Kaspersky GReAT Unveils OkoBot Malware Framework: Specifically Designed to Steal Cryptocurrency Wallet Mnemonics, Browser Cookies, and More

By: rootdata|2026/07/19 11:46:07

Coin Circle (120btc.CoM): Kaspersky's Global Research and Analysis Team (GReAT) has unveiled a malware framework named OkoBot. This framework comprises over 20 types of malicious programs and implants that operate collaboratively through SSH tunnels, specifically designed to steal mnemonics from cryptocurrency wallets, browser cookies, and account passwords, having infiltrated hundreds of users across 25 countries worldwide.

OkoBot Framework: 20 Types of Malware Collaborating
OkoBot is not a single piece of malware but a complete modular attack framework. Kaspersky detailed the entire infection chain in a Securelist technical report: TookPS downloader is responsible for the initial intrusion → SSHbot collects system information and establishes a reverse tunnel → HDUtil launcher deploys various malicious modules → ultimately sending stolen data back via SFTP.

The framework includes five main plugins:

  • CMD Wrapper (10xx): Executes command codes and individual instructions within the system
  • PowerShell Wrapper (11xx): Supports execution of PowerShell command codes
  • Environment Enumerator (12xx): Collects system information, active sessions, and processes
  • Downloader (14xx): Downloads additional payloads from embedded Base64 binary blobs or URLs
  • Process Injector (16xx): Injects malicious implants into normal processes

SeedHunter: Stealing Ledger and Trezor Mnemonics
One of the core modules, SeedHunter, monitors active processes in the system and injects implants into applications like Trezor Suite, Ledger Wallet, and Ledger Live. When a connected hardware wallet is detected, SeedHunter displays a hardcoded phishing page requesting the user to input their mnemonic. This page uses different layouts for each wallet type, and the stolen mnemonics are subsequently sent back to the C2 server encrypted with RC4.

Kaspersky specifically pointed out in its official press release that the infection routes for OkoBot mainly include ClickFix click fraud and disguised software distributed via GitHub. Researchers identified cases of fake SQL Server Management Studio installers that were actually embedded with malicious implants in the Audacity audio editor.

OkoSpyware: Simultaneously Recording Keystrokes and Screens
The newly added OkoSpyware module captures both keyboard inputs and video streams of target application windows. It lists over 100 executable names, including cryptocurrency wallets like Exodus and Litecoin QT, password managers like KeePassXC and 1Password, as well as various commonly used applications. For each identified process, OkoSpyware uses a built-in FFmpeg instance to record MP4 videos while simultaneously logging keystrokes.

Browsers are not exempt; when OkoSpyware detects the window title of wallet extension pages like MetaMask or Tonkeeper, it automatically starts recording video and input, writing the window title into a JSON relay data file.

Active for Over a Year, Developers as Primary Target
The infection chain of OkoBot has been operational since April 2025, continuing for over a year and still evolving. Kaspersky researchers noted that the countries most affected by attacks include Brazil, Vietnam, Canada, Mexico, and Turkey. While it is currently impossible to attribute the attacks to a specific criminal group, technical analysis has revealed traces of Russian-language code, and the espionage program used by the malware (Rilide) is widely circulated on Russian-language cybercrime forums.

Kaspersky warned in the report that the ongoing evolution of the OkoBot framework indicates that the backend maintainers are still actively developing it. As distribution activities continue, the framework has the potential to impact more cryptocurrency users and developers.

-- Price

--

Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.

You may also like

iconiconiconiconiconiconicon
Customer Support:@weikecs
Business Cooperation:@weikecs
Quant Trading & MM:[email protected]
VIP Program:[email protected]