Security researchers at Kaspersky have identified a sophisticated new malware strain dubbed OkoBot, which specifically targets cryptocurrency users across multiple jurisdictions. The malicious software is designed to exfiltrate sensitive data, including wallet seed phrases and login credentials, posing a significant threat to digital asset security. By leveraging advanced social engineering tactics and a modular architecture, the attackers have successfully compromised numerous systems worldwide.
ClickFix Tactics and Distribution Methods
The primary distribution vector for OkoBot involves the exploitation of GitHub repositories, where attackers disguise the malware as legitimate professional software. Recent reports indicate that the virus has been found embedded in files masquerading as SQL Server Management Studio and other popular developer tools.
To infect targets, the hackers employ a social engineering technique known as ClickFix. This method tricks users into manually executing malicious commands on their operating systems by presenting fake error messages or technical prompts. This approach bypasses traditional automated security warnings by convincing the user that the action is necessary for the software to function correctly.
Modular Structure and the SeedHunter Component
OkoBot is distinguished by its complex framework, consisting of approximately 20 distinct modules that perform various malicious tasks. This modularity allows the operators to update specific functions without redeploying the entire package. One of the most critical components identified by researchers is SeedHunter, a module specifically engineered to scan infected devices for mnemonic phrases.
- Identification of mnemonic seeds (12-24 words) used to recover private keys.
- Theft of browser-stored credentials and cookies to hijack exchange accounts.
- Monitoring of system processes to intercept data related to blockchain wallets.
- Automated exfiltration of stolen data to remote command-and-control servers.
Global Impact and Mitigation
While the exact number of victims remains under investigation, Kaspersky reports that users in multiple countries have already been affected. The malware targets various ecosystems, potentially putting assets on the Ethereum, Bitcoin, and Solana blockchains at risk if the corresponding seed phrases are stored in plain text or unencrypted files on the victim's hardware.
Attackers use ClickFix social engineering techniques to trick users into running malicious commands and spread it through GitHub repositories disguised as legitimate tools.
To mitigate the risk of infection, experts recommend that cryptocurrency holders avoid storing seed phrases in digital formats and verify the integrity of software downloaded from open-source platforms. As of July 2026, the OkoBot campaign remains active, highlighting the ongoing necessity for hardware-based security solutions and cold storage for significant digital asset holdings.
Frequently Asked Questions
Quick answers to the most common questions about this topic.