OkoBot Malware Uses ClickFix and Hidden Browser Extensions to Steal Crypto Data

https://hackread.com/wp-content/uploads/2026/07/okobot-malware-steals-crypto-seed-phrases-records-wallet-windows.jpg

Windows users who manage cryptocurrency on their PCs are being targeted by OkoBot malware, an active operation designed to steal wallet files, recovery phrases, passwords, and browser data while recording activity within financial applications.

DataManagement

Kaspersky identified the campaign in January 2026 after investigating malware that recorded the on-screen activity of cryptocurrency wallets. Researchers found a four-stage operation containing more than 20 malicious payloads and implants.

An Ongoing Campaign

OkoBot malware campaign has already affected hundreds of users in more than 25 countries, with Brazil, Vietnam, Canada, Mexico and Türkiye recording the most detections. Kaspersky said the campaign remained active when its long technical analysis was published on 15 July 2026.

According to researchers, OkoBot reaches Windows computers through ClickFix scamsand malicious software advertised through GitHub. ClickFix attacks display fake errors or verification instructions that persuade users to copy and run commands in PowerShell or the Windows Run...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more