Kaspersky identified OkoBot malware stealing cryptocurrency wallet seed phrases, browser credentials, and sensitive data across more than 25 countries worldwide. Attackers spread OkoBot throu
- Kaspersky identified OkoBot malware stealing cryptocurrency wallet seed phrases, browser credentials, and sensitive data across more than 25 countries worldwide.
- Attackers spread OkoBot through ClickFix attacks, fake GitHub repositories, and trojanized software installers that secretly infect unsuspecting cryptocurrency users.
- SeedHunter targets Ledger and Trezor wallets, while Kaspersky recommends trusted downloads, password managers, and multi-factor authentication for protection.
Cybersecurity firm Kaspersky has identified OkoBot, a malware framework that targets cryptocurrency users by stealing wallet seed phrases, browser credentials, and other sensitive information. Researchers found the malware uses more than 20 malicious modules and has already affected hundreds of users across more than 25 countries.
The campaign has operated for more than a year, with Brazil, Vietnam, Canada, Mexico, and Türkiye recording the highest number of victims. Moreover, Kaspersky believes the malware remains under active development, indicating attackers continue refining their techniques.
According to Kaspersky’s Global Research and Analysis Team, OkoBot mainly spreads through ClickFix attacks. This social engineering technique convinces victims to execute malicious commands manually instead of exploiting software vulnerabilities. Additionally, attackers publish fake GitHub repositories that imitate legitimate software projects to trick users into downloading infected files.
Also Read: Kenyan President’s Website Hacked as Attackers Demand 5 BTC Ransom in Defacement
Fake Installers Hide Malware Behind Trusted Software
Researchers also identified a fake installer disguised as Microsoft’s SQL Server Management Studio. Instead of installing the genuine application, it deployed a trojanized version of the Audacity audio editor containing malicious code.
Once activated, the malware launches a PowerShell script known as TookPS. The script installs an SSH bot that gathers usernames, operating system details, antivirus information, IP addresses, browser credentials, and cryptocurrency wallet data. Furthermore, it disables Windows Defender notifications while stealing browser cookies and login information.
Kaspersky noted that the malware collects enough system information to help attackers expand their access after the initial infection. As a result, compromised devices can expose both personal credentials and cryptocurrency-related data.
SeedHunter Targets Hardware Wallet Recovery Phrases
Kaspersky identified SeedHunter as one of OkoBot’s most dangerous modules because it targets popular hardware wallet applications. The malware injects malicious code into Trezor Suite, Ledger Wallet, and Ledger Live. Instead of displaying legitimate recovery pages, the compromised applications present convincing phishing screens. Consequently, users attempting to restore their wallets unknowingly submit their seed phrases directly to attackers.
Kaspersky warned that anyone who loses a recovery phrase also loses control of the associated cryptocurrency wallet. Attackers can transfer digital assets immediately, leaving victims with little chance of recovering their funds. Besides SeedHunter, the malware includes several additional spying tools. OkoSpyware records keystrokes and captures videos of cryptocurrency wallet windows through FFmpeg. Meanwhile, MC Keylogger collects clipboard contents, screenshots, copied images, USB connection activity, file paths, and keyboard input.
Another component, called ext daemon, targets Chromium-based browsers. It silently installs the malicious Rilide browser extension, enabling attackers to collect browser cookies, saved passwords, financial information, and cryptocurrency-related data without alerting users.
Kaspersky also found evidence showing the campaign has operated since at least mid-2025. Although researchers could not confidently attribute the attacks to a known cybercriminal group, several techniques resemble those previously associated with Russian-speaking threat actors. However, the servers distributing the malware block connections originating from Russia and Commonwealth of Independent States countries.
Dmitry Galov, Head of the Russia and CIS unit at Kaspersky GReAT, identified software developers as one of the campaign’s primary targets because attackers heavily rely on fake GitHub repositories and fraudulent software downloads. Therefore, Kaspersky urged users to download software only from trusted sources, avoid executing code from unverified repositories, enable multi-factor authentication, keep security software active, and store wallet recovery phrases in dedicated password managers instead of notes or photo galleries.
Conclusion
OkoBot highlights how attackers are combining social engineering with credential theft to target cryptocurrency users and software developers. Its expanding toolkit reinforces the importance of verifying software sources and protecting wallet recovery phrases from phishing attempts.
Also Read: Ripple President Monica Long Earns Dual Recognition on Stablecon’s Most Influential 2026 List
The post OkoBot Malware Steals Crypto Wallet Seed Phrases Through Fake GitHub Downloads appeared first on 36Crypto.