applications.
Hidden Browser Extensions Expand the Attack Surface
OkoBot also includes a loader capable of silently installing malicious browser extensions inside Chromium-based browsers.
The loader injects code into browser processes and uses internal browser functions to register extensions without following the normal installation workflow. It can grant requested permissions and hide the extensions from the user’s visible extension list.
During the analysed attacks, the framework installed Rilide, an information-stealing extension associated with credential, cookie and financial-data theft.
Malicious extensions can observe browser sessions, modify displayed content, intercept authentication information and interfere with cryptocurrency transactions.
Because the extension is hidden, victims may not identify it through a routine review of their installed browser add-ons. Its activity may therefore continue until endpoint-security controls detect the injected code or investigators identify the underlying system compromise.
The framework’s architecture also includes a plugin dispatcher that allows operators to introduce new capabilities. Identified plugins supported command execution, PowerShell activity, system enumeration, payload downloading and process injection.
This modular design provides flexibility. Attackers do not need to deploy every component to every victim and can adapt their payload selection according to the value of the target or the access available on the compromised machine.
OkoBot Victim Activity Spans More Than 25 Countries
Kaspersky reported hundreds of detected victims across more than 25 countries. Brazil, Vietnam, Canada, Mexico and Türkiye accounted for the largest shares of identified affected users.
The recorded distribution does not necessarily represent the complete scale of the operation. Security telemetry only reflects infections visible to the research organisation, while undetected or unreported compromises may exist elsewhere.
The campaign’s focus on software developers and technically capable users may be connected to its distribution through GitHub repositories and development-related software packages.
Developers often possess access to source-code repositories, cloud platforms, production systems and privileged credentials. Compromising such users can provide attackers with opportunities extending beyond personal cryptocurrency theft.
A developer’s workstation may also contain browser sessions, SSH credentials, API keys, password-manager databases and access to corporate infrastructure.
This makes the infection chain relevant to both individual cryptocurrency holders and organisational security teams responsible for endpoint protection, identity governance and software-supply-chain risk.
Defensive Priorities for Cryptocurrency Users and Developers
Users should download wallet applications, development tools and administrative software only from official vendor websites or repositories independently verified through trusted channels.
Search-engine placement should not be treated as proof that a GitHub repository or download page is legitimate. Attackers can create convincing documentation, branding and installation guides designed to imitate authentic projects.
Users should not execute PowerShell commands or scripts supplied by websites, pop-up messages, technical guides or unknown individuals unless the instructions have been independently reviewed and verified.
Wallet recovery phrases should never be stored in screenshots, unencrypted notes, cloud photo libraries or ordinary text files. Offline storage methods that minimise digital exposure remain safer than keeping recovery information on internet-connected devices.
Unexpected seed-phrase prompts should be treated as potential compromise indicators. Users encountering such prompts should close the application, disconnect the device where appropriate and verify the application’s integrity through the wallet provider’s official support channel.
Operating systems, wallet software, browsers and security applications should remain updated. Multi-factor authentication should be enabled wherever supported, although it cannot protect a wallet when an attacker obtains the complete seed phrase.
Organisations should monitor the execution of PowerShell, unauthorised SSH services, unexpected scheduled tasks, browser-process injection and new local accounts with remote-access privileges.
Endpoint-detection systems should also identify unusual access to browser profiles, wallet files, password-manager processes and cryptocurrency applications.
The full technical investigation, including the infection chain and indicators of compromise, is available through Kaspersky Securelist. The original report supplied for this article appeared in Leadership.
Keep reading for the latest cybersecurity developments, threat intelligence and breaking updates from across the Middle East.


