CryptoMag
NEWS Published: JUL 20, 2026, 8:30 AM

Kaspersky Uncovers OkoBot Malware Targeting Crypto Wallets

Kaspersky Uncovers OkoBot Malware Targeting Crypto Wallets

Kaspersky has identified a malware operation known as OkoBot, which has been stealing cryptocurrency wallet recovery phrases through a system of roughly 20 modules. This malware campaign has impacted users in at least five countries, including Brazil, Vietnam, Canada, Mexico, and Turkey.

Mechanism of the Attack

The OkoBot malware utilizes a range of deceptive strategies, including fake recovery screens and keylogging techniques. It is distributed via GitHub repositories, disguised as legitimate software such as Microsoft SQL Server Management Studio. Kaspersky’s investigation revealed that the malware has been active for over a year.

ClickFix Social Engineering Technique

One significant aspect of OkoBot’s attack strategy is its use of the ClickFix social engineering method. Victims are tricked into executing malicious commands on their devices through fake error messages or verification steps, leading them to unknowingly install the malware.

Modules Targeting Crypto Wallets

Among OkoBot’s various modules, SeedHunter is designed to mimic recovery interfaces for hardware wallets such as Ledger and Trezor. When users enter their recovery phrases, this module transmits the data back to the attackers. Additionally, the MC Keylogger captures keyboard input and clipboard activity, potentially compromising various sensitive information.

Another module, known as OkoSpyware, can track wallet passwords and even record visual data of what is displayed on the user’s screen.

Risks and Implications

Once a recovery phrase is compromised, attackers can gain control of the corresponding wallet, making it possible to transfer assets without the victim’s consent. Kaspersky warned that users face a slim chance of recovering stolen cryptocurrency, given the irreversible nature of blockchain transactions.

Wider Threat Landscape

The emergence of OkoBot highlights a growing trend of malware utilizing similar methods to target cryptocurrency sectors. For instance, North Korea’s state-backed Lazarus Group previously implemented a similar strategy in a macOS campaign called “Mach-O Man,” where they used fake meeting invitations to install malware capable of compromising cryptocurrency and corporate information.

As cyber threats continue to evolve, security measures for protecting cryptocurrency assets must become increasingly robust. Developers remain a critical target for such malware, as others like the TrapDoor malware have exploited software packages aimed at those in cryptocurrency and related fields.

Source: crypto.news

BTC / ZAR

Bitcoin · Rank #1

R1,410,078.59

-0.34% 24h

24h High
R1,447,590.00
24h Low
R1,393,588.25
Market Cap
R28.35T
Volume 24H
R1.24T

7-day price

View full BTC market Trade

Powered By