logo

OkoBot Malware Uses ClickFix, Hidden Browser Extensions to Steal Crypto Data

ID: eb42c2bc-42cd-5658-b1ab-fc0276485964

STIX ID: report--eb42c2bc-42cd-5658-b1ab-fc0276485964

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Waqas

...
...

**OkoBot** is an active, multi-stage malware campaign (identified by Kaspersky) that compromises Windows machines to steal cryptocurrency wallet files, seed phrases, browser-stored credentials, and record wallet application windows. The operation uses social-engineering ClickFix scams and malicious GitHub-distributed software to deliver a PowerShell loader (TookPS) that establishes SSH-based remote control, deploys screen/keylog capture (OkoSpyware), injects fake recovery UIs into hardware wallet apps (SeedHunter), installs hidden Chromium extensions, and implements persistence and RDP backdoors; it has infected hundreds of users across 25+ countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.