Sign up
Subscribe
Home / news / Kaspersky says OkoBot steals crypto wallet seed phrases, credentials, and browser data through ClickFix and fake GitHub repos
news

Kaspersky says OkoBot steals crypto wallet seed phrases, credentials, and browser data through ClickFix and fake GitHub repos

Kaspersky says OkoBot steals crypto wallet seed phrases, credentials, and browser data through ClickFix and fake GitHub repos

Kaspersky has described a new malware family, OkoBot, which it says spreads roughly 20 modules built to steal credentials, browser cookies, and cryptocurrency wallet seed phrases. For high-risk PSPs and crypto businesses, the useful bit is simple: once a seed phrase is exposed, the wallet is effectively compromised, and the funds usually leave for attacker-controlled addresses.

  1. Kaspersky said OkoBot has been active for more than a year and has been distributing the PowerShell script TookPS. The malware is delivered through ClickFix, a social-engineering technique that tricks users into running a malicious command, and through fake GitHub repositories disguised as legitimate software tools.
  2. In one fake repository, the attackers posed as SQL Server Management Studio (SSMS), but Kaspersky said it actually distributed a trojanized version of the audio editor Audacity. According to the researchers, TookPS is used at the first stage to install and configure an SSH bot that then spreads malicious components.
  3. The SSH bot collects the user name, antivirus software details, IP address, and operating system version, and it also disables Windows Defender notifications. It additionally gathers cryptocurrency wallet data, browser cookies, and credentials, which is the sort of inventory a fraud ring needs before it starts moving money or hijacking accounts.
  4. Kaspersky listed four modules used in OkoBot attacks: ext daemon/extl.exe, which is injected into Chrome browsers to stealthily install and hide the Rilide extension targeting credentials, cookies, financial information, and crypto-related data; SeedHunter, which is injected into Trezor Suite, Ledger Wallet, and Ledger Live to show a fake screen during seed phrase recovery; MC Keylogger, which records keystrokes and clipboard activity, including copied text, images, and file paths, and can also track USB connections and take screenshots every five minutes; and OkoSpyware, which monitors crypto wallet passwords and uses FFmpeg to record video of wallet windows and intercept keystrokes.
  5. Kaspersky said most affected users are in Brazil, Vietnam, Canada, Mexico, and Turkey. The company did not name the total amount stolen, and it also noted that access to the servers hosting the initial-stage PowerShell scripts is blocked for IP addresses from Russia and CIS countries.

The practical takeaway for wallet providers and PSPs is not subtle: phishing and social engineering are only the first step. Once a seed phrase, wallet password, browser session, or clipboard is captured, the attack chain moves from device compromise to asset theft fast, and recovery is typically not on the menu.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!