
Kaspersky researchers have exposed OkoBot, a sophisticated malware operation that has been active for over a year and affected users across at least five countries. According to reports from Bits.media, the malware uses approximately 20 modules to systematically steal crypto wallet recovery phrases from victims. Most identified victims were located in Brazil, Vietnam, Canada, Mexico, and Turkey, while the operators blocked IP addresses from Russia and other Commonwealth of Independent States countries.
As reported by Kaspersky, OkoBot is distributed through GitHub repositories and disguised as legitimate software, including Microsoft SQL Server Management Studio. The attackers rely on the ClickFix social engineering method, which tricks victims into running malicious commands on their own devices. The technique often presents users with fake error messages, verification steps, or repair instructions that cause victims to execute code that installs the malware without realizing the command is malicious.
According to Kaspersky's findings, OkoBot employs several specialized modules to maximize data collection. The SeedHunter module displays a fake recovery interface linked to hardware wallets such as Ledger and Trezor, capturing recovery phrases when users enter them into the fraudulent screen. The MC Keylogger module records keyboard input and monitors clipboard activity, capturing passwords, copied wallet addresses, and other credentials. Additionally, OkoSpyware can track wallet passwords and record videos of open windows, providing attackers with comprehensive observation capabilities.
As reported by Kaspersky, once a recovery phrase is exposed, attackers can use it to take control of the associated wallet and move its assets. The security company warned that victims have little chance of recovering stolen cryptocurrency because blockchain transfers are generally irreversible. The malware's modular design allows operators to collect different types of information from a single infected system, targeting both wallet access data and credentials connected to other services used on the device.
According to crypto.news reports, OkoBot represents the latest malware campaign using ClickFix against the cryptocurrency sector. Previous campaigns have included North Korea's state-backed Lazarus Group using similar techniques in a macOS campaign known as 'Mach-O Man' in April. Researchers have also documented TrapDoor malware distributed through poisoned software packages targeting developers in cryptocurrency, decentralized finance, artificial intelligence, and security infrastructure sectors.