Kaspersky uncovers OkoBot framework stealing crypto wallet seed phrases
Kaspersky's Global Research and Analysis Team (GReAT) has published research detailing OkoBot, a previously unknown malware framework built to target cryptocurrency users. Active since at least January 2026 and still ongoing as of July 2026, the campaign has reached hundreds of victims across more than 25 countries, with the highest concentrations in Brazil, Vietnam, Canada, Mexico and Türkiye.
The framework comprises more than 20 individual payloads and implants, giving operators a broad toolkit: local file collection, remote command execution, browser extension injection, video capture, credential harvesting and cryptocurrency wallet theft. A dedicated component called SeedHunter monitors running processes and injects code into Trezor Suite, Ledger Wallet and Ledger Live applications. When it detects a connected hardware wallet, it overlays a hard-coded phishing page designed to capture the user's seed phrase, with a bespoke layout for each wallet type.
How the infection spreads
Initial compromise arrives through two primary vectors. The first is ClickFix, a social-engineering technique in which attackers instruct targets to run malicious code themselves, typically via fake help guides or copy-paste prompts. The second involves trojanised software distributed through GitHub, including a counterfeit installer for SQL Server Management Studio (SSMS). The targeting of developer tooling is deliberate: Kaspersky researchers note that software developers appear to be among the primary intended victims, likely because they manage both technical infrastructure and significant cryptocurrency holdings.
A loader component modifies browser memory to install and conceal malicious extensions in Chromium-based browsers. A separate OkoSpyware module captures keystrokes and records the video stream of targeted application windows, supplementing the Rilide information stealer that is deployed as a secondary payload via the TookPS component.
Attribution remains uncertain. Kaspersky states that the techniques and infostealer tooling are consistent with Russian-speaking threat actors, and code artefacts in Russian were identified during analysis, but the company does not attribute the campaign to a named group with high confidence.
"The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026," said Dmitry Galov, head of Kaspersky GReAT's Russia and CIS unit. "Of particular concern is the malware's continued evolution, which indicates that the framework is being actively maintained."
Market and threat landscape context
OkoBot sits within a crowded but increasingly sophisticated category of crypto-targeting malware. Seed-phrase theft via hardware-wallet overlay attacks has grown sharply alongside the adoption of self-custody devices; earlier campaigns such as those targeting Ledger users through malicious browser extensions established the template that OkoBot appears to refine and extend. The use of GitHub as a distribution channel is also a recurring pattern across multiple threat actor groups, exploiting the implicit trust that developers place in code repositories.
From a regulatory standpoint, the EU's Markets in Crypto-Assets (MiCA) regulation, which entered full application in late 2024, imposes security obligations on crypto-asset service providers but does not extend to self-custody wallet software or the open-source tooling ecosystems that campaigns like OkoBot exploit. Broader NIS2 obligations may apply to exchanges or custodians that are upstream of affected users, though individual cryptocurrency holders remain outside formal regulatory protection frameworks.
Kaspersky recommends that users avoid executing code from unverified sources, keep operating systems and applications current, use dedicated password managers rather than photo galleries or notes applications to store recovery phrases, and enable multi-factor authentication wherever supported. The company says the campaign retains the capacity to expand into additional countries as distribution efforts continue.