Kaspersky Uncovers ”OkoBot” Malware Campaign Targeting Global Cryptocurrency Users
Kaspersky’s Global Research and Analysis Team (GReAT) has uncovered details regarding a new malware campaign dubbed "OkoBot," specifically targeting cryptocurrency users. This sophisticated new framework deploys "TookPS" malware to extract recovery seed phrases, utilizes a novel "OkoSpyware" module to monitor Chromium-based browsers, and distributes various types of malware, including the "Rilide" data stealer.
The campaign has already compromised hundreds of victims across more than 25 countries, with the highest concentration of affected users located in Brazil, Vietnam, Canada, Mexico, and Turkey. Kaspersky experts emphasize that this threat remains highly active, posing an ongoing and significant risk to the cryptocurrency community.
Sophisticated Malware Capabilities
In January 2026, GReAT experts detected multiple attacks employing a previously unknown malware capable of recording the visual contents of cryptocurrency wallet windows. Dubbed "OkoBot," this advanced malicious framework comprises over 20 malicious payloads and implants designed to execute a wide array of functions.
These functions include harvesting local files, executing remote commands, downloading arbitrary browser extensions, stealing crypto wallet contents, collecting seed phrases and credentials, recording videos, and performing other malicious activities. One of the novel implants used in this campaign is a loader that modifies browser memory to load and actively conceal malicious extensions. Additionally, the OkoBot framework incorporates a new "OkoSpyware" module tasked with logging keystrokes and streaming the visual content of the targeted application's window.
Attribution and Origins
Currently, there is insufficient evidence to attribute this campaign to a known threat actor with a high degree of confidence. However, the techniques and info-stealing malware employed are commonly associated with certain Russian-speaking cybercriminal groups. Furthermore, the technical analysis uncovered Russian-language artifacts within the code.
Infection Vectors
Initial infection typically occurs via two primary pathways. The first is through "ClickFix" attacks, where threat actors utilize social engineering to deceive users into executing the malware. The second involves malware distributed on GitHub disguised as legitimate software. During their investigation, researchers identified a notable case involving a fake installation file for SQL Server Management Studio (SSMS), a widely used Microsoft database management tool.
Targeting Hardware Wallets with 'SeedHunter'
The malicious framework also features "SeedHunter," a dangerous component that monitors active system processes and injects malicious hooks into official crypto asset management applications, namely Trezor Suite, Ledger Wallet, and Ledger Live.
When the tool detects a hardware wallet connected to either the Trezor or Ledger applications, it triggers interceptor functions. These functions deploy a pre-programmed phishing overlay designed to steal the user's recovery seed phrase, utilizing a deceptive interface tailored to match the specific type of wallet in use.


