New OkoBot Malware Framework Targets Cryptocurrency Users with Advanced Theft Tactics
A sophisticated malware framework, OkoBot, has emerged as a major threat to cryptocurrency users, employing a multi-stage attack chain to steal recovery phrases, credentials, and wallet data. First observed in January 2026, the campaign builds on the TookPS downloader, which has been active since March 2025.
OkoBot operates as a modular platform with over 202,020 payloads, allowing attackers to deploy capabilities remotely via SSH infrastructure. Initial infections occur through ClickFix social-engineering attacks and trojanized applications hosted on GitHub, including a fake Microsoft SQL Server Management Studio (SSMS) repository that delivered a malicious Audacity installer.
Once executed, TookPS installs an SSH service, establishes a tunnel to attacker-controlled servers, and conducts system reconnaissance identifying security software, harvesting browser data, and preparing for deeper compromise. The malware also enables remote desktop (RDP) access by modifying firewall rules, creating backdoor user accounts, and patching termsrv.dll to allow concurrent sessions.
A key component, HDUtil, bypasses User Account Control (UAC) using Windows RPC and msconfig.exe, while SeedHunter targets Ledger Live, Ledger Wallet, and Trezor Suite by injecting fake recovery prompts. When a victim enters their seed phrase, it is exfiltrated to moonsand[.]store and stored locally in an RC4-encrypted file.
Additional plugins include:
- MC Keylogger – Logs clipboard data, USB devices, and screenshots.
- OkoSpyware – Records keystrokes and video streams from wallet apps and password managers.
Kaspersky researchers detected hundreds of victims across 25+ countries, with the highest concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye. While attribution remains unclear, Russian-language artifacts, Rilide stealer usage, and CIS geoblocking suggest ties to Russian-speaking cybercrime groups.
The malware’s ability to bypass security controls, maintain persistence, and exfiltrate sensitive data makes it a significant risk for cryptocurrency holders and organizations.
Source: https://gbhackers.com/okobot-malware-uses-clickfix/
Ledger cybersecurity rating report: https://www.rankiteo.com/company/ledgerhq
GitHub cybersecurity rating report: https://www.rankiteo.com/company/github
Microsoft Security cybersecurity rating report: https://www.rankiteo.com/company/microsoft-security
Audacity Team cybersecurity rating report: https://www.rankiteo.com/company/audacity-team
Trezor cybersecurity rating report: https://www.rankiteo.com/company/trezor
"id": "LEDGITMICAUDTRE1784125944",
"linkid": "ledgerhq, github, microsoft-security, audacity-team, trezor",
"type": "Cyber Attack",
"date": "1/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Hundreds',
'industry': 'Cryptocurrency',
'location': ['Brazil',
'Vietnam',
'Canada',
'Mexico',
'Türkiye'],
'type': 'Individuals'}],
'attack_vector': ['ClickFix social-engineering attacks',
'Trojanized applications (GitHub)',
'Fake Microsoft SQL Server Management Studio (SSMS) '
'repository'],
'data_breach': {'data_encryption': 'RC4-encrypted files (local storage)',
'data_exfiltration': 'Yes (to moonsand[.]store)',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Recovery phrases',
'Credentials',
'Wallet data',
'Browser data',
'Personally identifiable '
'information']},
'date_detected': '2026-01',
'description': 'A sophisticated malware framework, OkoBot, has emerged as a '
'major threat to cryptocurrency users, employing a multi-stage '
'attack chain to steal recovery phrases, credentials, and '
'wallet data. The campaign builds on the TookPS downloader and '
'operates as a modular platform with over 202,020 payloads, '
'allowing attackers to deploy capabilities remotely via SSH '
'infrastructure.',
'impact': {'data_compromised': ['Recovery phrases',
'Credentials',
'Wallet data',
'Browser data',
'Keystrokes',
'Video streams',
'Clipboard data',
'USB device data',
'Screenshots'],
'identity_theft_risk': 'High',
'payment_information_risk': 'High',
'systems_affected': ['Cryptocurrency wallet applications (Ledger '
'Live, Ledger Wallet, Trezor Suite)',
'Password managers']},
'initial_access_broker': {'backdoors_established': 'SSH service, RDP access, '
'firewall rule '
'modifications, backdoor '
'user accounts',
'entry_point': ['ClickFix social-engineering '
'attacks',
'Trojanized applications'],
'high_value_targets': 'Cryptocurrency wallet '
'applications, password '
'managers'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain',
'post_incident_analysis': {'root_causes': ['Lack of user awareness (social '
'engineering)',
'Use of trojanized applications',
'Insufficient security controls '
'for wallet applications']},
'references': [{'source': 'Kaspersky'}],
'response': {'third_party_assistance': 'Kaspersky researchers'},
'threat_actor': 'Russian-speaking cybercrime groups (suspected)',
'title': 'New OkoBot Malware Framework Targets Cryptocurrency Users with '
'Advanced Theft Tactics',
'type': 'Malware'}