One browser-wallet compromise can turn into a remote control platform. The useful assumption is that you find one stealer, clean it, and move on. This campaign breaks that assumption: the infected host stays reachable through an SSH tunnel, so operators can keep swapping in new modules and keep harvesting data after the first payload is gone.
Kaspersky says the active OkoBot campaign evolved from earlier TookPS waves into a framework with more than 20 payloads and implants. It targets cryptocurrency users, monitors Chromium-based browsers, steals seed phrases, and has already been seen delivering strains including Rilide. TookPS now serves as the first step in a wider modular chain, not the whole infection.
That shifts the threat from a single malicious binary to a persistent delivery system. For defenders, cleaning one stealer does not tell you whether the SSH path and the rest of the module set are still in place.