Favicon

Kaspersky uncovers OkoSpyware framework targeting cryptocurrency users

Reported By: ST Report July 22, 2026, 4:25 pm Category: tech
Kaspersky uncovers OkoSpyware framework targeting cryptocurrency users
Photo: Courtesy
Kaspersky uncovers OkoSpyware framework targeting cryptocurrency users

July 22, 2026: In January 2026, Kaspersky's Global Research and Analysis Team (GReAT) uncovered OkoBot, a sophisticated malware framework designed to steal cryptocurrency assets and sensitive data. Comprising more than 20 malicious modules, OkoBot can harvest cryptocurrency wallets, seed phrases, credentials, local files, browser extensions, keystrokes, video recordings, and execute remote commands.

One implant loads hidden malicious browser extensions by modifying browser memory, while the OkoSpyware module records keystrokes and application windows. The malware primarily spreads through ClickFix social engineering attacks and fake GitHub software, including a counterfeit SQL Server Management Studio installer.

Another component, SeedHunter, targets Trezor Suite, Ledger Wallet, and Ledger Live, injecting malicious code to display phishing pages that steal hardware wallet seed phrases. Although the campaign has not been conclusively attributed, its techniques and code artifacts suggest links to Russian-speaking cybercriminals.

“The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026. The observed infection vectors strongly suggest that developers are among its primary targets. Of particular concern is the malware’s continued evolution, which indicates that the framework is being actively maintained. As distribution efforts persist, the campaign has the potential to reach more users and expand into additional countries in the near term,” says Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team.

The full report is available on securelist.com.

Kaspersky GReAT experts advise users to avoid running code or following instructions from unverified sources, as attackers often use these tactics to compromise devices. Install trusted security software such as Kaspersky Premium to detect and block threats. Store passwords and cryptocurrency recovery phrases securely using a dedicated password manager instead of notes or photo galleries. Never disable antivirus software to install applications, and be cautious when downloading game mods or third-party tools. Keep systems updated, use strong, unique passwords, and enable multi-factor authentication.

About the Global Research & Analysis Team

Established in 2008, Global Research & Analysis Team (GReAT) operates at the very heart of Kaspersky, uncovering APTs, cyber-espionage campaigns, major malware, ransomware and underground cyber-criminal trends across the world. Today GReAT consists of 35+ experts working globally – in Europe, Russia, Latin America, Asia and the Middle East. Talented security professionals provide company leadership in anti-malware research and innovation, bringing unrivaled expertise, passion and curiosity to the discovery and analysis of cyberthreats.