A malware framework called OkoBot is being used to steal passwords, browser cookies, cryptocurrency wallet files, and wallet recovery phrases from victims worldwide. Kaspersky says the campaign evolved from the TookPS activity seen since March 2025 and now uses multi-stage delivery through ClickFix social-engineering lures and trojanized GitHub repositories, including fake software offerings. More than 20 payloads are involved, including modules that inject into Chrome, Trezor Suite, Ledger Wallet, and Ledger Live, install malicious extensions, log keystrokes, and record activity in crypto wallets and password managers.
Why it matters: This can directly lead to drained crypto wallets and stolen accounts, and recovery may be impossible if seed phrases are captured. Organizations and users should avoid running code from untrusted GitHub repositories, treat ClickFix-style prompts as hostile, and hunt for the published indicators of compromise.
Bill Toulas
2026.07.16
100% relevant
This article establishes a distinct malware campaign centered on the OkoBot framework, with its own delivery chain, payload set, and crypto-focused theft methods rather than a previously tracked event.
← Back to all stories