OkoBot's 20-Payload Assault on Crypto Wallets
A malware framework called OkoBot is hitting hard — and it's not pulling any punches. Researchers at Kaspersky have been tracking a campaign that deploys more than 20 distinct payloads in attacks laser-focused on stealing cryptocurrency wallet seed phrases, browser credentials, and other sensitive data. What makes this particularly nasty isn't just the volume of tools in the arsenal, but how methodically each one is designed to extract value from victims.
The campaign has been running for over a year, evolving from an earlier infostealer called TookPS that first appeared in March 2025. OkoBot itself was spotted in January 2026, but calling it a successor undersells how thoroughly the infection chain was rebuilt from the ground up. This isn't TookPS with a fresh coat of paint — it's a complete architectural rethink.
Victims are being reached through two primary vectors: ClickFix social engineering attacks, where users are tricked into running malicious commands under the guise of fixing a software issue, and malicious GitHub repositories that masquerade as legitimate software distribution channels. In one particularly brazen example, a repository claimed to host SQL Server Management Studio (SSMS) but actually delivered a trojanized version of the Audacity audio editing tool. The audacity, honestly.
Source
Kaspersky researchers documented the campaign's delivery mechanisms, noting that OkoBot reaches victims through ClickFix attacks or malicious GitHub repositories pretending to host legitimate software tools. In one case, a repository claimed to offer SQL Server Management Studio (SSMS) but dropped a trojanized version of the Audacity audio editing tool.
The Infection Chain: TookPS Meets SSH Bot
Here's where the architecture gets interesting. The old TookPS campaign was already functional, but OkoBot restructured everything into a multi-stage pipeline. TookPS now serves as the entry point — its sole job is to install and configure an SSH bot on the victim's machine. That SSH bot then becomes the delivery vehicle for all 20 remaining malicious components.
The SSH bot itself is a surprisingly capable piece of malware. Before it even starts harvesting data, it gathers intelligence: username, antivirus software in use, IP address, and OS version. It also quietly disables Windows Defender notifications so the victim doesn't get spammed with alerts while their system is being gutted. Smart, in a deeply unpleasant way.
Once reconnaissance is complete and defenses are muted, the bot goes to work. It harvests cryptocurrency wallet files, browser cookies, and account credentials — basically everything that could be monetized. And then it starts deploying the actual payload modules, one by one.
Source
Kaspersky researchers say the OkoBot campaign has been ongoing for more than a year and evolved from the activity that delivered the malicious PowerShell script TookPS. The infection chain has been completely changed, with multiple attack stages and TookPS being used in the first phase to install and configure an SSH bot that delivered the other malicious components. The SSH bot is also responsible for collecting system details (username, antivirus software, IP address, OS version) and disabling Windows Defender notifications. It also harvests cryptocurrency wallet files, browser cookies, and account credentials.
The Payload Arsenal: Chrome Injectors, Keyloggers, and Fake Recovery Screens
Let's talk about what these 20 modules actually do, because the list is both impressive and deeply disturbing.
ext daemon/extl.exe injects into Chrome browsers to silently install and hide malicious extensions like Rilide. This extension then targets credentials, cookies, financial information, and cryptocurrency-related data sitting right in the victim's browser. No popup asking for permission. Just... gone.
SeedHunter is where things get truly malicious. This module injects into Trezor Suite, Ledger Wallet, and Ledger Live — the actual applications people use to manage their crypto holdings. It displays a fake seed-recovery screen designed specifically to steal wallet recovery phrases. Think about that for a second: the malware pretends to help you recover your wallet while actually handing the keys directly to attackers.
MC Keylogger records keystrokes and clipboard activity, including copied text, images, and file paths. It can also monitor for USB connections and takes screenshots every 5 minutes. That's not a bug, that's a feature — from the attacker's perspective, anyway.
OkoSpyware monitors 100 programs like cryptocurrency wallets and password managers, uses FFmpeg to record video of their windows, and also captures keystrokes. One hundred programs. The thing is, most people don't even realize their screen is being recorded until it's too late.
Source
Among the 20 modules OkoBot uses in these attacks, the most notable are: ext daemon/extl.exe injects into Chrome browsers to silently install and hide malicious extensions like Rilide, which targets credentials, cookies, financial information, and cryptocurrency-related data. SeedHunter injects into Trezor Suite, Ledger Wallet, and Ledger Live to display a fake seed-recovery screen designed to steal wallet recovery phrases from victims. MC Keylogger records keystrokes and clipboard activity, including copied text, images, and file paths, and can also monitor for USB connections and take screenshots every 5 minutes. OkoSpyware monitors 100 programs like cryptocurrency wallets and password managers, and uses FFmpeg to record video of their windows and also capture keystrokes.
Why Seed Phrases Are the Ultimate Prize
Here's the part that should keep crypto users up at night: a wallet recovery phrase provides full access to a user's cryptocurrency assets. If attackers obtain it, they can transfer the funds to wallets they control, with virtually no possibility of recovery.
This isn't like a stolen password that can be changed. Once that seed phrase is in the wrong hands, the funds are gone. Permanently. There's no customer service to call, no chargeback process, no way to reverse a blockchain transaction.
SeedHunter's approach is particularly clever because it doesn't just steal the phrase while the user has it typed in — it creates an entire fake recovery interface. The victim thinks they're troubleshooting a legitimate issue with their wallet software, and the malware is sitting there waiting for them to enter their recovery phrase. By the time they realize something's wrong, the funds have already been moved.
The combination of SeedHunter with OkoSpyware's screen recording capability means attackers get both the visual confirmation that the phrase was entered correctly and the actual data. It's a one-two punch designed to maximize success rates.
Source
It's important to note that a wallet recovery phrase provides full access to a user's cryptocurrency assets. If attackers obtain it, they can transfer the funds to wallets they control, with virtually no possibility of recovery.
Victim Geography and Attribution Clues
Kaspersky's telemetry paints a clear picture of who's getting hit. The majority of OkoBot victims are located in Brazil, followed by Vietnam, Canada, Mexico, and Turkey. But the campaign's reach is global — no region is safe.
As for who's behind it, Kaspersky hasn't officially attributed the campaign to any specific threat actor. But there are some strong clues pointing in a particular direction.
Access to the servers hosting the PowerShell scripts for the initial stage of the attack is geoblocked. When researchers tried accessing them from Russia or the Commonwealth of Independent States (CIS) space, the server returned an empty response. That's not a coincidence — it's a deliberate barrier.
Additional clues point to a Russian-speaking threat actor. The source code of the SeedHunter module contains Russian comments, and the infostealer is actively promoted on invitation-only Russian cybercrime forums. These aren't smoking guns, but they're enough to make investigators lean in a particular direction.
Source
Kaspersky telemetry shows that the majority of OkoBot's victims are located in Brazil, followed by Vietnam, Canada, Mexico, and Turkey. However, the campaign's reach is global. While Kaspersky does not attribute the OkoBot campaign to any threat actor, the researchers shared that access to the servers hosting the PowerShell scripts for the initial stage of the attack is geoblocked. They noticed that payloads are not delivered when using an IP address from Russia or the Commonwealth of Independent States (CIS) space, and the server returns an empty response. Additional clues pointing to a Russian-speaking threat actor include Russian comments present in the source code of the SeedHunter module and use of an infostealer that is actively promoted on invitation-only Russian cybercrime forums.
Indicators of Compromise and What to Watch For
Kaspersky's report provides a comprehensive set of indicators of compromise that security teams should be looking for. These include hashes for the malicious plugins, injector payloads, and SSH bot utilities, as well as file paths, domains, and IP addresses associated with the campaign.
For individual users, the practical takeaway is straightforward: be skeptical of GitHub repositories offering legitimate software tools. If something looks off — weird file names, unusual download counts, repositories created recently with no history — walk away. The same goes for ClickFix-style prompts. If your browser tells you there's a problem and offers to "fix" it with a command, verify through official channels first.
For organizations managing crypto assets, the SeedHunter threat alone should trigger an immediate review of endpoint protection. Traditional antivirus might not catch these injectors, especially when they're hiding inside legitimate-looking applications like Trezor Suite or Ledger Live.
Source
Kaspersky's report provides a set of indicators of compromise that includes hashes for the malicious plugins, injector payloads, SSH bot utilities, file paths, domains, and IP addresses.