New OkoBot framework deploys 20 payloads to steal data, crypto

New Malicious Framework, OkoBot, Deploying 20 Payloads to Steal Data and Crypto

A sophisticated malicious framework called OkoBot has been identified by cybersecurity researchers at Kaspersky, deploying over 20 payloads in attacks designed to steal sensitive data, including cryptocurrency wallet seed phrases, credentials, and other valuable information. The framework’s reach is global, with a significant presence in Brazil, Vietnam, Canada, Mexico, and Turkey.

OkoBot’s infection chain involves multiple attack stages, with the initial phase using the malicious PowerShell script TookPS to install an SSH bot on compromised devices. This SSH bot collects system details, disables Windows Defender notifications, and harvests cryptocurrency wallet files, browser cookies, and account credentials. The framework then injects malicious plugins into browsers, including Chrome, to silently install and hide extensions that target sensitive data.

One of the most notable modules used by OkoBot is SeedHunter, which injects into Trezor Suite, Ledger Wallet, and Ledger Live to display a fake seed-recovery screen designed to steal wallet recovery phrases from victims. A stolen wallet recovery phrase provides full access to a user’s cryptocurrency assets, allowing attackers to transfer funds to wallets they control with virtually no possibility of recovery.

The framework also uses other malicious modules, including ext daemon/extl.exe, which injects into Chrome browsers to install and hide malicious extensions; MC Keylogger, which records keystrokes and clipboard activity; and OskoSpyware, which monitors 100 programs like cryptocurrency wallets and password managers. These modules allow attackers to capture sensitive data, including financial information, and transfer funds undetected.

Kaspersky researchers have been tracking the OkoBot campaign for over a year, observing that it has evolved from the TookPS activity that started in March 2025. While no threat actor has been attributed to the OkoBot campaign, additional clues point to a Russian-speaking threat actor. The use of geoblocked servers hosting PowerShell scripts and the presence of Russian comments in the source code of the SeedHunter module suggest a connection to Russian cybercrime forums.

Security teams should take note that OkoBot’s reach is global, and users from all over the world may be affected by these attacks. To protect against such threats, it’s essential to stay informed about emerging malware and frameworks like OkoBot. Security experts recommend implementing robust security measures, including regular software updates, strong antivirus protection, and secure password management practices.

In conclusion, the emergence of OkoBot highlights the need for vigilance in cybersecurity. Users should be cautious when downloading software from untrusted sources, especially those claiming to offer legitimate tools like SQL Server Management Studio or audio editing software. By being aware of these threats and taking proactive measures to protect themselves, users can reduce their risk of falling victim to attacks like OkoBot.


Source: Bleeping Computer — 2026-07-16