Subscribe to our Telegram channel!
OkoBot disguises itself as legitimate software and steals data from Trezor and Ledger crypto wallets
Experts have identified a malicious bot called OkoBot, which has been attacking cryptocurrency users for over a year. To infect devices, attackers use the ClickFix social engineering technique: they trick the victim into executing a malicious command themselves. At the same time, the bot spreads through fake GitHub repositories disguised as legitimate software tools.
One such repository offered a download of SQL Server Management Studio, but in reality, the user received an infected version of the Audacity audio editor containing a Trojan. A PowerShell script called TookPS is distributed through this channel, which launches the first stage of the attack: it installs and configures an SSH bot for the subsequent deployment of malicious components.
The SSH bot collects the user’s name, operating system version, IP address, and antivirus software information, and disables Windows Defender notifications. In addition, it intercepts browser cookies, saved login credentials, and information about cryptocurrency wallets.
OkoBot uses several specialized modules. The ext daemon/extl.exe module injects itself into the Chrome browser and silently installs the Rilide extension, which collects financial data, cookies, and cryptocurrency information. SeedHunter targets Trezor Suite, Ledger Wallet, and Ledger Live hardware wallets by replacing the seed phrase recovery screen with a fake one. MC Keylogger records all keystrokes and clipboard content, takes screenshots every five minutes, and monitors USB device connections. The OkoSpyware module monitors passwords for crypto wallets and, using FFmpeg, records videos of their windows and intercepts keystrokes.
If attackers obtain the seed phrase, they gain full control over all of the victim’s crypto assets. Funds are instantly transferred to addresses controlled by the hackers, and it is virtually impossible to recover them.
According to experts, the highest number of OkoBot victims has been recorded in Brazil, Vietnam, Canada, Mexico, and Turkey. The total amount of stolen funds has not been disclosed.
This is not the first such incident: last year, experts at ScamSniffer identified a scheme to steal seed phrases from Phantom Wallet users. At that time, the scammers created fake pop-up windows offering to update the browser extension, after which they asked the victim to enter their seed phrase for confirmation.
