Kaspersky reported that a malware campaign named OkoBot, active for more than a year, uses roughly 20 modules to steal cryptocurrency wallet recovery phrases and has compromised...
Kaspersky reported that a malware campaign named OkoBot, active for more than a year, uses roughly 20 modules to steal cryptocurrency wallet recovery phrases and has compromised users in Brazil, Vietnam, Canada, Mexico and Turkey. The software distributes through GitHub repositories, disguising itself as legitimate tools such as Microsoft SQL Server Management Studio. OkoBot leverages the ClickFix social‑engineering method, presenting victims with fake error messages or repair instructions that prompt them to execute malicious commands, thereby installing the malware without their knowledge. Modules include SeedHunter, which displays a fake wallet interface for Ledger and Trezor devices, MC Keylogger, which records keystrokes and clipboard activity, and OkoSpyware, which monitors screen content. The report published by Bits.media indicated that the operators block IP addresses from Russia and other Commonwealth of Independent States countries. Kaspersky warned that once a recovery phrase is exposed, blockchain transactions are generally irreversible, leaving victims with limited prospects of recovering lost funds.
- Publisher
- cryptonews
- Reliability
- high
- Published
- 7/19/2026, 10:00:35 AM
- Retrieved
- 7/19/2026, 10:00:35 AM
- Relevance
- 80%
- Confidence
- 85%

