Kaspersky reveals a new malicious framework targeting cryptocurrency users with the use of OkoSpyware as cybersecurity researchers warn of an evolving malware campaign that has already compromised hundreds of victims in more than 25 countries.
Kaspersky reveals a new malicious framework targeting cryptocurrency users with the use of OkoSpyware as campaign expands globally
Kaspersky’s Global Research and Analysis Team (GReAT) has uncovered a sophisticated malware ecosystem known as OkoBot, describing it as one of the more advanced cyber threats currently targeting cryptocurrency users worldwide. The campaign, which has remained active for more than a year, combines multiple malicious tools capable of stealing digital assets, harvesting sensitive credentials and monitoring user activity.
According to Kaspersky researchers, the framework consists of more than 20 different malicious payloads and implants designed to perform a wide range of cybercriminal activities. These include collecting local files, executing remote commands, downloading malicious browser extensions, stealing cryptocurrency wallets, recording video and capturing sensitive user information.
Among the most concerning discoveries is a newly identified OkoSpyware module, which monitors Chromium-based browsers, records keystrokes and captures video streams from targeted application windows. The framework also deploys additional malware, including the Rilide stealer, further increasing the threat posed to victims.
The campaign employs a malware component known as TookPS to exfiltrate cryptocurrency seed phrases, allowing attackers to gain complete control over victims’ digital wallets. Another module, called SeedHunter, actively monitors system processes and injects malicious code into legitimate cryptocurrency wallet applications, including Trezor Suite, Ledger Wallet and Ledger Live.
When a supported hardware wallet is detected, the malware displays convincing phishing pages specifically designed for each wallet type. These fake interfaces trick users into revealing their recovery seed phrases, giving attackers direct access to cryptocurrency holdings.
Researchers said the campaign has already affected users in more than 25 countries, with the highest number of infections reported in Brazil, Vietnam, Canada, Mexico and Türkiye. While attribution remains uncertain, technical analysis identified several code artifacts written in Russian, and the techniques closely resemble those commonly used by Russian-speaking cybercriminal groups.
The investigation found that attackers primarily rely on two infection methods. One involves ClickFix attacks, a social engineering technique that convinces users to execute malicious commands themselves. The second uses malware disguised as legitimate software hosted on GitHub repositories.
During the investigation, Kaspersky analysts identified a fake installer masquerading as Microsoft SQL Server Management Studio (SSMS), a widely used database management application. Unsuspecting users downloading the software instead installed malware that provided attackers with access to their systems.
The findings indicate that developers are among the campaign’s primary targets, likely because they frequently download software, development tools and code repositories from online sources. However, anyone involved in managing digital assets remains at significant risk.
Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team, said the OkoBot campaign has remained active through July 2026 and continues to evolve.
According to Galov, the malware’s continuous development suggests that threat actors are actively maintaining and expanding the framework. As distribution efforts continue, researchers believe the campaign could spread to additional countries and compromise more users in the coming months.
To reduce the risk of infection, Kaspersky advises users never to execute unknown code or follow software installation instructions from unverified sources. The company also recommends using comprehensive security software, securely storing passwords and recovery phrases in trusted password managers instead of notes or photo galleries, and avoiding the installation of unofficial software, game modifications or third-party utilities that require disabling antivirus protection.
Experts further recommend keeping operating systems and applications fully updated, using strong and unique passwords for every account, enabling multi-factor authentication wherever available and maintaining good cryptocurrency security practices to reduce exposure to increasingly sophisticated malware attacks targeting digital assets.

