
Kaspersky researchers detail how OkoBot uses ClickFix social engineering to steal recovery phrases from Ledger and Trezor users across five countries.
Kaspersky has exposed OkoBot, a year-old malware operation that uses roughly 20 modules to steal crypto wallet recovery phrases. The attack has affected users across at least five countries, according to a report published by Bits.media.
Most identified victims were in Brazil, Vietnam, Canada, Mexico, and Turkey, Kaspersky researchers found. The operators blocked IP addresses from Russia and other Commonwealth of Independent States countries.
The malware spreads through GitHub repositories. It is disguised as legitimate software, including Microsoft SQL Server Management Studio. The attackers rely on the ClickFix social engineering method, which tricks victims into running malicious commands on their own devices, Kaspersky said.
The technique typically presents users with fake error messages, verification steps, or repair instructions. Following those directions causes victims to execute code that installs the malware without realizing the command is malicious.
Among OkoBot's modules, one called SeedHunter displays a fake recovery interface linked to hardware wallets such as Ledger and Trezor. When users enter their recovery phrases into the fraudulent screen, the module sends the information to the malware operators, Kaspersky said.
A second module, MC Keylogger, records keyboard input and monitors clipboard activity. It captures passwords and copied wallet addresses. OkoSpyware can track wallet passwords and record videos of open windows, giving attackers another way to observe activity on an infected device.
Once a recovery phrase is exposed, the attackers can take control of the associated wallet and move its assets. Victims have little chance of recovering stolen cryptocurrency because blockchain transfers are generally irreversible, Kaspersky warned.
The malware's modular design lets operators collect different types of information from a single infected system. According to the security company's findings, OkoBot can target both wallet access data and credentials connected to other services on the device.
OkoBot is the latest campaign found using ClickFix against the cryptocurrency sector. As crypto.news reported in April, North Korea's state-backed Lazarus Group used the same technique in a macOS campaign known as "Mach-O Man."
CertiK, the blockchain security firm, said Lazarus sent fake online meeting invitations to fintech and crypto executives. Victims were instructed to paste supposed repair or verification commands into the macOS Terminal, which installed malware capable of stealing cryptocurrency and corporate information.
CertiK also found that the Mach-O Man toolkit deleted itself after running, making forensic analysis more difficult. The campaign combined social engineering with terminal-level commands instead of relying only on malicious file downloads.
Developer tools have provided another route into crypto systems. In May, crypto.news reported that TrapDoor malware was distributed through poisoned software packages targeting developers in cryptocurrency, decentralized finance, artificial intelligence, and security infrastructure.
TrapDoor sought wallet data, API keys, cloud credentials, and SSH access tied to services including Coinbase, Binance, MetaMask, Brave, Solana, Sui, and Aptos. Researchers also found hidden prompts designed to manipulate Claude and Cursor into running fake security scans that exposed secrets and transmitted them to the attackers.
Victims of OkoBot have little chance of recovering stolen cryptocurrency because blockchain transfers are generally irreversible, Kaspersky warned.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.