A malware campaign tracked as OkoBot has been operating for more than a year and targeting cryptocurrency users across at least 25 countries, according to Kaspersky. Researchers say the framework is designed to steal seed phrases, wallet credentials and browser data through a broad set of tools delivered via social engineering and fake software downloads.

How the malware spreads

Kaspersky says OkoBot is distributed through ClickFix-style attacks and bogus software hosted through fake GitHub downloads. The campaign is aimed at luring users into installing malicious files that then deploy a wider framework made up of more than 20 separate modules.

Those modules are used to collect different kinds of sensitive data. According to the report, the malware can harvest wallet credentials and browser information while also monitoring user activity on infected systems.

Seed phrase theft as a central tactic

One of the most significant components identified by researchers is a module called SeedHunter. Kaspersky says it swaps out legitimate recovery interfaces for Ledger and Trezor wallets with phishing pages designed to capture seed phrases.

If a recovery phrase is stolen, attackers can gain full access to the associated crypto assets. Researchers said hundreds of users have been targeted through the campaign, with the highest numbers of victims reported in Brazil, Vietnam, Canada, Mexico and Türkiye.

Broader surveillance features

Beyond wallet-focused theft, OkoBot includes spyware-style functions intended to gather a wider range of information from victims’ devices. Kaspersky says the framework includes keylogging, screen capture tools and browser extension injection techniques that can be used to steal credentials and other sensitive data.

The report describes OkoBot as a modular operation that is still evolving. Researchers said the campaign remains under active development, suggesting its operators are continuing to refine or expand its capabilities.

Attribution remains unclear

Kaspersky said it has not linked the campaign to a specific threat group. However, researchers noted that some of the methods used in OkoBot resemble techniques associated with Russian-speaking threat actors.

The company advised users to obtain software only from trusted sources, keep security software enabled, store seed phrases in dedicated password managers and use multi-factor authentication where possible.

The findings add to continuing concerns around malware tailored to cryptocurrency users, particularly campaigns that target recovery phrases and wallet access rather than only exchange logins or payment data. In this case, Kaspersky’s warning points to a long-running operation with global reach, a specialized focus on Ledger and Trezor recovery flows, and an attribution picture that remains unsettled.

Source: Coin Edition