Kaspersky, a cybersecurity firm, has uncovered a sophisticated malware framework designed to steal cryptocurrency from unsuspecting users.
The firm warns that the campaign remains active and has already affected hundreds of victims in more than 25 countries.
The malware, dubbed OkoBot, is a previously undocumented framework comprising more than 20 malicious components capable of stealing cryptocurrency wallets, harvesting seed phrases, capturing keystrokes, recording videos, downloading malicious browser extensions and executing remote commands on infected devices.
According to researchers from Kaspersky’s Global Research and Analysis Team (GReAT), the framework employs a tool known as TookPS to extract cryptocurrency wallet seed phrases while a newly identified OkoSpyware module monitors Chromium-based browsers and injects additional malware, including the Rilide banking trojan.
The security firm said the campaign primarily targets cryptocurrency users, with the highest number of victims recorded in Brazil, Vietnam, Canada, Mexico and Türkiye.
Researchers first detected the attacks in January 2026 after identifying malware capable of capturing information displayed in cryptocurrency wallet windows.
Further analysis revealed that OkoBot can collect local files, steal credentials, monitor user activity and deploy multiple malware strains, making it one of the more comprehensive crypto-focused attack frameworks discovered this year.
Kaspersky said the malware typically reaches victims through two main infection methods. The first involves ClickFixattacks, where cybercriminals use social engineering techniques to trick users into manually executing malicious code.
The second relies on malware disguised as legitimate software hosted on GitHub repositories.
In one case investigated by the researchers, attackers distributed a fake installer masquerading as Microsoft’s SQL Server Management Studio (SSMS), a widely used database management tool, to infect victims’ computers.
The discovery comes as cryptocurrency-related cyberattacks continue to increase globally, with cybercriminals targeting wallet credentials and recovery seed phrases to gain access to users’ digital assets.
Kaspersky advised cryptocurrency users to download software only from trusted sources, avoid running commands suggested by unknown websites, enable multi-factor authentication, and keep security software updated to reduce the risk of compromise.
Get Newsletter Updates
Enjoying our column?
Subscribe to our specialised **Tech Pulse** feed to receive fresh reports and analyses directly in your inbox.

