Kaspersky GReAT Unveils OkoBot Malware Framework: Specifically Designed to Steal Cryptocurrency Wallet Mnemonics, Browser Cookies, and More
Coin Circle (120btc.CoM): Kaspersky's Global Research and Analysis Team (GReAT) has unveiled a malware framework named OkoBot. This framework comprises over 20 types of malicious programs and implants that operate collaboratively through SSH tunnels, specifically designed to steal mnemonics from cryptocurrency wallets, browser cookies, and account passwords, having infiltrated hundreds of users across 25 countries worldwide.
OkoBot Framework: 20 Types of Malware Collaborating
OkoBot is not a single piece of malware but a complete modular attack framework. Kaspersky detailed the entire infection chain in a Securelist technical report: TookPS downloader is responsible for the initial intrusion → SSHbot collects system information and establishes a reverse tunnel → HDUtil launcher deploys various malicious modules → ultimately sending stolen data back via SFTP.
The framework includes five main plugins:
- CMD Wrapper (10xx): Executes command codes and individual instructions within the system
- PowerShell Wrapper (11xx): Supports execution of PowerShell command codes
- Environment Enumerator (12xx): Collects system information, active sessions, and processes
- Downloader (14xx): Downloads additional payloads from embedded Base64 binary blobs or URLs
- Process Injector (16xx): Injects malicious implants into normal processes
SeedHunter: Stealing Ledger and Trezor Mnemonics
One of the core modules, SeedHunter, monitors active processes in the system and injects implants into applications like Trezor Suite, Ledger Wallet, and Ledger Live. When a connected hardware wallet is detected, SeedHunter displays a hardcoded phishing page requesting the user to input their mnemonic. This page uses different layouts for each wallet type, and the stolen mnemonics are subsequently sent back to the C2 server encrypted with RC4.
Kaspersky specifically pointed out in its official press release that the infection routes for OkoBot mainly include ClickFix click fraud and disguised software distributed via GitHub. Researchers identified cases of fake SQL Server Management Studio installers that were actually embedded with malicious implants in the Audacity audio editor.
OkoSpyware: Simultaneously Recording Keystrokes and Screens
The newly added OkoSpyware module captures both keyboard inputs and video streams of target application windows. It lists over 100 executable names, including cryptocurrency wallets like Exodus and Litecoin QT, password managers like KeePassXC and 1Password, as well as various commonly used applications. For each identified process, OkoSpyware uses a built-in FFmpeg instance to record MP4 videos while simultaneously logging keystrokes.
Browsers are not exempt; when OkoSpyware detects the window title of wallet extension pages like MetaMask or Tonkeeper, it automatically starts recording video and input, writing the window title into a JSON relay data file.
Active for Over a Year, Developers as Primary Target
The infection chain of OkoBot has been operational since April 2025, continuing for over a year and still evolving. Kaspersky researchers noted that the countries most affected by attacks include Brazil, Vietnam, Canada, Mexico, and Turkey. While it is currently impossible to attribute the attacks to a specific criminal group, technical analysis has revealed traces of Russian-language code, and the espionage program used by the malware (Rilide) is widely circulated on Russian-language cybercrime forums.
Kaspersky warned in the report that the ongoing evolution of the OkoBot framework indicates that the backend maintainers are still actively developing it. As distribution activities continue, the framework has the potential to impact more cryptocurrency users and developers.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Grayscale Files for Spot ETF Conversion for Litecoin on NYSE Arca

Criminal Case Initiated in Voronezh for Legalizing Drug Trafficking Profits via Cryptocurrency

Grayscale Highlights Zcash Among 4 Key Cryptocurrencies

ONDO Tokenized Smart-Portfolio Narrative Builds| WEEX TradFi Daily Brief (September 25, 2026)
Global markets on the morning of September 25 Beijing time focus on rate pricing and a split in AI infrastructure. On September 24 ET the S&P 500 was near 7,704 and almost unchanged, the Nasdaq edged higher and the Dow fell 0.31%. The 10-year yield rose to about 5.18% and the 30-year to about 5.47%. Bitcoin last traded around $84,400.

WEEX Exclusive:ONDO Tokenized Smart-Portfolio Narrative Builds| WEEX TradFi Daily Brief (September 25, 2026)

Binance Research Team: A Bull Market Requires the Resonance of Monetary Easing and Paradigm Innovation, with RWA as a Key Driving Force

Grayscale to Convert $82.3 Million Litecoin Trust into ETF

Luxxfolio Holdings Increases Miner Fleet by 380%

Luxxfolio Invests in 228 Bitmain Scrypt Miners to Expand Litecoin Mining Operations

Lite Strategy repurchases 4.9 million shares using Litecoin sales

Cryptocurrency Mining in Moscow and Several Regions of Russia to Be Banned Until 2032

The disclosure of a zero-day vulnerability in Litecoin triggered DoS attacks and abnormal MWEB transactions, which were fixed after a block reorganization

The “20 Million Bandit” and “Shanzhai Air Force Leader” Bearish on LTC with Massive Short Positions
Key Takeaways Notable crypto entities, the “20 Million Bandit” and “Shanzhai Air Force Leader”, have significantly increased their…

Lite Strategy, a Litecoin-focused financial services company, has approved a $25 million stock buyback plan.

Which was the best-performing sector in the last two months of this year? Should we HODL or take profits now?

Bitwise Solana Staking ETF "BSOL" Achieves $56 Million in Trading Volume on First Day of Listing

Bloomberg: New Cryptocurrency ETF Debuts in U.S. Amid SEC Halt

Litecoin Reserve Company MEI Pharma Renamed to Litecoin Strategy

Litecoin Treasury Company MEI Pharma Announces Rebranding to Lite Strategy

Grayscale has filed the S-1 for the Hedera ETF and the S-3 for the Litecoin ETF.

Morning Report | Strategy invested $1.57 billion last week to increase its holdings by 22,337 bitcoins; Abra plans to go public through a SPAC merger; Metaplanet aims to raise approximately $765 million to increase its bitcoin holdings

T. Rowe Price submits a second amendment for its actively managed cryptocurrency ETF

CertiK: DeFi Protocol Whale Steals $282 Million; Hacker Bridges About $63 Million to New Address

How to Buy Crypto with a Credit Card Without Verification
In the ever-evolving world of cryptocurrency, one of the growing trends is purchasing digital assets effortlessly while maintaining…
Grayscale Files for Spot ETF Conversion for Litecoin on NYSE Arca
Criminal Case Initiated in Voronezh for Legalizing Drug Trafficking Profits via Cryptocurrency
Grayscale Highlights Zcash Among 4 Key Cryptocurrencies
ONDO Tokenized Smart-Portfolio Narrative Builds| WEEX TradFi Daily Brief (September 25, 2026)
Global markets on the morning of September 25 Beijing time focus on rate pricing and a split in AI infrastructure. On September 24 ET the S&P 500 was near 7,704 and almost unchanged, the Nasdaq edged higher and the Dow fell 0.31%. The 10-year yield rose to about 5.18% and the 30-year to about 5.47%. Bitcoin last traded around $84,400.



