Kaspersky identified OkoBot as a modular malware framework evolved from TookPS, with initial infections primarily delivered through ClickFix attacks and fake GitHub repositories.
Its modules steal browser credentials, cookies, password manager data, cryptocurrency wallet seed phrases, and other sensitive information from Windows endpoints.
Kaspersky detected hundreds of victims across more than 25 countries, highlighting the campaign’s broad geographic reach.
Organizations should strengthen endpoint security, restrict untrusted software, and investigate systems using published indicators of compromise.
Trusted software platforms are increasingly being abused to distribute malware. A newly identified malware framework called OkoBot combines ClickFix attacks, fake GitHub repositories, and a staged infection chain to compromise Windows systems and steal sensitive data.
According to Kaspersky, OkoBot evolved from the previously documented TookPS campaign and uses a modular architecture to deploy more than 20 malicious payloads. Observed modules harvest browser credentials, cookies, password manager data, cryptocurrency wallet seed phrases, and other sensitive information. Researchers also identified components that install hidden Chromium-based browser extensions and capture keystrokes.
For organizations, the campaign highlights how trusted developer platforms and social engineering can increase the risk of credential theft and endpoint compromise, reinforcing the need for stronger software trust and endpoint security controls.
Why OkoBot represents more than another Infostealer
Unlike traditional infostealers, OkoBot uses a modular architecture that enables attackers to deploy multiple malicious components throughout an attack.
Modular framework: Kaspersky identified more than 20 malicious payloads and implants with specialized functions.
Expanded capabilities: Observed components support credential theft, browser compromise, keylogging, spyware, and cryptocurrency wallet targeting.
Flexible deployment: Attackers can deploy additional components after the initial compromise instead of relying on a single malware executable.
More complex investigations: Security teams may need to identify multiple implants, review endpoint activity, and correlate published indicators of compromise (IOCs) to determine the full scope of an infection.
Top 10 Cybersecurity Challenges for Enterprises
Explore the top enterprise cybersecurity challenges and practical strategies to reduce risk.
How the campaign gains a foothold
The OkoBot campaign begins with social engineering rather than software exploits. Kaspersky observed two primary delivery methods: ClickFix attacks, which trick users into executing malicious commands, and fake GitHub repositories masquerading as legitimate software downloads. Both techniques rely on users trusting familiar platforms and completing the infection themselves.
One repository impersonated Microsoft SQL Server Management Studio (SSMS) but instead delivered a trojanized version of Audacity containing a malicious implant. The repository mimicked official installation guidance and ranked highly in search results, making it appear legitimate to unsuspecting users.
Observed infection stages
Stage
Observed Activity
Operational Priority
Initial lure
ClickFix attack or fake GitHub repository
Block execution and educate users
Initial execution
TookPS PowerShell downloader runs
Investigate the endpoint immediately
Host preparation
SSH tunnel configured and system profiled
Review endpoint telemetry
Framework deployment
OkoBot modules delivered
Isolate the affected device
Data targeting
Credential and wallet theft modules activated
Rotate credentials and assess exposure
What the payload ecosystem reveals
Rather than relying on a single malware component, OkoBot uses specialized modules that target different types of sensitive data and user activity. Kaspersky identified more than 20 malicious payloads and implants, enabling the framework to perform multiple functions on compromised Windows endpoints.
Browser compromise
Hidden Chromium-based browser extensions
Browser cookie theft
Browser credential harvesting
These modules focus on capturing authentication data and maintaining visibility into browser activity.
Credential and identity theft
Stored credential theft
Password manager data collection
Clipboard monitoring
Keylogging
Together, these capabilities increase the risk of account compromise by collecting credentials entered or stored on the device.
Cryptocurrency targeting
SeedHunter modules
Ledger wallet targeting
Trezor wallet targeting
Recovery seed phrase theft
Unlike generic infostealers, OkoBot includes dedicated components designed to target cryptocurrency wallets and recovery information.
Endpoint surveillance
Screenshot capture
Spyware modules monitoring user activity
Collection of system and application information
These modules provide attackers with additional visibility into user activity while collecting screenshots, application information, and other sensitive data from compromised endpoints.
What security teams should prioritize during investigation
If OkoBot activity is suspected, security teams should prioritize evidence that aligns with the framework’s documented infection chain and post-compromise behavior.
Review software downloaded from GitHub repositories impersonating legitimate tools, especially developer and administrative applications.
Look for unauthorized Chromium-based browser extensions or unexpected browser modifications on affected endpoints.
Examine SSH-related activity, including unexpected SSH installations, tunnels, or connections to external infrastructure.
Review browser credential stores, cookies, and password manager access for signs of unauthorized collection.
Search for Kaspersky-published indicators of compromise (IOCs), including file hashes, file paths, domains, and IP addresses.
Rotate exposed credentials and recovery phrases if compromise is confirmed or strongly suspected.
Featured resource
Cybersecurity kit
Build a stronger cybersecurity strategy with practical frameworks, checklists, policies, and enterprise security guidance.
While vendor guidance should remain the primary source for investigating and remediating OkoBot malware incidents, organizations can strengthen their endpoint security posture with layered controls.
With Hexnode UEM, administrators can enforce application control policies, maintain device compliance, and remotely execute management actions to remediate managed endpoints. Organizations can use compliance policies and Conditional Access integrations, such as Microsoft Entra ID, to restrict access from non-compliant
Hexnode XDR complements these efforts by providing endpoint visibility into suspicious activity and supporting incident investigation and remediation workflows on managed Windows devices.
Together, these capabilities help organizations contain affected endpoints and strengthen defenses against malware campaigns that rely on social engineering and compromised endpoints, without replacing vendor-specific remediation guidance.
Conclusion
OkoBot malware combines ClickFix attacks, fake GitHub repositories, and modular tooling to increase the risk of credential theft and endpoint compromise. Its specialized components target browsers, password managers, and cryptocurrency wallets, making investigations more challenging.
Organizations should look beyond patching by strengthening software trust, browser security controls, endpoint visibility, and credential hygiene. Combining these controls with timely investigation and published indicators of compromise can help reduce exposure to campaigns that rely on trusted platforms and user interaction.
Strengthen endpoint defenses before attackers adapt
Protect managed devices with visibility, policy enforcement, and rapid response workflows.
Organizations whose employees download software from online repositories or regularly use developer tools, browsers, password managers, and cryptocurrency wallets face a higher risk if users unknowingly install trojanized applications.
Does OkoBot target only cryptocurrency users?
No. While OkoBot includes modules targeting cryptocurrency wallets, it also steals browser credentials, cookies, password manager data, and other sensitive information, making it relevant to enterprise environments.
Does the OkoBot campaign exploit a software vulnerability?
Current public reporting indicates OkoBot primarily relies on ClickFix social engineering and fake GitHub repositories to gain initial access rather than exploiting a specific software vulnerability.
A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.