OkoSpyware is a Windows spyware component within the OkoBot malware framework that targets cryptocurrency users and other high-value desktop application users. It monitors more than 100 applications, including cryptocurrency wallets and password managers, and captures both user input and visual activity from targeted windows. Its core behavior is to watch for execution of selected applications or matching browser wallet-page titles, then use a bundled FFmpeg component to record MP4 video of the target window while simultaneously logging keystrokes. Observed targets include wallet software, browser-based wallet interfaces, and password-management tools, indicating a focus on theft of credentials, wallet access material, and other sensitive user actions performed inside trusted applications.
OkoSpyware has been deployed as a later-stage implant in the broader OkoBot intrusion chain. That framework has been delivered through ClickFix social-engineering lures and trojanized software distributed via GitHub, after which additional modules are staged onto compromised hosts. OkoSpyware is associated with campaigns active from 2025 into 2026 that affected victims in more than 25 countries, with especially high victim counts in Brazil, Vietnam, Canada, Mexico, and Türkiye. The broader operation focused heavily on cryptocurrency theft and persistent remote access on infected Windows systems. Public reporting did not conclusively attribute the campaign to a known threat actor, though several indicators were assessed as consistent with a suspected Russian-speaking operator.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
For each match, a bundled FFmpeg instance records MP4 video of that window while logging keystrokes. A separate keylogger captures clipboard text
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A spyware/keylogging module in the OkoBot framework that records wallet and password manager windows, logs keystrokes, captures clipboard contents, screenshots, copied images, file paths, and USB device details.
Шпионский модуль OkoBot, наблюдающий за более чем 100 приложениями, включая криптокошельки и менеджеры паролей; записывает нажатия клавиш и сохраняет видео из окон целевых программ.
An implant delivered as part of the OkoBot campaign that records video of cryptocurrency wallet application windows and logs keystrokes to capture sensitive wallet activity and credentials.
A spyware module that monitors applications including cryptocurrency wallets and password managers, records their windows, and captures keystrokes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.