Researchers reported that the OkoBot malware framework has been actively compromising users since 2025 through ClickFix social-engineering lures and trojanized software hosted on GitHub, then establishing SSH-based access to infected machines. The framework, described as an evolution of the TookPS campaign, delivers more than 20 payloads for persistence, remote command execution, credential theft, browser-extension abuse, and cryptocurrency theft, with observed victims spanning more than 25 countries and the highest concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye.
The operators use modules including HDUtil, SeedHunter, MC Keylogger, OkoSpyware, and a malicious browser-extension loader to steal wallet files, browser data, credentials, screenshots, clipboard contents, and recordings of wallet or password-manager windows. Investigators said the campaign specifically targets cryptocurrency users by phishing for hardware-wallet seed phrases and abusing browser extensions to capture sensitive data, while infrastructure and code artifacts—including geoblocking of Russia/CIS IP space, use of the Rilide extension, and Russian-language comments—suggest links to Russian-speaking cybercriminals, though attribution remains unconfirmed.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
Kaspersky disclosed that OkoBot includes a SeedHunter module that hooks Trezor Suite, Ledger Wallet, and Ledger Live to inject fake recovery-phrase pages inside the legitimate applications. The module can wait until a real Ledger or Trezor device is connected before prompting victims, showing the campaign specifically targets cryptocurrency hardware wallet users via endpoint compromise rather than a wallet vulnerability.
Securelist reported that OkoBot was still active as of mid-2026, with hundreds of victims observed across more than 25 countries. The report also described the framework's SSH-based access, wallet-targeting modules, and indicators suggesting possible Russian-speaking cybercriminal involvement.
Securelist reported that the OkoBot malware framework, an evolved TookPS-based campaign, has been operating since 2025. The campaign uses ClickFix lures and trojanized GitHub-hosted software to infect victims and deploy numerous payloads for persistence, credential theft, and cryptocurrency theft.
James Forshaw described new Sandbox Analysis Tools capabilities for interacting with Windows Local RPC servers from managed .NET code and demonstrated a previously undocumented UAC bypass via the APPINFO service's hidden UAC RPC interface.
In January 2026, investigators detected multiple attacks using the OkoBot malware framework to steal cryptocurrency wallet data. The campaign used a four-stage infection chain initiated by a malicious PowerShell script, coordinated more than 20 payloads over an SSH tunnel, and the report published related IOCs and detection queries.
Researchers reported that in early 2025, multiple campaigns impersonated DeepSeek with fake websites and bogus desktop clients to deliver a Python stealer, SSH-enabling PowerShell payloads, a KCP-tunneling backdoor, and a Farfli backdoor variant. The lures were distributed via typosquatted domains and social media posts, and some infrastructure used geofencing or targeted Chinese-speaking users.
Securelist reported that attackers distributed the TookPS downloader via fake and pirated-software lures impersonating UltraViewer, AutoCAD, SketchUp, Ableton, and Quicken, targeting both individuals and organizations. The report said TookPS fetched PowerShell payloads that established SSH tunnels and deployed additional malware including a modified TeviRat sample and Lapmon.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 79 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
12 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcexakep.ru
Open sourcehackread.com
Open sourcebleepingcomputer.com
Open sourcemoonlock.com
Open sourcesecurelist.com
Open sourcesecurelist.com
Open sourcegoogleprojectzero.blogspot.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.