Close Menu
Altcoinvest
    What's Hot

    CPI, PPI, and FOMC minutes headline a two-week data window

    August 17, 2026

    Greenlane’s $70M BERA treasury ends Q2 valued at $16M

    August 17, 2026

    비트코인도미넌스로 예측하는 알트불장 싸이클 1편

    August 17, 2026
    Facebook X (Twitter) Instagram
    Altcoinvest
    • Bitcoin
    • Altcoins
    • Exchanges
    • Youtube
    • Crypto Wallets
    • Learn Crypto
    • bitcoinBitcoin(BTC)$63,546.000.70%
    • ethereumEthereum(ETH)$1,900.891.00%
    • tetherTether(USDT)$1.000.00%
    • binancecoinBNB(BNB)$605.37-0.10%
    • usd-coinUSDC(USDC)$1.000.00%
    • rippleXRP(XRP)$1.000.10%
    • solanaSolana(SOL)$75.470.00%
    • tronTRON(TRX)$0.3323560.40%
    • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-0.50%
    • HyperliquidHyperliquid(HYPE)$58.952.70%
    Altcoinvest
    Home»Altcoins»Kaspersky exposes OkoBot’s 20-module crypto wallet attack
    Kaspersky exposes OkoBot’s 20-module crypto wallet attack
    Altcoins

    Kaspersky exposes OkoBot’s 20-module crypto wallet attack

    July 18, 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Kaspersky exposes OkoBot’s 20-module crypto wallet attack

    Kaspersky has exposed OkoBot, a year-old malware operation that uses roughly 20 modules to steal crypto wallet recovery phrases and has affected users across at least five countries.

    Summary

    • Kaspersky uncovered OkoBot using roughly 20 modules to steal crypto wallet credentials.
    • The malware has affected users in Brazil, Vietnam, Canada, Mexico, and Turkey.
    • OkoBot uses fake recovery screens, keylogging, spyware, and ClickFix commands to target victims.

    Kaspersky researchers discovered that the malware has remained active for more than a year, according to a report published by Bits.media. Most identified victims were located in Brazil, Vietnam, Canada, Mexico, and Turkey, while the operators blocked IP addresses from Russia and other Commonwealth of Independent States countries.

    Distributed through GitHub repositories, OkoBot is disguised as legitimate software, including Microsoft SQL Server Management Studio. Kaspersky found that the attackers rely on the ClickFix social engineering method, which tricks victims into running malicious commands on their own devices.

    The technique often presents users with fake error messages, verification steps, or repair instructions. Following those directions causes victims to execute code that installs the malware without realizing the command is malicious.

    OkoBot targets seed phrases and wallet credentials

    Among OkoBot’s modules, SeedHunter displays a fake recovery interface linked to hardware wallets such as Ledger and Trezor, according to Kaspersky. When users enter their recovery phrases into the fraudulent screen, the module sends the information to the malware operators.

    A second module called MC Keylogger records keyboard input and monitors clipboard activity, allowing it to capture passwords, copied wallet addresses, and other credentials. OkoSpyware can track wallet passwords and record videos of open windows, giving attackers another way to observe activity on an infected device.

    Once a recovery phrase is exposed, the attackers can use it to take control of the associated wallet and move its assets. Kaspersky warned that victims have little chance of recovering stolen cryptocurrency because blockchain transfers are generally irreversible.

    The malware’s modular design also lets its operators collect different types of information from a single infected system. According to the security company’s findings, OkoBot can target both wallet access data and credentials connected to other services used on the device.

    ClickFix attacks have also targeted crypto developers

    OkoBot is the latest malware campaign found using ClickFix against the cryptocurrency sector. As crypto.news reported in April, North Korea’s state-backed Lazarus Group used the same technique in a macOS campaign known as “Mach-O Man.”

    Citing research from CertiK, the report found that Lazarus sent fake online meeting invitations to fintech and crypto executives. Victims were instructed to paste supposed repair or verification commands into the macOS Terminal, which installed malware capable of stealing cryptocurrency and corporate information.

    CertiK also found that the Mach-O Man toolkit deleted itself after running, making forensic analysis more difficult. The campaign combined social engineering with terminal-level commands instead of relying only on malicious file downloads.

    Developer tools have provided another route into crypto systems. In May, crypto.news reported that TrapDoor malware was distributed through poisoned software packages targeting developers in cryptocurrency, decentralized finance, artificial intelligence, and security infrastructure.

    According to that report, TrapDoor sought wallet data, API keys, cloud credentials, and SSH access tied to services and ecosystems including Coinbase, Binance, MetaMask, Brave, Solana, Sui, and Aptos. Researchers also found hidden prompts designed to manipulate Claude and Cursor into running fake security scans that exposed secrets and transmitted them to the attackers.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    National Bank Of Canada Discloses XRP And Bitcoin ETF Holdings

    August 17, 2026

    Israel crypto broker Bits of Gold probes customer data breach

    August 17, 2026

    Bitcoin’s U.S. demand flashes a 90-day warning – What it means for BTC

    August 17, 2026

    The SEC meeting that wasn’t: State of Crypto

    August 16, 2026
    Add A Comment

    Comments are closed.

    Tweets by InfoAltcoinvest

    Top Posts

    National Bank Of Canada Discloses XRP And Bitcoin ETF Holdings

    August 17, 2026

    Israel crypto broker Bits of Gold probes customer data breach

    August 17, 2026

    Bitcoin’s U.S. demand flashes a 90-day warning – What it means for BTC

    August 17, 2026

    Trump Administration Weighs Pentagon Loans for U.S. Drone Manufacturers as Defense Stocks Rally

    May 28, 2026

    BITCOIN: IT IS REPEATING!!!!! (My strategy 2026)

    June 18, 2026

    This Hack Just Broke DeFi… And Exposed Everything

    April 26, 2026

    HBAR Punches Back Above $0.10 On This Breakthrough

    March 17, 2026

    Altcoinvest is a leading platform dedicated to providing the latest news and insights on the dynamic world of cryptocurrencies.

    We're social. Connect with us:

    Facebook X (Twitter)
    Top Insights

    CPI, PPI, and FOMC minutes headline a two-week data window

    August 17, 2026

    Greenlane’s $70M BERA treasury ends Q2 valued at $16M

    August 17, 2026

    비트코인도미넌스로 예측하는 알트불장 싸이클 1편

    August 17, 2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.


    Facebook X (Twitter)
    • Home
    • About us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    © 2026 altcoinvest.com

    Type above and press Enter to search. Press Esc to cancel.