A sophisticated new threat called OkoBot malware is targeting cryptocurrency users worldwide. The framework can deploy more than 20 malicious payloads to steal wallet recovery phrases, login details, browser cookies, and other sensitive information.
The campaign relies on several infection methods. These include fake software repositories and ClickFix attacks that trick users into running malicious commands. Once inside a Windows system, OkoBot creates a complex infection chain designed to maintain access and quietly collect data.
Security researchers first detected the current activity in January 2026. However, the campaign evolved from an earlier operation involving a malicious PowerShell downloader called TookPS.
Fake Software Downloads Spread OkoBot Malware
Attackers distribute OkoBot malware through ClickFix campaigns and malicious GitHub repositories. The repositories appear to offer legitimate applications, which helps them gain the victim’s trust.
In one case, a repository claimed to provide SQL Server Management Studio. Yet the download actually contained a modified version of the Audacity audio editor. Attackers had embedded a malicious component inside one of its libraries.
The repository also appeared prominently in search results for people looking for the database management software. Therefore, victims could easily mistake it for a legitimate download page.
Both infection methods ultimately launch TookPS. This malicious PowerShell script installs SSH components and connects the device to an attacker-controlled server.
SSH Bot Collects Data From Infected Computers
After the initial infection, an automated SSH bot connects to the compromised computer. It then gathers information about the device and its security setup.
The collected details include:
- The Windows username
- The operating system version
- The device’s IP address
- Installed antivirus software
- Browser profiles and cookies
- Saved account credentials
- Cryptocurrency wallet files
The bot also disables Windows Defender notifications. As a result, the victim may not receive warnings about suspicious changes.
In addition, the attackers can configure Remote Desktop access and establish a reverse SSH tunnel. This gives them another route into the infected system. The bot then downloads more malicious components through SFTP.
SeedHunter Targets Hardware Wallet Users
SeedHunter is one of the most dangerous OkoBot malware modules. It targets the Trezor Suite, Ledger Wallet, and Ledger Live applications.
The module injects malicious code into these programs. It can then display a fake wallet recovery page when it detects a connected hardware wallet. The page asks the victim to enter their recovery phrase.
Once entered, the phrase goes directly to the attackers. A recovery phrase provides complete control over the associated cryptocurrency wallet. Criminals can use it to transfer all available funds to another address.
Crypto transactions are generally irreversible. Therefore, victims have little chance of recovering stolen assets after the attackers move them.
Hidden Browser Extensions Steal Credentials
Another OkoBot malware component targets Chromium-based browsers. It silently installs malicious extensions and then hides them from the browser’s extension list.
One extension used in the campaign is Rilide. This information stealer can collect login credentials, session cookies, financial details, and cryptocurrency-related data.
Because the extension remains hidden, users may not notice anything unusual. Meanwhile, other browser extensions continue to work normally.
The framework can also inject malicious components into legitimate processes. This approach helps it operate quietly while making detection more difficult.
Keylogger Records Screenshots and Clipboard Data
The MC Keylogger module monitors far more than keyboard input. It also records clipboard activity, including copied text, images, and file paths.
Furthermore, the module tracks connected USB devices. It can record device identifiers, manufacturer details, and other hardware information.
OkoBot can also capture screenshots every five minutes. Consequently, the attackers may obtain sensitive information even when the victim never types or copies it.
Another component, called OkoSpyware, monitors around 100 applications. Its targets include cryptocurrency wallets and password managers. It can record video from active application windows while also capturing keystrokes.
Campaign Has Reached Victims Worldwide
Most identified victims are in Brazil. However, infections have also appeared in Vietnam, Canada, Mexico, and Turkey. Researchers describe the campaign as global.
The earlier TookPS operation began in March 2025. Attackers later redesigned the infection chain and added a broader selection of tools. Researchers now track this evolved framework as OkoBot.
The campaign has not been linked to a specific cybercrime group. Still, several clues suggest a possible connection to Russian-speaking attackers.
For example, the malware delivery servers do not provide payloads to IP addresses in Russia or the Commonwealth of Independent States. Researchers also found Russian-language comments inside the SeedHunter source code. In addition, one of the information stealers linked to the campaign has appeared on invitation-only Russian cybercrime forums.
Users Should Treat Recovery Requests as Suspicious
Cryptocurrency wallet applications should not unexpectedly ask users to enter their full recovery phrase. Therefore, any sudden recovery prompt should be treated as a potential attack.
Users should also avoid downloading software from unfamiliar repositories, even when those pages appear high in search results. Instead, applications should come directly from official developer websites or verified repositories.
Finally, users should never paste unfamiliar commands into PowerShell or another terminal. ClickFix attacks rely on convincing victims to launch the infection themselves.
The OkoBot malware campaign remains active. Its modular design, hidden browser extensions, surveillance tools, and focus on wallet recovery phrases make it a serious threat to cryptocurrency users.


0 responses to “OkoBot Malware Deploys 20 Payloads to Steal Crypto”