Kaspersky researchers identify OkoBot malware targeting crypto wallet seed phrases and credentials

Kaspersky researchers identify OkoBot malware targeting crypto wallet seed phrases and credentials

N
News Editor
2026-07-18 09:52:55
Kaspersky security researchers have identified a new malware strain called OkoBot that is designed to steal cryptocurrency wallet seed phrases and credentials, according to Bits.media. The malware reportedly uses roughly 20 modules and relies on ClickFix social engineering to trick users into running malicious commands on their own devices. Researchers said the campaign is also being distributed through GitHub repositories disguised as legitimate tools, including SQL Server Management Studio. Several modules were highlighted in the report. SeedHunter targets hardware wallets such as Trezor and Ledger by injecting itself into the recovery process and showing a fake interface when users enter seed phrases. MC Keylogger records keyboard input and clipboard activity, while OkoSpyware tracks wallet passwords and captures window video. Kaspersky said that once attackers obtain a victim’s seed phrase, they can take full control of the related crypto assets, leaving little chance of fund recovery. The company added that OkoBot has been active for more than a year. Most victims were located in Brazil, Vietnam, Canada, Mexico, and Turkey. The attackers also geofenced IP addresses from Russia and CIS countries.
KasperskyOkoBotmalwarecrypto walletsseed phrasescybersecurityhardware wallets

Kaspersky security researchers have identified a new malware strain called OkoBot that can steal cryptocurrency wallet seed phrases and credentials through about 20 modules, according to Bits.media.

The attackers use ClickFix social engineering to trick users into executing malicious commands. The malware is also distributed through GitHub repositories disguised as legitimate software tools, including SQL Server Management Studio.

Modules used to steal wallet data

The report highlighted several OkoBot modules aimed at wallet access and user activity:

  • SeedHunter: injects into hardware wallets including Trezor and Ledger and shows a fake interface during seed phrase recovery;
  • MC Keylogger: records keyboard and clipboard activity;
  • OkoSpyware: tracks wallet passwords and records window video.

Kaspersky said that once attackers obtain a seed phrase, they can fully control the victim’s crypto assets, and the funds are often nearly impossible to recover.

Victim distribution and geofencing

According to Kaspersky, OkoBot has existed for more than a year. Most victims are located in Brazil, Vietnam, Canada, Mexico, and Turkey. The attackers also applied geoblocking to IP addresses from Russia and CIS countries.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.