Malware

OkoBot Framework Steals Data and Crypto

July 18, 2026 12:25 · 12 min read
OkoBot Framework Steals Data and Crypto

OkoBot Framework: A New Malicious Framework

A new malicious framework called OkoBot has been discovered, delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data. The framework reaches victims through ClickFix attacks or malicious GitHub repositories pretending to host legitimate software tools.

Infection Chain

Researchers at cybersecurity company Kaspersky say that the OkoBot campaign has been ongoing for more than a year and evolved from the activity that delivered the malicious PowerShell script TookPS. However, the infection chain has been completely changed, with multiple attack stages and TookPS being used in the first phase to install and configure an SSH bot that delivered the other malicious components.

The SSH bot is also responsible for collecting system details (username, antivirus software, IP address, OS version) and disabling Windows Defender notifications. It also harvests cryptocurrency wallet files, browser cookies, and account credentials.

Notable Modules

Among the 20 modules OkoBot uses in these attacks, the most notable are:

It's essential to note that a wallet recovery phrase provides full access to a user's cryptocurrency assets. If attackers obtain it, they can transfer the funds to wallets they control, with virtually no possibility of recovery.

Victim Location and Campaign Reach

Kaspersky telemetry shows that the majority of OkoBot's victims are located in Brazil, followed by Vietnam, Canada, Mexico, and Turkey. However, the campaign’s reach is global. OkoBot activity was first observed in January as an evolution of the TookPS campaign that has been running since March 2025.

Threat Actor Attribution

While Kaspersky does not attribute the OkoBot campaign to any threat actor, the researchers shared that access to the servers hosting the PowerShell scripts for the initial stage of the attack is geoblocked. They noticed that payloads are not delivered when using an IP address from Russia or the Commonwealth of Independent States (CIS) space, and the server returns an empty response. Additional clues pointing to a Russian-speaking threat actor include Russian comments present in the source code of the SeedHunter module and the use of an infostealer that is actively promoted on invitation-only Russian cybercrime forums.

Kaspersky's report provides a set of indicators of compromise that includes hashes for the malicious plugins, injector payloads, SSH bot utilities, file paths, domains, and IP addresses.

Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free