logo

OkoBot: new sophisticated malware framework targets cryptocurrency users

ID: 8333563c-2490-506e-87fe-317c7c6a2261

STIX ID: report--8333563c-2490-506e-87fe-317c7c6a2261

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2026-07-15

Date Updated: 2026-07-23

Author: Yaroslav Kikel

...
...

Kaspersky analysts describe OkoBot, a modular multi-stage crimeware framework initiated by the TookPS PowerShell downloader that establishes SSH tunnels to orchestrate payload delivery and exfiltration. The framework (over 20 payloads) includes browser-extension loaders, a SeedHunter module that phishes hardware-wallet seed phrases, a keylogger, screen/video capture (OkoSpyware), process injectors, and a plugin dispatcher; it employs UAC bypass, RDP persistence, VMProtect obfuscation, and encrypted in-memory implants. Hundreds of victims in 25+ countries were observed, with active C2 infrastructure and comprehensive IoCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.