> Back to All Posts

OkoBot Malware Deploys 20 Payloads to Steal Crypto

OkoBot Malware

A newly identified threat called OkoBot malware is hitting victims with more than 20 separate payloads designed to drain cryptocurrency wallets and steal sensitive data. Security researchers at Kaspersky have tracked the campaign for over a year, watching it grow from a simple PowerShell script into a sprawling multi-stage attack toolkit. The scale of this operation makes it one of the more sophisticated crypto-theft frameworks currently in circulation.

Attackers behind OkoBot malware are not relying on a single trick to reach victims. Instead, they use two main delivery methods, both built on trust and disguise.

How OkoBot Malware Spreads

The first method involves ClickFix attacks, where victims are tricked into copying and running a malicious command themselves, often after seeing a fake error message or verification prompt. This social engineering approach works because it puts the victim in control of the final step, which makes the action feel legitimate.

The second method relies on fake GitHub repositories. Attackers upload projects that claim to be legitimate software tools, but the code inside tells a different story. In one documented case, a repository advertised as SQL Server Management Studio actually delivered a trojanized version of the Audacity audio editor instead.

Because developers and IT professionals frequently pull tools directly from GitHub, this approach can bypass the skepticism that a random email attachment might trigger. The malicious repository looks like any other open-source project, so victims download and run it without a second thought.

Inside the Infection Chain

Once a victim executes the malicious payload, an earlier tool called TookPS handles the first stage of infection. TookPS installs and configures an SSH bot on the compromised machine, and that bot becomes the backbone of the entire OkoBot malware operation.

The SSH bot gathers basic system information first, including the username, installed antivirus software, IP address, and operating system version. It then disables Windows Defender notifications so the victim receives no warning as additional malicious components arrive. After that, it begins pulling down the rest of the OkoBot malware toolkit, piece by piece.

This staged approach gives attackers flexibility. They can adjust which modules get deployed based on what the SSH bot finds on each individual machine, so a victim running a popular wallet app might receive different payloads than someone without one installed.

The Most Dangerous Payloads

Among the 20-plus modules attackers use, a handful stand out for how directly they target financial assets. A module known as ext daemon/extl.exe injects itself into Chrome browsers, silently installing hidden extensions like Rilide. That extension then harvests credentials, cookies, and financial data without the victim noticing anything unusual in their browser.

A separate module called SeedHunter goes after hardware wallets directly. It injects into Trezor Suite, Ledger Wallet, and Ledger Live, then displays a fake seed-recovery screen that tricks victims into typing in their wallet recovery phrase. Because that phrase grants full access to a wallet’s contents, handing it over means attackers can drain the funds instantly, and recovery is nearly impossible once the transfer happens.

Two other modules round out the most damaging tools in the OkoBot malware arsenal. MC Keylogger records every keystroke and clipboard action, including copied text, images, and file paths, while also watching for USB connections and capturing screenshots every five minutes. OkoSpyware, meanwhile, monitors roughly 100 different programs, including wallets and password managers, and uses the FFmpeg tool to record video of those windows in action.

Who Is Behind the Campaign

Kaspersky has not formally attributed OkoBot malware to a specific threat actor, but several clues point toward a Russian-speaking group. The servers hosting the initial PowerShell scripts geoblock traffic from Russia and the Commonwealth of Independent States, returning empty responses to any request from those regions.

Researchers also found Russian-language comments inside the SeedHunter module’s source code. On top of that, one of the infostealers used in the campaign gets actively promoted on invitation-only Russian cybercrime forums, adding further weight to the theory.

Victim data shows Brazil as the hardest-hit country so far, followed by Vietnam, Canada, Mexico, and Turkey. However, the campaign’s infrastructure appears built for global reach rather than a specific regional focus.

Protecting Yourself From OkoBot Malware

Avoiding OkoBot malware starts with basic caution around where software comes from. Downloading tools only from official sources, rather than third-party GitHub repositories with unclear ownership, removes one of the two main infection paths entirely. Because ClickFix attacks depend on victims running commands themselves, never copy and paste terminal commands from a website or pop-up unless you fully understand what they do.

Hardware wallet users should also stay alert to any unexpected recovery-phrase prompts. Legitimate wallet software never asks for a seed phrase outside of the initial setup process, so any screen requesting it later is a red flag. Combining that vigilance with a reputable antivirus tool and a VPN that blocks known malicious domains adds another layer of protection against the initial payload delivery.

Keeping software updated and avoiding pirated or “cracked” tools also reduces exposure, since many of these campaigns rely on victims seeking free versions of paid software.

Final Thoughts

OkoBot malware shows how far crypto-focused attackers have come, building a modular framework with more than 20 specialized tools instead of relying on a single piece of malware. The combination of fake GitHub repositories and ClickFix tactics gives attackers multiple ways into a victim’s system, and the SeedHunter module’s fake recovery screen represents a particularly effective way to drain hardware wallets. Staying cautious about software sources, verifying prompts before entering sensitive information, and pairing good habits with strong security tools remain the best defense against this kind of evolving threat.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.