Cybersecurity researchers at Kaspersky have uncovered a sophisticated malware framework, dubbed OkoBot, that is targeting cryptocurrency users by stealing wallet recovery phrases, browser credentials and other sensitive information through a multi-stage attack campaign spanning more than 25 countries.
The researchers said the malware, active since April 2025, employs more than 20 malicious payloads and has evolved into an advanced cybercrime platform focused on compromising digital asset holders. According to Kaspersky’s Global Research and Analysis Team (GReAT), the campaign remains active and has already affected hundreds of users worldwide.
Kaspersky disclosed that one of the framework’s most dangerous components, known as SeedHunter, injects malicious code into legitimate cryptocurrency wallet applications, including Ledger Wallet, Ledger Live and Trezor Suite, before displaying fake recovery phrase prompts designed to trick victims into surrendering their seed phrases.
The security firm explained that once attackers obtain a victim’s recovery phrase, they gain complete control over the cryptocurrency wallet, enabling them to transfer digital assets with virtually no chance of recovery.
Commenting on the discovery, Security Researcher at Kaspersky’s GReAT, Dmitry Galov, said,
“This campaign has been running for more than a year and remains active. OkoBot is not just a single piece of malware but an extensible framework built primarily to compromise cryptocurrency users.”
Galov added that the malware is continuously maintained and enhanced, underscoring the attackers’ long-term focus on financial theft.
According to Kaspersky, victims are typically infected through ClickFix phishing attacks or malicious GitHub repositories masquerading as legitimate software downloads. In one instance, a fake Microsoft SQL Server Management Studio repository secretly installed a trojanized version of the Audacity audio editor embedded with malicious code.
Following the initial compromise, the attackers deploy a PowerShell downloader called TookPS,which establishes an encrypted SSH connection to attacker-controlled infrastructure. The malware then harvests browser cookies, wallet files, stored credentials and system information before downloading additional malicious modules.
Among the additional payloads is OkoSpyware which monitors more than 100 applications, which includes cryptocurrency wallets and password managers—records user activity and captures keystrokes and video of application windows. Another module silently installs malicious browser extensions capable of stealing financial information and authentication tokens.
However, Kaspersky’s telemetry indicates that the largest concentrations of victims have been recorded in Brazil, Vietnam, Canada, Mexico and Türkiye, although the malware campaign has spread to users across more than 25 countries.
The cybersecurity firm advised cryptocurrency users never to enter wallet recovery phrases into prompts displayed by desktop applications or websites unless they have independently verified their authenticity.
Furthermore,It also urged users to download wallet software exclusively from official sources, enable multi-layered endpoint protection, and remain cautious of software offered through unofficial repositories or phishing websites.
Kaspersky noted that while hardware wallets themselves remain secure, attackers are increasingly exploiting the software that accompanies them, making user awareness a critical line of defence against evolving cryptocurrency-focused cyber threats.
We’ve got the edge. Get real-time reports, breaking scoops, and exclusive angles delivered straight to your phone. Don’t settle for stale news. Join LEADERSHIP NEWS on WhatsApp for 24/7 updates →
Join Our WhatsApp Channel




