
Kaspersky said OkoBot has hit hundreds of victims in more than 25 countries since at least January 2026, using ClickFix lures and trojanized GitHub software to steal seed phrases, wallet data and credentials.
Kaspersky has identified OkoBot, a modular malware framework targeting cryptocurrency investors and hardware-wallet users through ClickFix lures and trojanized GitHub software, with hundreds of victims across more than 25 countries and activity still ongoing as of mid-July 2026. The framework carries more than 20 payloads used to steal wallet data, seed phrases, credentials and other sensitive information, including components that inject fake recovery pages into Trezor and Ledger applications. Kaspersky said OkoBot differs from a simple browser stealer because it combines wallet theft, keylogging, spyware and persistence mechanisms such as reverse-SSH access and RDP re-entry. The company said currently available information does not allow high-confidence attribution to a known crimeware actor, though unconfirmed reporting has suggested a possible Russian-speaking link.