Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

OkoBot framework infection chain

0
Medium
Published: 07/15/2026 (07/15/2026, 11:58:10 UTC)
Source: AlienVault OTX General

Description

In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/15/2026, 22:03:27 UTC

Technical Analysis

The OkoBot malware framework uses a complex infection chain starting with TookPS PowerShell scripts delivered through ClickFix attacks or fake GitHub software. An automated SSH bot deploys multiple malicious modules such as HDUtil launcher, browser extension injectors that install the Rilide stealer, SeedHunter for wallet seed phrase theft, and OkoSpyware for window capture. The framework employs VMProtect obfuscation and UAC bypass techniques to evade detection and maintain persistence through RDP access and scheduled tasks. The campaign targets cryptocurrency users and has affected victims in over 25 countries, notably Brazil, Vietnam, Canada, Mexico, and Turkey. Russian language artifacts and geoblocking patterns suggest Russian-speaking threat actors.

Potential Impact

The malware framework enables theft of cryptocurrency wallet seed phrases and other sensitive data, compromising victims' cryptocurrency holdings. It achieves persistence and stealth through obfuscation and UAC bypass, increasing the difficulty of detection and removal. The broad geographic distribution of victims indicates a widespread campaign with potential significant financial losses for affected users.

Defensive Guidance

No official patch or fix is available for this malware framework. Mitigation should focus on preventing initial infection by avoiding execution of untrusted PowerShell scripts and fake software, especially from GitHub or suspicious domains. Monitoring for unusual SSH and RDP activity and removing unauthorized scheduled tasks can help limit persistence. Use endpoint protection solutions capable of detecting obfuscated malware and browser extension injectors. Refer to vendor advisories and threat intelligence sources for updated detection signatures and mitigation techniques.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Author
AlienVault
Tlp
white
References
["https://securelist.com/okobot-framework-targets-cryptocurrency-wallets/120660/"]
Adversary
null
Pulse Id
6a5775d2afd24bb0357b62c1
Threat Score
null

Indicators of Compromise

Domain

ValueDescriptionCopy
domaincoffeesaloon.online
domainlivewallpapers.online
domain2baserec2.guru
domainkbeautyreviews.com
domainrecavb22.online
domainthatwascringe.com

Hash

ValueDescriptionCopy
hashb07d451ee65a1580f20a784c8f0e7a46
hash187a1f68ae786e53d3831166dc84e6d2
hashd84e8dc509308523e0209d3cd3544619
hash83e6b8fcb92a0b13e109301f8ff649cf
hash7306885bb4c98f2a9f056104cf092bc9
hashb4c2e16cdb513be4dc798f88e2527334
hash2157d2429124ad28db7a26f2477cb985
hash77cecf5e2a622ae07d8ae9913457ab57
hashe0c3bc27a65750e740c4f1719e531c7d
hash3d2b43f91f65bfbf36a9c71b6b418876
hash70fef9fd6e351f4d53cfeee8dcdfcd99
hashacd31c9941b6c1cabd4e45e6877b9038
hashdd52f5108a176c62ad807c327734ad12
hashac93a821617aea1f56d4bc0bef4af327
hash11dbc8a2bea04b15f8f68f3f01e8faf9

Threat ID: 6a58000568715ace438b1866

Added to database: 07/15/2026, 21:47:49 UTC

Last enriched: 07/15/2026, 22:03:27 UTC

Last updated: 08/15/2026, 04:14:37 UTC

Views: 248

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses