Kaspersky’s Global Research and Analysis Team has exposed OkoBot, a modular malware framework that has quietly targeted crypto wallet holders for more than a year, compromising hundreds of victims across at least 25 countries including Brazil, Vietnam, Canada, Mexico, and Türkiye.
The discovery highlights how OkoBot has evolved into a highly organized cybercrime operation.
Unlike conventional malware that relies on a single payload, OkoBot employs a modular architecture that enables attackers to steal different categories of sensitive information from infected systems while continuously adapting to evade detection.
OkoBot uses clever clickFix trick to fool crypto users
According to findings published by Kaspersky and reported by Bits.media, OkoBot spreads primarily through GitHub repositories where it masquerades as trusted software, including fake versions of Microsoft SQL Server Management Studio.
Rather than exploiting software vulnerabilities, OkoBot depends heavily on the increasingly popular ClickFix social engineering technique.
Victims are presented with convincing fake error messages, verification prompts, or troubleshooting instructions that encourage them to manually execute malicious commands on their own computers.
“Social engineering remains one of the most effective attack vectors because it exploits human trust rather than software flaws,” Kaspersky researchers explained in their report.
Once users unknowingly execute the malicious command, OkoBot installs silently and immediately begins harvesting valuable information.
Researchers identified victims primarily in Brazil, Vietnam, Canada, Mexico, and Turkey. Interestingly, the malware operators intentionally blocked IP addresses originating from Russia and several Commonwealth of Independent States (CIS) countries, suggesting a deliberate geographical targeting strategy.
OkoBot specifically targets crypto wallet recovery phrases
One of OkoBot’s most dangerous capabilities is a module known as SeedHunter.
The module presents users with convincing fake recovery interfaces resembling those used by popular hardware wallet manufacturers including Ledger and Trezor.
Once victims enter their recovery phrases, the information is immediately transmitted to attackers.
Possession of a wallet’s recovery phrase effectively grants complete ownership of the wallet itself.
Kaspersky warned that once attackers obtain these seed phrases, victims typically have virtually no way to recover stolen digital assets because cryptocurrency transactions are irreversible on blockchain networks.
As Ledger repeatedly advises users:
“Never share your 24-word recovery phrase with anyone. Ledger will never ask for it.”
That warning has become even more relevant as campaigns like OkoBot continue to grow.
OkoBot deploys multiple modules to capture every credential
Beyond SeedHunter, OkoBot deploys several additional modules that significantly increase its effectiveness.
The MC Keylogger continuously records keyboard activity while monitoring clipboard contents, allowing attackers to capture passwords, copied wallet addresses, authentication credentials, and sensitive login information.
Meanwhile, OkoSpyware records videos of active windows and monitors wallet passwords entered during normal user activity.
The modular design allows OkoBot operators to customize infections depending on their objectives, making the malware both flexible and difficult to detect.
Kaspersky researchers noted that the malware can simultaneously target cryptocurrency wallets alongside credentials linked to cloud services, email accounts, development environments, and other digital assets stored on infected devices.
Growing crypto malware trend raises fresh security concerns
The emergence of OkoBot reflects a broader evolution in cybercrime targeting cryptocurrency users.
Earlier this year, cybersecurity company CertiK revealed that North Korea’s Lazarus Group employed the ClickFix technique in its “Mach-O Man” malware campaign aimed at cryptocurrency firms and fintech executives.
According to CertiK researchers:
“The campaign relied heavily on social engineering rather than exploiting software vulnerabilities.”
Victims received fake online meeting invitations and were instructed to paste malicious commands into the macOS Terminal, ultimately installing malware capable of stealing cryptocurrency and sensitive corporate information.
Security researchers also uncovered the TrapDoor malware campaign in May, which targeted developers working in cryptocurrency, decentralized finance (DeFi), artificial intelligence, and security infrastructure.
TrapDoor sought valuable assets including wallet credentials, cloud secrets, API keys, SSH credentials, and authentication tokens associated with platforms such as Coinbase, Binance, MetaMask, Brave, Solana, Sui, and Aptos.
OkoBot demonstrates why seed phrase protection matters more than ever
Cybersecurity experts believe OkoBot represents another warning that attackers are shifting toward highly convincing psychological manipulation instead of relying solely on technical exploits.
“The biggest vulnerability isn’t always the software—it’s the human behind the keyboard,” security professionals have repeatedly emphasized when discussing modern phishing campaigns.
For crypto investors, protecting recovery phrases remains the single most effective defense.
Users should never enter seed phrases outside official wallet recovery procedures, avoid downloading software from unverified GitHub repositories, enable multi-factor authentication wherever possible, and verify every command before executing it on their systems.
As cryptocurrency adoption continues expanding worldwide, campaigns like OkoBot illustrate how cybercriminals are becoming increasingly sophisticated.
Kaspersky’s latest findings serve as a timely reminder that maintaining strong cybersecurity habits may be the difference between protecting digital wealth and losing it permanently.