OkoBot is a modular Windows malware framework focused on cryptocurrency theft, credential theft, and persistent remote access. Active since at least April 2025, it has been used in a multi-stage intrusion chain that deploys more than 20 payloads and implants. The framework is associated with the evolution of TookPS-based activity and is designed to compromise users who manage cryptocurrency on Windows systems, including owners of hardware wallets.
Initial access has been observed through ClickFix social-engineering lures and trojanized software distributed through GitHub, including fake professional software packages. After execution, the TookPS PowerShell stage installs SSH, establishes an SSH tunnel to attacker infrastructure, and enables follow-on access by an automated bot that inventories the host and steals wallet files, browser profiles, cookies, and credentials. OkoBot also weakens host defenses by suppressing Microsoft Defender notifications, and it enables persistent remote access by opening Remote Desktop firewall access, adding a remote-access user, patching terminal services to allow concurrent RDP sessions, and creating scheduled-task-based persistence.
The framework delivers additional modules over the SSH channel or subsequent stages. Browser-focused components inject into Chromium-based browsers and silently install hidden malicious extensions, including Rilide. SeedHunter targets Trezor and Ledger companion applications by injecting into wallet software, monitoring for connected hardware wallets, and displaying convincing fake recovery interfaces to steal seed phrases. OkoSpyware monitors more than 100 applications, including cryptocurrency wallets and password managers, records keystrokes, and captures video of targeted application windows. A separate keylogging component captures keystrokes, clipboard contents, screenshots, file-copy activity, and USB-device information. Exfiltration stages upload collected artifacts and then remove local traces such as harvested files and PowerShell console history.
Victimology indicates broad global reach with hundreds of observed victims across more than 25 countries, with especially high activity in Brazil, Vietnam, Canada, Mexico, and Türkiye. The campaign has not been conclusively attributed to a known threat actor, though multiple reporting points noted indicators consistent with a suspected Russian-speaking operator, including Russian-language code comments, geofencing of Russia and CIS locations, and use of tooling associated with Russian-speaking cybercrime ecosystems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
...with a scheduled task named “Apple Sync” reconnecting the machine to attackers every hour.
If the warning returns at a regular interval, Task Scheduler is the first place to correlate.
Its PowerShell command can fetch both a randomly named 7-Zip program and a randomly named payload, or download the payload directly.
ErrTraffic begins after someone reaches a compromised WordPress website. The injected JavaScript does not contain the final destination in clear text.
Instead of exploiting a software flaw, the page tells a visitor to copy and paste a supposed fix, often into the Windows Run box or PowerShell. | The campaign, tracked as ErrTraffic, turns hacked WordPress sites into launch points for fake verification prompts that persuade visitors to run harmful Windows commands. The trick is known as ClickFix.
...with a scheduled task named “Apple Sync” reconnecting the machine to attackers every hour.
If the warning returns at a regular interval, Task Scheduler is the first place to correlate.
...with a scheduled task named “Apple Sync” reconnecting the machine to attackers every hour.
If the warning returns at a regular interval, Task Scheduler is the first place to correlate.
For each match, a bundled FFmpeg instance records MP4 video of that window while logging keystrokes. A separate keylogger captures clipboard text
For each match, a bundled FFmpeg instance records MP4 video of that window while logging keystrokes. A separate keylogger captures clipboard text
For each match, a bundled FFmpeg instance records MP4 video of that window... and a screenshot every five minutes.
49 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Okobot is presented as a payload delivered by ErrTraffic that arrives via ZIP and malicious DLL files, attempts to disable or weaken Microsoft Defender protections, and tampers with LSASS protections to facilitate credential access.
Referenced only as a comparative example involving hidden PowerShell and deceptive scheduled tasks.
A multi-stage malware framework used to steal cryptocurrency wallet data and provide full remote control on victim machines. It harvests wallet files, browser cookies, and credentials, enables RDP access, deploys additional modules over SFTP, and supports seed phrase phishing, keylogging, screen recording, and clipboard/screenshot theft.
A Windows-focused stealer targeting cryptocurrency users. It steals wallet files, seed or recovery phrases, passwords, and browser data, records activity in financial applications, disables Defender notifications, enables RDP access, creates a remote user, and establishes persistence via a scheduled task.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.