A New Malicious Framework Spreads Across the Globe, Stealing Sensitive Data and Cryptocurrency
A highly sophisticated malicious framework called OkoBot has been identified by cybersecurity researchers at Kaspersky, delivering over 20 payloads to steal cryptocurrency wallet seed phrases, credentials, and other sensitive data. This campaign has been ongoing for more than a year, with attacks reaching victims through ClickFix attacks or malicious GitHub repositories that pretend to host legitimate software tools.
One notable example of how OkoBot operates is by masquerading as the SQL Server Management Studio (SSMS) on GitHub, but instead dropping a trojanized version of the Audacity audio editing tool. This tactic highlights the sophistication and stealth of the attackers, who have successfully evaded detection for an extended period.
The infection chain used by OkoBot has undergone significant changes since its inception, evolving from the earlier TookPS campaign that delivered malicious PowerShell scripts. The new framework uses multiple attack stages, with TookPS serving as the initial stage to install and configure an SSH bot that delivers additional malicious components. This SSH bot is responsible for collecting system details, disabling Windows Defender notifications, and harvesting sensitive data such as cryptocurrency wallet files, browser cookies, and account credentials.
Among the 20 modules used by OkoBot are several notable payloads that demonstrate its focus on stealing sensitive information. For instance, “ext daemon/extl.exe” injects into Chrome browsers to install and hide malicious extensions like Rilide, which targets credentials, cookies, financial information, and cryptocurrency-related data. Another payload called SeedHunter displays a fake seed-recovery screen designed to steal wallet recovery phrases from victims.
Kaspersky’s research has revealed that OkoBot’s victims are primarily located in Brazil, followed by Vietnam, Canada, Mexico, and Turkey. However, the campaign’s reach is global, with attacks observed across multiple regions. The researchers have also discovered clues pointing to a Russian-speaking threat actor, including geoblocked access to servers hosting the initial PowerShell scripts and the presence of Russian comments in the source code of the SeedHunter module.
For individuals and organizations, this serves as a stark reminder of the importance of robust security measures and staying vigilant against evolving threats. As Kaspersky’s report highlights, it is essential to test every layer of defense before attackers do, using techniques such as breach and attack simulation to identify vulnerabilities in SIEM and EDR rules.
In light of these findings, we recommend that users take immediate action to protect themselves from OkoBot attacks:
* Verify the authenticity of software tools and repositories before installing them.
* Regularly update and patch all systems and applications.
* Implement robust security measures, including anti-virus software and firewalls.
* Stay informed about emerging threats and adjust your defenses accordingly.
By being aware of these risks and taking proactive steps to secure your environment, you can reduce the likelihood of falling victim to OkoBot’s sophisticated attacks.
Source: Bleeping Computer — 2026-07-16