Kaspersky recently revealed a new malicious framework that targets cryptocurrency users with the use of OkoSpyware, named OkoBot.
The new framework utilizes TookPS for exfiltrating seed phrases and OkoSpyware for monitoring Chromium-based browsers, deploying malware including the Rilide stealer. It has impacted hundreds of victims in over 25 countries, particularly in Brazil, Vietnam, Canada, Mexico, and Türkiye. Kaspersky experts indicate that this active threat primarily targets cryptocurrency users.
In January 2026, Kaspersky’s GReAT team uncovered a new malware, Okobot, that targets cryptocurrency wallets. This sophisticated framework includes over 20 malicious payloads, capable of functions such as collecting local files, executing commands, stealing cryptocurrency wallets, and recording video. A notable implant modifies browser memory to load and conceal malicious extensions, while another module, OkoSpyware, captures keystrokes and video streams from applications.
Information currently does not permit attributing the campaign to a specific crimeware actor with high confidence. However, the involved techniques and infostealer are commonly used by Russian-speaking threat actors, with technical analysis indicating code artifacts in Russian.
The initial infection occurs through ClickFix attacks, where threat actors use social engineering to deceive users into executing malicious code, and through malware distributed on GitHub as legitimate software. One confirmed case involved a fake SQL Server Management Studio (SSMS) installer.
The malicious framework features SeedHunter, a malware component that tracks system processes and injects an implant into cryptocurrency management applications like Trezor Suite and Ledger Wallet. Upon detecting a connected Trezor or Ledger hardware wallet, it activates functions to present a phishing page designed to steal the user’s seed phrase, with a unique layout for each wallet type.

“The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026. The observed infection vectors strongly suggest that developers are among its primary targets. Of particular concern is the malware’s continued evolution, which indicates that the framework is being actively maintained. As distribution efforts persist, the campaign has the potential to reach more users and expand into additional countries in the near term.”
Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team
The full report is available on the link below.
To stay safe, Kaspersky GReAT experts recommend users:
- Never follow instructions from unverified sources to deploy unknown code on a device, whether given directly or found in guides. Attackers often use this tactic to infect systems, which can lead to data loss and even loss of control over the device.
- Use a strong security solution on all computers and mobile devices, such as Kaspersky Premium. It will warn you and prevent an infection.
- Manage sensitive data securely: avoid storing passwords or recovery phrases in your photo gallery or notes; instead, use a dedicated, trusted password manager such as Kaspersky Password Manager.
- Never disable antivirus or security tools to install software and exercise caution when downloading game mods, cheats or third-party utilities.
Keep operating systems and applications updated, use strong, unique passwords and enable multi-factor authentication wherever possible.


