• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
EU Russia sanctions

Russian billionaires shift billions into crypto, gold amid capital flight

07/20/2026
Criminal Procedure Act

South Korea proposes new warrant rules for seizing self-custodied crypto

07/20/2026
AZ-COM Maruwa to pay 2,300 contractors in JPYC stablecoin

AZ-COM Maruwa to pay 2,300 contractors in JPYC stablecoin

07/20/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
EU Russia sanctions

Russian billionaires shift billions into crypto, gold amid capital flight

07/20/2026
Criminal Procedure Act

South Korea proposes new warrant rules for seizing self-custodied crypto

07/20/2026
AZ-COM Maruwa to pay 2,300 contractors in JPYC stablecoin

AZ-COM Maruwa to pay 2,300 contractors in JPYC stablecoin

07/20/2026
Tuesday, July 21, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

Kaspersky exposes OkoBot, a 20-module malware framework draining crypto wallets via GitHub

OkoBot has emerged as one of the most dangerous crypto malware campaigns after Kaspersky exposed its sophisticated 20-module attack targeting crypto wallets

by Davidson Okechukwu
18 hours ago
in Crypto News
Reading Time: 4 mins read
0
Google report reveals rise of AI powered malwares

Five malware families now exploit AI models like Gemini to evade detection, Google says

Share on FacebookShare on Twitter

Kaspersky’s Global Research and Analysis Team has exposed OkoBot, a modular malware framework that has quietly targeted crypto wallet holders for more than a year, compromising hundreds of victims across at least 25 countries including Brazil, Vietnam, Canada, Mexico, and Türkiye.

The discovery highlights how OkoBot has evolved into a highly organized cybercrime operation.

Unlike conventional malware that relies on a single payload, OkoBot employs a modular architecture that enables attackers to steal different categories of sensitive information from infected systems while continuously adapting to evade detection.

OkoBot uses clever clickFix trick to fool crypto users

According to findings published by Kaspersky and reported by Bits.media, OkoBot spreads primarily through GitHub repositories where it masquerades as trusted software, including fake versions of Microsoft SQL Server Management Studio.

Rather than exploiting software vulnerabilities, OkoBot depends heavily on the increasingly popular ClickFix social engineering technique.

Victims are presented with convincing fake error messages, verification prompts, or troubleshooting instructions that encourage them to manually execute malicious commands on their own computers.

“Social engineering remains one of the most effective attack vectors because it exploits human trust rather than software flaws,” Kaspersky researchers explained in their report.

Once users unknowingly execute the malicious command, OkoBot installs silently and immediately begins harvesting valuable information.

Researchers identified victims primarily in Brazil, Vietnam, Canada, Mexico, and Turkey. Interestingly, the malware operators intentionally blocked IP addresses originating from Russia and several Commonwealth of Independent States (CIS) countries, suggesting a deliberate geographical targeting strategy.

OkoBot specifically targets crypto wallet recovery phrases

One of OkoBot’s most dangerous capabilities is a module known as SeedHunter.

The module presents users with convincing fake recovery interfaces resembling those used by popular hardware wallet manufacturers including Ledger and Trezor.

Once victims enter their recovery phrases, the information is immediately transmitted to attackers.

Possession of a wallet’s recovery phrase effectively grants complete ownership of the wallet itself.

Kaspersky warned that once attackers obtain these seed phrases, victims typically have virtually no way to recover stolen digital assets because cryptocurrency transactions are irreversible on blockchain networks.

As Ledger repeatedly advises users:

“Never share your 24-word recovery phrase with anyone. Ledger will never ask for it.”

That warning has become even more relevant as campaigns like OkoBot continue to grow.

OkoBot deploys multiple modules to capture every credential

Beyond SeedHunter, OkoBot deploys several additional modules that significantly increase its effectiveness.

The MC Keylogger continuously records keyboard activity while monitoring clipboard contents, allowing attackers to capture passwords, copied wallet addresses, authentication credentials, and sensitive login information.

Meanwhile, OkoSpyware records videos of active windows and monitors wallet passwords entered during normal user activity.

The modular design allows OkoBot operators to customize infections depending on their objectives, making the malware both flexible and difficult to detect.

Kaspersky researchers noted that the malware can simultaneously target cryptocurrency wallets alongside credentials linked to cloud services, email accounts, development environments, and other digital assets stored on infected devices.

Growing crypto malware trend raises fresh security concerns

The emergence of OkoBot reflects a broader evolution in cybercrime targeting cryptocurrency users.

Earlier this year, cybersecurity company CertiK revealed that North Korea’s Lazarus Group employed the ClickFix technique in its “Mach-O Man” malware campaign aimed at cryptocurrency firms and fintech executives.

According to CertiK researchers:

“The campaign relied heavily on social engineering rather than exploiting software vulnerabilities.”

Victims received fake online meeting invitations and were instructed to paste malicious commands into the macOS Terminal, ultimately installing malware capable of stealing cryptocurrency and sensitive corporate information.

Security researchers also uncovered the TrapDoor malware campaign in May, which targeted developers working in cryptocurrency, decentralized finance (DeFi), artificial intelligence, and security infrastructure.

TrapDoor sought valuable assets including wallet credentials, cloud secrets, API keys, SSH credentials, and authentication tokens associated with platforms such as Coinbase, Binance, MetaMask, Brave, Solana, Sui, and Aptos.

OkoBot demonstrates why seed phrase protection matters more than ever

Cybersecurity experts believe OkoBot represents another warning that attackers are shifting toward highly convincing psychological manipulation instead of relying solely on technical exploits.

“The biggest vulnerability isn’t always the software—it’s the human behind the keyboard,” security professionals have repeatedly emphasized when discussing modern phishing campaigns.

For crypto investors, protecting recovery phrases remains the single most effective defense.

Users should never enter seed phrases outside official wallet recovery procedures, avoid downloading software from unverified GitHub repositories, enable multi-factor authentication wherever possible, and verify every command before executing it on their systems.

As cryptocurrency adoption continues expanding worldwide, campaigns like OkoBot illustrate how cybercriminals are becoming increasingly sophisticated.

Kaspersky’s latest findings serve as a timely reminder that maintaining strong cybersecurity habits may be the difference between protecting digital wealth and losing it permanently.

Tags: ClickFix attackCrypto malwareCrypto wallet securityCryptocurrencycybersecurityKasperskyLedger WalletOkoBotseed phrase theftTrezor Wallet
Share198Tweet124
Davidson Okechukwu

Davidson Okechukwu

Davidson Okechukwu is a passionate crypto journalist/writer and Web3 enthusiast, focusing on blockchain innovation, deFI, NFT ecosystems, and the societal impact of decentralized systems. His engaging style bridges the gap between technology and everyday understanding with a degree in Computer Science and various professional certifications from prestigious institutions. With over four years of experience in the crypto and DeFi space, Davidson combines his technical knowledge with a keen understanding of market dynamics. In addition to his work in cryptocurrency, he is a dedicated realtor and web management professional.

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
AI People joins Dubai’s innovation one — Declares war on the forgetting of humanity

AI People joins Dubai’s Innovation One program: Declares war on the forgetting of humanity

07/22/2025 - Updated on 07/23/2025
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
EU Russia sanctions

Russian billionaires shift billions into crypto, gold amid capital flight

07/20/2026
Criminal Procedure Act

South Korea proposes new warrant rules for seizing self-custodied crypto

07/20/2026
AZ-COM Maruwa to pay 2,300 contractors in JPYC stablecoin

AZ-COM Maruwa to pay 2,300 contractors in JPYC stablecoin

07/20/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.