Malware · 60 days ago
One browser-wallet compromise can turn into a remote control platform. The useful assumption is that you find one stealer, clean it, and move on. This campaign breaks that assumption: the infected host stays reachable through an SSH tunnel, so operators can keep swapping in new modules and keep harvesting data after the first payload is gone.
Kaspersky says the active OkoBot campaign evolved from earlier TookPS waves into a framework with more than 20 payloads and implants. It targets cryptocurrency users, monitors Chromium-based browsers, steals seed phrases, and has already been seen delivering strains including Rilide. TookPS now serves as the first step in a wider modular chain, not the whole infection.
That shifts the threat from a single malicious binary to a persistent delivery system. For defenders, cleaning one stealer does not tell you whether the SSH path and the rest of the module set are still in place.
3 sources covering this story
New OkoBot framework deploys 20 payloads to steal data, crypto
A new malicious framework called OkoBot is delivering more than 20 payloads in attacks focused on stealing cryptocurrency wallet seed phrases, credentials, and other sensitive data.
OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps
OkoBot injects recovery phrase lures into Ledger and Trezor apps, targeting hundreds of Windows users across more than 25 countries.
OkoBot framework infection chain
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users.
Part of the PlainSec briefing for 2026-07-17