A malware framework dubbed OkoBot has been silently lurking for more than a year, targeting the single most dreaded vulnerability for crypto owners: seed phrases. Cybersecurity firm Kaspersky recently uncovered how it operates, revealing an alarming scope - around 20 malicious modules working together, ranging from fake hardware wallet interfaces to background screen recorders.
What sets OkoBot apart from previous campaigns, according to Kaspersky, is how it exfiltrates stolen data: via an SSH tunnel routed directly from the victim’s computer to the attacker’s server. Victims have already been identified in at least five countries - Brazil, Vietnam, Canada, Mexico, and Turkey. Interestingly, its operators deliberately block IP addresses from Russia and other CIS nations, offering a subtle hint regarding the attack’s likely origin.
Tricked into Compromising Their Own Wallets
OkoBot’s primary weapon is not sophisticated exploit code, but a deception known as ‘ClickFix’. This social engineering technique tricks victims into manually executing malicious commands - through fake error messages, bogus verification steps, or convincing ‘fix’ instructions. The malware is distributed via GitHub repositories disguised as legitimate software, including Microsoft SQL Server Management Studio.
Once inside, the modules operate with well-structured roles. The ‘SeedHunter’ module displays a fake recovery interface mimicking Ledger or Trezor - as soon as the victim types in their seed phrase, the secret words are sent straight to the operators. ‘MC Keylogger’ logs keystrokes and monitors the clipboard to steal passwords and copied wallet addresses. Meanwhile, ‘OkoSpyware’ tracks passwords and even records video of active windows on the victim’s screen.
Kaspersky noted that OkoBot evolved from an older malware dubbed ‘TookPS’, first identified in 2025. Since January 2026, the firm has tracked numerous attacks utilizing this malware family.
Not an Isolated Threat
OkoBot appears to be part of a broader wave. Security firm SlowMist reported a separate campaign where attackers impersonated Web3 recruiters on LinkedIn, sending fake GitHub repositories disguised as technical interview assessments to drain project keys, cloud credentials, and browser wallet extension data from deceived developers.
The ClickFix technique itself has an established track record. North Korea-linked hacking group Lazarus previously deployed it in the ‘Mach-O Man’ macOS campaign reported by CertiK in April - sending fake meeting invites to fintech and crypto executives, then prompting victims to paste ‘fix’ commands into Terminal. Another malware, TrapDoor (reported in May), was distributed via poisoned developer packages, targeting access to Coinbase, Binance, MetaMask, Solana, and Aptos. TrapDoor even attempted to manipulate AI assistants using hidden prompts to execute fake ‘security scans’ that leaked secrets.
Why This Is No Ordinary Threat
A crucial point to remember: once a seed phrase is compromised, blockchain transactions cannot be reversed. There is no undo button, and no bank to freeze the funds. For victims, asset recovery is nearly impossible. That is why seed phrase attacks are far more devastating than routine password thefts - and why a single momentary lapse in pasting commands from unknown sources can drain an entire wallet. Exercising caution around ‘error messages instructing you to run commands’ is no longer paranoia, but a necessity.
Reported by crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




