Introducing OkoBot, a new malicious framework responsible for delivering over 20 payloads aimed at stealing sensitive data, including cryptocurrency wallet seed phrases and user credentials.
OkoBot employs ClickFix attacks and utilizes malicious GitHub repositories disguised as legitimate software tools to reach its targets.
One notable incident involved a repository falsely claiming to offer SQL Server Management Studio (SSMS), instead distributing a trojanized version of the Audacity audio editing tool.
Cybersecurity experts from Kaspersky Lab have reported that the OkoBot campaign has been active for over a year, evolving from its initial focus on distributing the malicious PowerShell script TookPS.
The infection chain has undergone a complete transformation, featuring multiple attack stages. The initial stage uses TookPS to install and configure an SSH bot responsible for deploying additional malicious components.

Source: Kaspersky
This SSH bot gathers critical system information (username, antivirus details, IP address, OS version) and disables Windows Defender notifications. It is also capable of stealing cryptocurrency wallet files, browser cookies, and account credentials.
Key modules utilized in OkoBot’s attacks include:
- ext daemon/extl.exe: Injects into Chrome to install hidden malicious extensions like Rilide, which target user credentials, cookies, and cryptocurrency data.
- seed hunter: Targets Trezor Suite and Ledger Wallet, displaying a fake seed recovery screen to steal wallet recovery phrases.
- MC keylogger: Records keystrokes, clipboard contents, and monitors USB connections while capturing screenshots every five minutes.
- Orco Spyware: Monitors 100 applications including cryptocurrency wallets and password managers, capturing window videos and keystrokes using FFmpeg.
Note that obtaining the wallet recovery phrase grants complete access to a user’s cryptocurrency funds, allowing attackers to transfer assets without any recovery options.

Source: Kaspersky
Kaspersky Telemetry indicates that the majority of OkoBot victims reside in Brazil, followed by Vietnam, Canada, Mexico, and Turkey. However, the campaign’s reach is global.
OkoBot’s activity was first detected in January as an evolution of the TookPS campaign, which has been underway since March 2025.
While Kaspersky Lab has not linked OkoBot to a specific threat actor, researchers found that the servers hosting PowerShell scripts were geo-blocked during the attack’s early stages.
Analysis revealed that using IP addresses from Russia or the Commonwealth of Independent States (CIS) led to non-delivery of the payload, with the server responding with empty data.
Evidence suggesting a Russian-speaking attacker includes comments in Russian within the SeedHunter module’s source code and the use of information theft tools heavily marketed on private Russian cybercrime forums.
For more detailed insights, refer to the Kaspersky report, which offers a range of indicators of compromise, including malicious plugins, injector payloads, SSH bot utilities, file paths, domains, and IP address hashes.
Security teams successfully document only 54% of attacks, issuing alerts on a mere 14%. The rest often go undetected.
Picus’ whitepaper explains how to enhance your SIEM and EDR rules using breach and attack simulations to identify lurking threats.
Source: www.bleepingcomputer.com




