Kaspersky identifies OkoBot malware targeting crypto wallet seed phrases

Kaspersky identifies OkoBot malware targeting crypto wallet seed phrases

Kaspersky said OkoBot has hit hundreds of victims in more than 25 countries since at least January 2026, using ClickFix lures and trojanized GitHub software to steal seed phrases, wallet data and credentials.

Fact Check
The claim is fully corroborated by Kaspersky's own primary sources. The Securelist report by Kaspersky GReAT and the Kaspersky press release (both July 15, 2026) confirm the malware is named OkoBot, is modular (20+ payloads), targets crypto wallet seed phrases via the SeedHunter module injecting phishing pages into hardware wallet apps (Trezor/Ledger), uses fake GitHub tools and ClickFix tactics for distribution, monitors passwords/credentials, and affects victims across 25+ countries. The Hacker News report independently corroborates all key elements. Every component of the claim matches authoritative primary evidence.
    Reference123
Summary

Kaspersky has identified OkoBot, a modular malware framework targeting cryptocurrency investors and hardware-wallet users through ClickFix lures and trojanized GitHub software, with hundreds of victims across more than 25 countries and activity still ongoing as of mid-July 2026. The framework carries more than 20 payloads used to steal wallet data, seed phrases, credentials and other sensitive information, including components that inject fake recovery pages into Trezor and Ledger applications. Kaspersky said OkoBot differs from a simple browser stealer because it combines wallet theft, keylogging, spyware and persistence mechanisms such as reverse-SSH access and RDP re-entry. The company said currently available information does not allow high-confidence attribution to a known crimeware actor, though unconfirmed reporting has suggested a possible Russian-speaking link.

Terms & Concepts
  • ClickFix: A social engineering tactic that tricks users into executing malicious commands on their own devices.
  • seed phrases: Recovery words that can restore access to a crypto wallet; if stolen, they can give attackers control of funds.
  • reverse-SSH: A technique that lets an infected machine open a remote connection back to an attacker, helping maintain access and move data out.