Kaspersky GReAT Unveils OkoBot Malware Framework: Specifically Designed to Steal Cryptocurrency Wallet Mnemonics, Browser Cookies, and More
Coin Circle (120btc.CoM): Kaspersky's Global Research and Analysis Team (GReAT) has unveiled a malware framework named OkoBot. This framework comprises over 20 types of malicious programs and implants that operate collaboratively through SSH tunnels, specifically designed to steal mnemonics from cryptocurrency wallets, browser cookies, and account passwords, having infiltrated hundreds of users across 25 countries worldwide.
OkoBot Framework: 20 Types of Malware Collaborating
OkoBot is not a single piece of malware but a complete modular attack framework. Kaspersky detailed the entire infection chain in a Securelist technical report: TookPS downloader is responsible for the initial intrusion → SSHbot collects system information and establishes a reverse tunnel → HDUtil launcher deploys various malicious modules → ultimately sending stolen data back via SFTP.
The framework includes five main plugins:
- CMD Wrapper (10xx): Executes command codes and individual instructions within the system
- PowerShell Wrapper (11xx): Supports execution of PowerShell command codes
- Environment Enumerator (12xx): Collects system information, active sessions, and processes
- Downloader (14xx): Downloads additional payloads from embedded Base64 binary blobs or URLs
- Process Injector (16xx): Injects malicious implants into normal processes
SeedHunter: Stealing Ledger and Trezor Mnemonics
One of the core modules, SeedHunter, monitors active processes in the system and injects implants into applications like Trezor Suite, Ledger Wallet, and Ledger Live. When a connected hardware wallet is detected, SeedHunter displays a hardcoded phishing page requesting the user to input their mnemonic. This page uses different layouts for each wallet type, and the stolen mnemonics are subsequently sent back to the C2 server encrypted with RC4.
Kaspersky specifically pointed out in its official press release that the infection routes for OkoBot mainly include ClickFix click fraud and disguised software distributed via GitHub. Researchers identified cases of fake SQL Server Management Studio installers that were actually embedded with malicious implants in the Audacity audio editor.
OkoSpyware: Simultaneously Recording Keystrokes and Screens
The newly added OkoSpyware module captures both keyboard inputs and video streams of target application windows. It lists over 100 executable names, including cryptocurrency wallets like Exodus and Litecoin QT, password managers like KeePassXC and 1Password, as well as various commonly used applications. For each identified process, OkoSpyware uses a built-in FFmpeg instance to record MP4 videos while simultaneously logging keystrokes.
Browsers are not exempt; when OkoSpyware detects the window title of wallet extension pages like MetaMask or Tonkeeper, it automatically starts recording video and input, writing the window title into a JSON relay data file.
Active for Over a Year, Developers as Primary Target
The infection chain of OkoBot has been operational since April 2025, continuing for over a year and still evolving. Kaspersky researchers noted that the countries most affected by attacks include Brazil, Vietnam, Canada, Mexico, and Turkey. While it is currently impossible to attribute the attacks to a specific criminal group, technical analysis has revealed traces of Russian-language code, and the espionage program used by the malware (Rilide) is widely circulated on Russian-language cybercrime forums.
Kaspersky warned in the report that the ongoing evolution of the OkoBot framework indicates that the backend maintainers are still actively developing it. As distribution activities continue, the framework has the potential to impact more cryptocurrency users and developers.
Disclaimer: This content is provided for general branding and informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online events, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets or to use any services. Crypto assets are highly volatile and may result in loss. WEEX services and online events may not be available in all regions and are subject to applicable laws, regulations, and eligibility requirements. You are responsible for ensuring that your use of WEEX services complies with local laws and for carefully assessing the risks before participating in any crypto-related activities.
You may also like

The Pressure Moment for Base

WEEX P2P now supports DOP, PEN, CLP & BOB—Merchant Recruitment Now Open

Bernstein Analysis: 50GW Power Revaluation of Equipment Stocks, Is the AI Equipment Super Cycle Coming?

Bridging Finance and Web3: Next-Generation Payment Infrastructure Built by Financial Institutions Together|WebX2026

From Le Mans to Portimão: Carl Moon Delivers Back-to-Back Podiums on Racing's Toughest Track
Crypto influencer and racing driver Carl Moon backed by WEEX secured P2 and P4 finishes at the Ferrari Challenge Portugal round in Portimão, marking his second consecutive podium weekend of the season. Here's how he did it — and what's next.

The Long Tail Phenomenon of the Korean Exchange: Why is the Coin Listing Effect So Prominent?

Why Did Mining Stocks Rise While BTC Fell 46%?

Hong Kong Stablecoin HKDAP Set to Launch This Month, Reports Say

Hong Kong Monetary Authority Forms Tokenized Bond Expert Group

Account Wars: When Dollar Accounts Emerge Outside of Banks

Wall Street is buying cryptocurrencies again in droves. This hasn't happened in months!

Former Executive Charged in TSMC Technology Leak Attempt as Taiwan Strengthens Vigilance Against Chinese Espionage

Decentralization is the Only Defense for Public Chains Under Capital Siege

Wanchain Cardano bridge exploit drains 515M NIGHT worth $9M

War, Bitcoin, and the Super Cycle: We May Be Closer to the Bottom Than We Feel

Recreating the 'DeepSeek Moment'? Wall Street Says Kimi K3 Actually Strengthens Demand for Computing Power

What is isolated margin and cross margin? The trading minute

Ripple veteran regrets selling XRP at $0.10 and Ethereum near $1

Bitcoin Approaches $70,000! July 21 Assessment

WAIC Observation: Crowded Consensus, Huge Bubble

What is 'Currency'? Exploring the History of Digital Money and the Duality of Currency and Assets (Episode 10 of 'So That's How Blockchain Works')

Bitcoin at $72,000: The $2.5 Billion Bet Timed for the Fed Meeting

Bitcoin ETF: Two Consecutive Weeks in the Green

Polymarket refers nearly 100 wallets amid $200M insider-trade concerns

Has Trustlessness Erased Trust? - A Reconfiguration of Verification | HashHub Research

HashKey taps Kbank, BPMG in South Korea stablecoin payments push

Did Vlad Follow Pons to Claim the Robinhood Chain Launchpad Throne?

10-Day Ceasefire Proposal Emerges, but Energy, Shipping, and Capital Cost Risk Chains Remain Unresolved

US SEC Sues Massachusetts Cryptocurrency Mining Company Mining Automatic: Features of a Ponzi Scheme

Airbnb CEO's X Account Compromised, AI-Generated Cryptocurrency Posts Spread
The Pressure Moment for Base
WEEX P2P now supports DOP, PEN, CLP & BOB—Merchant Recruitment Now Open
Bernstein Analysis: 50GW Power Revaluation of Equipment Stocks, Is the AI Equipment Super Cycle Coming?
Bridging Finance and Web3: Next-Generation Payment Infrastructure Built by Financial Institutions Together|WebX2026
From Le Mans to Portimão: Carl Moon Delivers Back-to-Back Podiums on Racing's Toughest Track
Crypto influencer and racing driver Carl Moon backed by WEEX secured P2 and P4 finishes at the Ferrari Challenge Portugal round in Portimão, marking his second consecutive podium weekend of the season. Here's how he did it — and what's next.






