OkoBot Malware Uses ClickFix, Hidden Browser Extensions to Steal Crypto Data
ID: eb42c2bc-42cd-5658-b1ab-fc0276485964
STIX ID: report--eb42c2bc-42cd-5658-b1ab-fc0276485964
Feed Name: HackRead
**OkoBot** is an active, multi-stage malware campaign (identified by Kaspersky) that compromises Windows machines to steal cryptocurrency wallet files, seed phrases, browser-stored credentials, and record wallet application windows. The operation uses social-engineering ClickFix scams and malicious GitHub-distributed software to deliver a PowerShell loader (TookPS) that establishes SSH-based remote control, deploys screen/keylog capture (OkoSpyware), injects fake recovery UIs into hardware wallet apps (SeedHunter), installs hidden Chromium extensions, and implements persistence and RDP backdoors; it has infected hundreds of users across 25+ countries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
