Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
OkoBot Malware Uses 20 Modules to Steal Bitcoin Wallet Seed Phrases

OkoBot Malware Uses 20 Modules to Steal Bitcoin Wallet Seed Phrases

CoinotagCoinotag2026/07/18 19:12
By:Coinotag

Crypto News

Kaspersky has exposed OkoBot, a year-old malware framework built from roughly 20 separate modules engineered to steal cryptocurrency wallet recovery phrases. Our reading of the disclosure shows the operation has already compromised users across at least five countries — Brazil, Vietnam, Canada, Mexico and Turkey — while its operators deliberately blocked IP addresses from Russia and other Commonwealth of Independent States nations. The modular design lets attackers harvest wallet files, browser data and login credentials from a single infected machine. Because seed phrases unlock full control of a wallet, victims face near-total loss: blockchain transfers are irreversible, leaving almost no path to recover stolen funds.

The infection chain begins with social engineering rather than a software flaw. OkoBot is distributed through GitHub repositories disguised as legitimate tools, including a counterfeit build of Microsoft SQL Server Management Studio. Kaspersky documented heavy use of the ClickFix technique, a method that presents fake error messages, verification prompts or repair instructions and tricks victims into pasting malicious commands into their own terminals. Following those steps silently installs the backdoor. The approach sidesteps traditional defenses because the user, not an exploit, executes the payload — a pattern security teams increasingly see aimed at holders of Bitcoin and other altcoins.

At the core of the theft sits SeedHunter, a module that renders a fake recovery interface mimicking hardware wallets such as Ledger and Trezor. When a user types a 12- or 24-word recovery phrase into the fraudulent screen, the data is transmitted straight to the operators, who can then reconstruct the wallet and drain it. The tactic specifically targets the one secret that hardware wallets are designed to keep offline. For anyone securing a self-custody crypto wallet, the lesson is direct: a genuine device never asks you to retype a seed phrase into a desktop window.

Two additional modules widen the surveillance. MC Keylogger records keystrokes and monitors clipboard activity, capturing passwords and copied wallet addresses in real time, while OkoSpyware tracks wallet passwords and even records video of open windows to observe a victim's activity. Together they defeat the copy-paste habits many traders assume are safe, and they can quietly intercept credentials for exchange accounts or an automated AI trading bot running on the same device. The framework's ability to pull several data types from one host means a single careless install can expose an entire portfolio, not merely one wallet or login.

OkoBot did not appear from nowhere. Kaspersky traced it to TookPS, a 2025 campaign that pushed a Trojan downloader through fake software websites, and confirmed multiple attacks tied to the new family since January 2026. What distinguishes this generation is its plumbing: all 20 payloads are orchestrated over a single SSH tunnel, an encrypted channel that transports stolen data from infected computers to attacker-controlled machines while blending into normal network traffic. Researchers warned the framework's modular, reusable structure lowers the barrier for copycats, meaning derivative kits targeting seed phrases could proliferate well beyond the original operators.

The campaign is part of a wider push against the people who build crypto. Separately, blockchain security researchers at SlowMist flagged a scheme in which attackers pose as Web3 recruiters on LinkedIn, then send candidates fake GitHub repositories described as a minimum viable product to test before an interview. Running that code — a routine step in any technical screening — delivers a remote access trojan that steals project keys, cloud credentials and wallet-extension data. A related operation targeted macOS users to hijack Telegram sessions. None of these lures involve a legitimate token airdrop, yet they borrow the same trust-based framing to disarm targets.

Read together, these incidents describe one strategy, not several: attackers have shifted from breaking cryptography to breaking human trust, weaponizing GitHub, LinkedIn and fake wallet screens to reach the seed phrase directly. COINOTAG's own market data underscores why the timing matters — with the Fear & Greed Index at 25 (Extreme Fear), Bitcoin dominance near 69.9% and total crypto market capitalization around $1.85 trillion, jittery holders rushing to secure or move funds are exactly the audience social-engineering kits exploit. Our read is that operational security now protects capital as much as any price level or all-time high; a compromised recovery phrase erases gains no market recovery can restore.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

Understand the market, then trade.
Bitget offers one-stop trading for cryptocurrencies, stocks, and gold.
Trade now!

You may also like

VIPAre There Quantitative Indicators That Work Over the Long Term in Crypto?

Cooling inflation has revived expectations for monetary easing. The probability of a September rate hike fell from around 55% to 34%, while the S&P 500 broke above 7800 for the first time and 18 global equity indexes reached all-time highs on the same day. South Korea's KOSPI led the gains, rising 10.9% for the week. In earnings, Tapestry, Cisco, and JD.com all beat quarterly expectations but still plunged 7%–16% in a single session after disappointing guidance. In the current market, strong results alone are not enough—investors are rewarding strong guidance. Crypto has been left behind by the broader rally, but we believe it is consolidating near a potential bottom. BTC fell 2.6% for the week to around $63,400, but spot ETF outflows moderated and approximately $1 billion flowed back into stablecoins. Sentiment shows an unusually wide divergence: the U.S. equity Fear & Greed Index stands at 66 (Greed), while the Crypto Fear & Greed Index remains at 29 (Fear). Quantitative strategy focus: the four top-performing strategies we identified significantly outperformed buy-and-hold. For ETH, Supertrend generated a total return of 151.2% (44.8% annualized) and outperformed buy-and-hold by 117 percentage points after fees, while ATR Channel Breakout achieved a Sharpe ratio of 1.33 with a maximum drawdown of just 10.2%. For BTC, Bollinger Band Mean Reversion returned 151.3%, outperforming buy-and-hold by 54 percentage points after fees. The effectiveness of each strategy depends on the market regime: mean-reversion strategies perform better in range-bound markets with an upward bias, while trend-following strategies that can move into cash are better suited to range-bound markets with a downward bias. Key assets to watch: BTC, ETH, SOL, XAUUSD, UKOUSD, USOUSD, rWMT, rHD, ONDO, RDDT.

Bitget2026/08/17 04:26
Are There Quantitative Indicators That Work Over the Long Term in Crypto?