Cybersecurity firm Kaspersky has identified a new malware framework called OkoBot that specifically targets cryptocurrency investors through sophisticated social engineering tactics and trojanized applications on GitHub. The malware has been active since April 2025.
OkoBot operates by injecting seed phrase phishing prompts directly into legitimate hardware wallet software, including Ledger and Trezor desktop applications. On an infected PC, the malware waits for users to connect their hardware wallet, then displays a convincing but malicious page within the legitimate app interface to capture recovery phrases. This technique makes it particularly dangerous as victims believe they are interacting with trusted software.
The malware framework is modular in design, with components capable of session hijacking, credential theft, and clipboard monitoring. One module specifically targets browser-stored cryptocurrency wallet extensions and password managers.
Kaspersky researchers noted that OkoBot represents an evolution in crypto-targeting malware, moving beyond simple keyloggers toward sophisticated man-in-the-browser attacks that can intercept and modify transactions in real time. The report, covered by Cointelegraph and The Hacker News, recommends that crypto users only download wallet software from official sources, enable two-factor authentication, and regularly monitor for unauthorized transactions.
