Kaspersky Flags OkoBot Malware Targeting Crypto
Kaspersky has identified OkoBot, an active malware framework built to steal cryptocurrency wallet data, recovery phrases and credentials from Windows computers.
The campaign has reached hundreds of users in more than 25 countries, with the highest shares of detected victims in Brazil, Vietnam, Canada, Mexico and Türkiye. Kaspersky did not disclose how much cryptocurrency has been stolen.
Kaspersky Flags OkoBot Malware Targeting Crypto
OkoBot infects devices through ClickFix scams that persuade users to run malicious commands, or through trojanized software on GitHub. Researchers found one repository advertising Microsoft SQL Server Management Studio that instead delivered a modified version of Audacity containing malicious code.
Both routes execute TookPS, a PowerShell downloader that creates a tunnel to attacker-controlled infrastructure. An automated bot then collects browser profiles, cookies, credentials and wallet files.
The malware also enables Remote Desktop access, establishes persistence and downloads additional modules. Kaspersky said OkoBot contains more than 20 payloads and implants and has evolved since TookPS-linked activity appeared in 2025.
SeedHunter Targets Trezor and Ledger Apps
One module, SeedHunter, monitors Trezor Suite, Ledger Wallet and Ledger Live. It injects code into the legitimate desktop applications and can wait until a supported hardware wallet is connected before showing a fake recovery page.
Any seed phrase entered into that page is sent to the attackers. The method does not break the hardware wallet or its cryptography. It compromises the computer and uses the trusted wallet interface to persuade the user to disclose the recovery phrase.
OkoSpyware Targets 100-Plus Applications
OkoSpyware records keystrokes and video from more than 100 targeted applications. Targets include cryptocurrency wallets, password managers and browser windows showing MetaMask or Tonkeeper pages.
Other modules take screenshots, monitor clipboard contents and silently install malicious Chromium extensions, including the Rilide information stealer. Collected files are uploaded to command-and-control servers and deleted from the infected machine.
Kaspersky Leaves OkoBot Campaign Unattributed
Kaspersky cannot confidently attribute the campaign to a known criminal group. Russian-language code comments, infrastructure blocking connections from Russia and other Commonwealth of Independent States countries, and malware circulated on Russian-speaking forums provide indicators but not proof.
The campaign remained active when Kaspersky published its findings on July 15. Users should avoid commands from unverified websites, download software from trusted sources and never enter a recovery phrase into an unexpected desktop prompt.