Need help? Support
BITCOIN
Tether Dominance USDT.D

OkoBot malware campaign expands against crypto wallets

Published 564 words 3 min read

TLDR

OkoBot is a modular malware framework that has been actively expanding its attacks on crypto users, focusing on stealing wallet recovery phrases and credentials.

  1. OkoBot uses social engineering and trojanized software to infect devices, then deploys about 20 payloads that target crypto wallets and sensitive data.
  2. The campaign has run for over a year, hitting hundreds of victims across more than 25 countries and directly phishing hardware wallet seed phrases.
  3. The main defense is strict operational hygiene: never entering seed phrases into software prompts, and downloading tools only from verified official sources.

Deep Dive

1. How OkoBot Works

Security firm Kaspersky describes OkoBot as a malware framework rather than a single virus, bundling more than 20 modules focused on crypto theft. It is delivered through tactics like ClickFix pop up repair messages and trojanized GitHub repositories disguised as legitimate tools such as SQL Server Management Studio, which silently install the malware once run on a victim device.

After infection, OkoBot orchestrates all its payloads through an SSH tunnel, letting attackers harvest wallet files, browser data, credentials, and live wallet application windows from compromised computers and send them to attacker controlled machines. Modules like SeedHunter and OkoSpyware specifically target crypto apps, key managers, and hardware wallet software, according to Kasperskys technical analysis and follow up reporting from Crypto.news and Cointelegraph.

2. Scale And Targets

Researchers report that the OkoBot campaign has been active for more than a year, with multiple attacks observed since early 2026 and hundreds of victims across at least 25 countries, including Brazil, Vietnam, Canada, Mexico, and Trkiye. The operation focuses on people who hold and move digital assets, not on any single coin or chain.

A critical risk is that SeedHunter injects fake recovery pages directly into Trezor Suite, Ledger Wallet, and Ledger Live, prompting users to re enter seed phrases inside what looks like legitimate software. Once a seed is captured, attackers gain full control of the wallet, and on chain transfers are effectively irreversible. Technical clues like geoblocking and Russian language comments point to a Russian speaking operator, but attribution remains unconfirmed.

What this means

The attack is aimed at self custody workflows themselves, so even cold hardware wallet users are at risk if they type seed phrases into compromised devices.

3. Defenses And What To Watch

Kaspersky and wallet makers converge on one core rule: never enter seed phrases or private keys into any software prompt, pop up, or web page, even if it appears inside a familiar wallet interface. Recovery phrases should only be written down and used for restoring devices in strictly controlled conditions.

Operationally, the higher risk zones are developer tools, productivity software from unverified GitHub repos, and scripts that ask you to paste commands into a terminal. The broader trend, highlighted by related ClickFix and LinkedIn based campaigns against Web3 developers, is that attackers increasingly exploit realistic workflows rather than obviously fake scam sites. Watching for future reports from Kaspersky, SlowMist, and other security firms will be important to track copycat frameworks that reuse OkoBots modules.

Conclusion

OkoBot shows that modern crypto malware is built as flexible toolkits that plug directly into self custody habits, especially hardware wallet recovery and developer tooling. For crypto users, the main protection is not a specific device, but disciplined operational security: treating seed phrases as offline only, treating software prompts as untrusted by default, and being very selective about what code runs on any machine that ever touches a wallet.

Educational information only. Crypto markets are volatile and this is not financial advice.


Top