Kaspersky GReAT Unveils OkoBot Malware Framework: Specifically Designed to Steal Cryptocurrency Wallet Mnemonics, Browser Cookies, and More
Coin Circle (120btc.CoM): Kaspersky's Global Research and Analysis Team (GReAT) has unveiled a malware framework named OkoBot. This framework comprises over 20 types of malicious programs and implants that operate collaboratively through SSH tunnels, specifically designed to steal mnemonics from cryptocurrency wallets, browser cookies, and account passwords, having infiltrated hundreds of users across 25 countries worldwide.
OkoBot Framework: 20 Types of Malware Collaborating
OkoBot is not a single piece of malware but a complete modular attack framework. Kaspersky detailed the entire infection chain in a Securelist technical report: TookPS downloader is responsible for the initial intrusion → SSHbot collects system information and establishes a reverse tunnel → HDUtil launcher deploys various malicious modules → ultimately sending stolen data back via SFTP.
The framework includes five main plugins:
- CMD Wrapper (10xx): Executes command codes and individual instructions within the system
- PowerShell Wrapper (11xx): Supports execution of PowerShell command codes
- Environment Enumerator (12xx): Collects system information, active sessions, and processes
- Downloader (14xx): Downloads additional payloads from embedded Base64 binary blobs or URLs
- Process Injector (16xx): Injects malicious implants into normal processes
SeedHunter: Stealing Ledger and Trezor Mnemonics
One of the core modules, SeedHunter, monitors active processes in the system and injects implants into applications like Trezor Suite, Ledger Wallet, and Ledger Live. When a connected hardware wallet is detected, SeedHunter displays a hardcoded phishing page requesting the user to input their mnemonic. This page uses different layouts for each wallet type, and the stolen mnemonics are subsequently sent back to the C2 server encrypted with RC4.
Kaspersky specifically pointed out in its official press release that the infection routes for OkoBot mainly include ClickFix click fraud and disguised software distributed via GitHub. Researchers identified cases of fake SQL Server Management Studio installers that were actually embedded with malicious implants in the Audacity audio editor.
OkoSpyware: Simultaneously Recording Keystrokes and Screens
The newly added OkoSpyware module captures both keyboard inputs and video streams of target application windows. It lists over 100 executable names, including cryptocurrency wallets like Exodus and Litecoin QT, password managers like KeePassXC and 1Password, as well as various commonly used applications. For each identified process, OkoSpyware uses a built-in FFmpeg instance to record MP4 videos while simultaneously logging keystrokes.
Browsers are not exempt; when OkoSpyware detects the window title of wallet extension pages like MetaMask or Tonkeeper, it automatically starts recording video and input, writing the window title into a JSON relay data file.
Active for Over a Year, Developers as Primary Target
The infection chain of OkoBot has been operational since April 2025, continuing for over a year and still evolving. Kaspersky researchers noted that the countries most affected by attacks include Brazil, Vietnam, Canada, Mexico, and Turkey. While it is currently impossible to attribute the attacks to a specific criminal group, technical analysis has revealed traces of Russian-language code, and the espionage program used by the malware (Rilide) is widely circulated on Russian-language cybercrime forums.
Kaspersky warned in the report that the ongoing evolution of the OkoBot framework indicates that the backend maintainers are still actively developing it. As distribution activities continue, the framework has the potential to impact more cryptocurrency users and developers.
Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.
You may also like

SBI Holdings Acquires Cryptocurrency Exchange Coinhako Following Approval from Singapore Authorities

Hotcoin Research | The Second Battlefield of the AI Super Cycle: A 24/7 On-Chain Pricing Experiment

Ansem: Redefining Meme Coins to Transform Creator Influence into Assets

Stripe's Ambition in Cryptocurrency Payments Behind $53.4 Billion PayPal Acquisition Proposal

Market Takes on 'Rate Hike', Waller Fully 'Fights Inflation'

Locus Chain Unveils Demonstration Video of Next-Generation Order Book Decentralized Exchange 'LDEX'

Polygon to Acquire Coinme, Implementing Workforce Reductions Amid Organizational Restructuring

U.S. Senate Unanimously Resolves Against Pardon for Sam Bankman-Fried

New Financial Infrastructure or Pseudo-Sewing Platform: What Web3 Neobank Is Doing

The End of Moonbeam: A Chain Without Killer Apps Will Eventually Learn to Read the Room

Japan reclassifies crypto as financial products, paving way for lower taxes and ETFs

Cardano Activates Its First Improvement Voted Through On-Chain Governance

Nvidia and Japan Seal Alliance for Industrial Physical AI

English Court Considers Whether Debt Can Be Paid in Bitcoin

Moonshot and the DeepSeek 2 Moment: What Changes in the AI Race

You Won't Understand What's Happening with Cryptocurrencies Unless You Look at the USA!

Van Rossem Hard Fork Activated on Cardano Network; Is It Time for ADA Price Surge?

Lyn Alden on the Bitcoin Fashion Debate: It's Not in My Top 10 Important Issues

"I made a mistake": Warren Buffett finally buys Google and explains why

Vale's CPI: Why Congress is Targeting Government Interference

USDT Holds Steady, USDS Plummets, the Stablecoin Market Changes Face

AI Shakes Online Trust: ZK Verification Emerges as a Solution

AZ-COM Maruwa puts ¥1B behind JPYC in major stablecoin push

Japan logistics giant plans JPYC payments for 2,300 partners

Activation of Solana (SOL) Trading and Stable Technical Support

UnitedHealth Surprises Wall Street and Signals Turnaround

Wall Street Eyes Korean Stocks: KOSPI's Price-to-Earnings Ratio Hits 20-Year Low, Goldman Sachs Maintains 12,000 Point Target for Buying on Dips

Circle president backs USDC as new rival pressures CRCL stock

Spreadefi: A closer look at whether it is a scam or not







