Sophia
Hart

OkoBot Malware Uses ClickFix and Fake GitHub Repositories

Sophia Hart

Jul 17, 2026

6 min read

okobot malware

TL; DR

  • Kaspersky identified OkoBot as a modular malware framework evolved from TookPS, with initial infections primarily delivered through ClickFix attacks and fake GitHub repositories.
  • Its modules steal browser credentials, cookies, password manager data, cryptocurrency wallet seed phrases, and other sensitive information from Windows endpoints.
  • Kaspersky detected hundreds of victims across more than 25 countries, highlighting the campaign’s broad geographic reach.
  • Organizations should strengthen endpoint security, restrict untrusted software, and investigate systems using published indicators of compromise.

Trusted software platforms are increasingly being abused to distribute malware. A newly identified malware framework called OkoBot combines ClickFix attacks, fake GitHub repositories, and a staged infection chain to compromise Windows systems and steal sensitive data.

According to Kaspersky, OkoBot evolved from the previously documented TookPS campaign and uses a modular architecture to deploy more than 20 malicious payloads. Observed modules harvest browser credentials, cookies, password manager data, cryptocurrency wallet seed phrases, and other sensitive information. Researchers also identified components that install hidden Chromium-based browser extensions and capture keystrokes.

For organizations, the campaign highlights how trusted developer platforms and social engineering can increase the risk of credential theft and endpoint compromise, reinforcing the need for stronger software trust and endpoint security controls.

Achieve unified threat management with Hexnode XDR

Why OkoBot represents more than another Infostealer

Unlike traditional infostealers, OkoBot uses a modular architecture that enables attackers to deploy multiple malicious components throughout an attack.

  • Modular framework: Kaspersky identified more than 20 malicious payloads and implants with specialized functions.
  • Expanded capabilities: Observed components support credential theft, browser compromise, keylogging, spyware, and cryptocurrency wallet targeting.
  • Flexible deployment: Attackers can deploy additional components after the initial compromise instead of relying on a single malware executable.
  • More complex investigations: Security teams may need to identify multiple implants, review endpoint activity, and correlate published indicators of compromise (IOCs) to determine the full scope of an infection.

How the campaign gains a foothold

The OkoBot campaign begins with social engineering rather than software exploits. Kaspersky observed two primary delivery methods: ClickFix attacks, which trick users into executing malicious commands, and fake GitHub repositories masquerading as legitimate software downloads. Both techniques rely on users trusting familiar platforms and completing the infection themselves.

One repository impersonated Microsoft SQL Server Management Studio (SSMS) but instead delivered a trojanized version of Audacity containing a malicious implant. The repository mimicked official installation guidance and ranked highly in search results, making it appear legitimate to unsuspecting users.

Observed infection stages

Stage Observed Activity Operational Priority
Initial lure ClickFix attack or fake GitHub repository Block execution and educate users
Initial execution TookPS PowerShell downloader runs Investigate the endpoint immediately
Host preparation SSH tunnel configured and system profiled Review endpoint telemetry
Framework deployment OkoBot modules delivered Isolate the affected device
Data targeting Credential and wallet theft modules activated Rotate credentials and assess exposure

What the payload ecosystem reveals

Rather than relying on a single malware component, OkoBot uses specialized modules that target different types of sensitive data and user activity. Kaspersky identified more than 20 malicious payloads and implants, enabling the framework to perform multiple functions on compromised Windows endpoints.

Browser compromise

  • Hidden Chromium-based browser extensions
  • Browser cookie theft
  • Browser credential harvesting

These modules focus on capturing authentication data and maintaining visibility into browser activity.

Credential and identity theft

  • Stored credential theft
  • Password manager data collection
  • Clipboard monitoring
  • Keylogging

Together, these capabilities increase the risk of account compromise by collecting credentials entered or stored on the device.

Cryptocurrency targeting

  • SeedHunter modules
  • Ledger wallet targeting
  • Trezor wallet targeting
  • Recovery seed phrase theft

Unlike generic infostealers, OkoBot includes dedicated components designed to target cryptocurrency wallets and recovery information.

Endpoint surveillance

  • Screenshot capture
  • Spyware modules monitoring user activity
  • Collection of system and application information

These modules provide attackers with additional visibility into user activity while collecting screenshots, application information, and other sensitive data from compromised endpoints.

What security teams should prioritize during investigation

If OkoBot activity is suspected, security teams should prioritize evidence that aligns with the framework’s documented infection chain and post-compromise behavior.

  • Review software downloaded from GitHub repositories impersonating legitimate tools, especially developer and administrative applications.
  • Look for unauthorized Chromium-based browser extensions or unexpected browser modifications on affected endpoints.
  • Examine SSH-related activity, including unexpected SSH installations, tunnels, or connections to external infrastructure.
  • Review browser credential stores, cookies, and password manager access for signs of unauthorized collection.
  • Search for Kaspersky-published indicators of compromise (IOCs), including file hashes, file paths, domains, and IP addresses.
  • Rotate exposed credentials and recovery phrases if compromise is confirmed or strongly suspected.
cybersecurity-kit
Featured resource

Cybersecurity kit

Build a stronger cybersecurity strategy with practical frameworks, checklists, policies, and enterprise security guidance.

DOWNLOAD

Strengthening endpoint defenses with Hexnode

While vendor guidance should remain the primary source for investigating and remediating OkoBot malware incidents, organizations can strengthen their endpoint security posture with layered controls.

With Hexnode UEM, administrators can enforce application control policies, maintain device compliance, and remotely execute management actions to remediate managed endpoints. Organizations can use compliance policies and Conditional Access integrations, such as Microsoft Entra ID, to restrict access from non-compliant

Hexnode XDR complements these efforts by providing endpoint visibility into suspicious activity and supporting incident investigation and remediation workflows on managed Windows devices.

Together, these capabilities help organizations contain affected endpoints and strengthen defenses against malware campaigns that rely on social engineering and compromised endpoints, without replacing vendor-specific remediation guidance.

Conclusion

OkoBot malware combines ClickFix attacks, fake GitHub repositories, and modular tooling to increase the risk of credential theft and endpoint compromise. Its specialized components target browsers, password managers, and cryptocurrency wallets, making investigations more challenging.

Organizations should look beyond patching by strengthening software trust, browser security controls, endpoint visibility, and credential hygiene. Combining these controls with timely investigation and published indicators of compromise can help reduce exposure to campaigns that rely on trusted platforms and user interaction.

FAQs

Organizations whose employees download software from online repositories or regularly use developer tools, browsers, password managers, and cryptocurrency wallets face a higher risk if users unknowingly install trojanized applications.

No. While OkoBot includes modules targeting cryptocurrency wallets, it also steals browser credentials, cookies, password manager data, and other sensitive information, making it relevant to enterprise environments.

Current public reporting indicates OkoBot primarily relies on ClickFix social engineering and fake GitHub repositories to gain initial access rather than exploiting a specific software vulnerability.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.