← All stories
● Covered by 2 sources · 2 reportsMedium impact

OkoBot Malware Targets Cryptocurrency Wallets via Seed Phrase Phishing

🔄 Updated 77d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • OkoBot targets cryptocurrency wallets via phishing.
  • Active since April 2025 with global victims.
  • Predominantly affects users in Brazil, Vietnam, Canada, Mexico, and Türkiye.
  • Deploys over 20 payloads for data theft.
  • Uses ClickFix attacks and fake GitHub repositories.

OkoBot Malware Targets Wallet Apps

OkoBot is a malicious framework that has been targeting cryptocurrency wallet users since April 2025. It operates by injecting phishing pages into the desktop software of legitimate wallet applications like Ledger and Trezor, tricking users into providing their recovery phrases.

Global Impact with Regional Hotspots

Kaspersky has reported that OkoBot has affected hundreds of users worldwide, with particular concentrations in Brazil, Vietnam, Canada, Mexico, and Türkiye. The malware's presence underscores the widespread security threats faced by cryptocurrency users globally.

Complex Attack Methods

OkoBot employs over 20 payloads to execute its attacks, utilizing methods such as ClickFix attacks and distributing trojanized software through fake GitHub repositories. This sophisticated approach allows it to steal various types of sensitive data, including cryptocurrency credentials and browser cookies.

Why This Matters

The OkoBot framework poses a significant threat to cryptocurrency wallet owners, as it directly targets the security of highly-protected assets through complex cyberattack methods. Given its global impact and potential for financial loss, it highlights the need for strengthened cybersecurity measures in the cryptocurrency sector.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The new OkoBot malicious framework deploys over 20 payloads designed to steal cryptocurrency credentials and sensitive data. Utilizing ClickFix attacks and trojanized software from fake GitHub repositories, OkoBot has evolved from previous campaigns and poses a significant threat to global users, particularly in Brazil.

The OkoBot malware framework has been active since April 2025, targeting hardware wallet users by injecting phishing pages into legitimate wallet software. Kaspersky reported hundreds of victims worldwide, with a significant concentration in Brazil, Vietnam, Canada, Mexico, and Türkiye, highlighting the threat to cryptocurrency security.