Kaspersky Unveils OkoBot Malicious Attack: 20+ Programs Team Up to Steal Crypto Wallet Seed Phrases

Kaspersky GReAT team exposes the malicious software framework OkoBot, in which more than 20 types of malware team up to steal crypto wallet mnemonic phrases, browser cookies, and other data; it has already infiltrated 25 countries and hundreds of users worldwide.
(Background: Be careful! Kaspersky has found malware that steals wallet mnemonic phrases in popular Android and iOS apps)
(Additional background: The malware SparkKitty infiltrated Apple and Google stores, stealing crypto wallet “mnemonic screenshot” data)

Table of contents

Toggle

  • OkoBot framework: 20 types of malware working together
  • SeedHunter: steals Ledger and Trezor mnemonic phrases
  • OkoSpyware: records both keystrokes and the screen
  • Continuously active for over a year, with the developer as the main target

Kaspersky’s Global Research and Analysis Team (GReAT) has uncovered a malicious software framework called OkoBot. The framework includes more than 20 types of malicious programs and implants, working in coordination through SSH tunnels. It is designed to steal cryptocurrency wallet mnemonic phrases, browser cookies, and account passwords, and has infiltrated hundreds of users across 25 countries worldwide.

OkoBot framework: 20 types of malware working together

OkoBot is not a single piece of malware, but a modular attack framework. In a Securelist technical report, Kaspersky breaks down the full infection chain in detail: the TookPS downloader is responsible for the initial intrusion → the SSH bot collects system information and establishes a reverse tunnel → the HDUtil loader deploys the various malicious modules → finally, the stolen data is sent back via SFTP.

The framework includes five main plugins:

  • CMD wrapper (10xx): executes scripts and individual commands on the system
  • PowerShell wrapper (11xx): supports PowerShell script execution
  • environment enumerator (12xx): collects system information, active sessions, and processes
  • downloader (14xx): downloads additional payloads from an embedded Base64 binary blob or from a URL
  • process injector (16xx): injects malicious implants into legitimate processes

SeedHunter: steals Ledger and Trezor mnemonic phrases

One of the core modules, SeedHunter, monitors active processes on the system and injects implants into applications such as Trezor Suite, Ledger Wallet, and Ledger Live. When it detects a connected hardware wallet, SeedHunter displays a hardcoded phishing page that prompts the user to enter their mnemonic phrase. The page uses different layout designs for each wallet type, and the stolen mnemonic phrase is subsequently sent back to the C2 server after being encrypted with RC4.

Kaspersky specifically noted in an official press release that OkoBot’s main infection methods include ClickFix click-fraud and disguised software distributed via GitHub. Researchers identified cases involving a fake SQL Server Management Studio installer, which actually embeds a malicious implant inside the Audacity audio editor.

OkoSpyware: records both keystrokes and the screen

The latest addition to OkoBot, the OkoSpyware module, captures both keyboard input and a video stream of the target application window. It lists more than 100 executable file names, including crypto wallets such as Exodus and Litecoin QT, password managers such as KeePassXC and 1Password, and various common applications. For each identified process, OkoSpyware uses an embedded FFmpeg instance to record MP4 videos while also recording keystroke input.

Browsers are not exempt either. When OkoSpyware detects the window title of a wallet extension page such as MetaMask or Tonkeeper, it automatically starts recording and logs input, and writes the window title into a JSON metadata file.

Continuously active for over a year, with the developer as the main target

OkoBot’s infection chain has been operating since April 2025; it has already been over a year and is still evolving. Kaspersky researchers said the countries with the most attacked users are Brazil, Vietnam, Canada, Mexico, and Turkey. Although it is currently not possible to determine attribution to a specific criminal group, technical analysis found traces of Russian-language code, and the malware’s exfiltration module (Rilide) is widely circulated on Russian-language cybercrime forums.

In its report, Kaspersky warns that the continued evolution of the OkoBot framework shows that the backend maintainer is still actively developing it. As distribution activities continue, the framework has the potential to impact more cryptocurrency users and developers.

LTC-1.07%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned