
OkoBot Hunts for Seed Phrases: How a Single Bot Drains Crypto Wallets
Kaspersky specialists have warned of a new threat: the malicious bot OkoBot steals seed phrases and account credentials from cryptocurrency wallets. Let us break down how this attack is built, why bots are dangerous in general, and how to keep your coins safe.
What Happened
Cybersecurity experts discovered a bot that distributes around 20 malicious programs for stealing account credentials and seed phrases. This bot targets cryptocurrency wallets specifically and has been operating unnoticed for more than a year.
This is not a one-off incident but an entire platform: a single controlling bot hands out tasks to dozens of auxiliary modules, each responsible for its own part of the attack.
What a Bot Is in Simple Terms
Before diving into the details, let us clarify the term. A bot is a program that performs actions automatically, without human involvement. A useful bot answers questions or collects data, while its malicious version steals information.
In essence, any such program is an executor of commands. The only difference is who issues those commands and for what purpose such bots are launched.
Good Bots and Bad Bots
Not every bot is dangerous. Search bots index websites, chatbots help with support, trading bots track the exchange rate. Such bots work for the benefit of people.
But there are also malicious bots, created for theft and deception. It is exactly to this category that OkoBot belongs: behind the facade of an ordinary bot hides one of the most malicious tools for draining wallets.
How a Bot Gets Onto a Device
To launch the bot onto victims' devices, attackers use the ClickFix attack - a social engineering technique in which a user is tricked into running a malicious command. After that, the bot entrenches itself in the system.
The second route is fake GitHub repositories disguised as legitimate applications but containing a set of malicious programs. A user downloads a supposedly useful utility, and along with it a bot slips onto the computer.
The Fake Software Story
One of the repositories offered the SQL Server Management Studio tool. But under its guise, an infected version of the Audacity audio editor was being distributed with a Trojan hiding a bot inside.
Such infected files are a classic bait. The victim is sure they are installing the software they need, but in reality they launch a bot into their own system themselves.
The TookPS Script: The First Stage
Hidden inside was a PowerShell script called TookPS. It is what launches the whole chain and prepares the ground for the remaining bots.
TookPS is used at the first stage to install and configure an SSH bot. This bot deploys the package of malicious programs, opening the door to a whole army of other pests.
What the SSH Bot Collects
The SSH bot conducts reconnaissance. It gathers data about the username, the antivirus, the IP address, and the operating system version, in order to tailor the attack to the specific machine.
In addition, this bot disables Windows Defender notifications and quietly collects data on crypto wallets, browser cookie files, and accounts. After the reconnaissance, a narrowly specialized bot steps in.
The ext daemon Module
The first of this set of malicious programs is ext daemon. This bot embeds itself into the Chrome browser and quietly installs the Rilide extension.
It is one of the most malicious extensions: it targets the collection of account credentials, cookie files, financial information, and crypto-related data. The user notices nothing, while the bot is already gathering everything valuable.
The SeedHunter Module: The Hunt for the Seed Phrase
The most dangerous of the malicious modules in the bundle is SeedHunter. It embeds itself into the Trezor, Ledger Wallet, and Ledger Live hardware wallets.
This bot's job is to show a fake screen at the moment the seed phrase is being restored. The victim enters the words, thinking they are dealing with the real app, while the bot intercepts them and passes them to the attackers.
The MC Keylogger Module
Another bot, MC Keylogger, records keystrokes and clipboard activity. This includes copied text, images, and file paths.
This bot can also monitor USB connections and take screenshots every five minutes. In effect, the bot sees everything that happens on the device.
The OkoSpyware Module
The last bot, OkoSpyware, tracks passwords for cryptocurrency wallets. To do this, the bot uses FFmpeg - it records video from the screen and intercepts keystrokes.
Such a set of malicious functions turns a computer into a transparent display case: any user action comes under surveillance, while the malicious bot assembles the full picture.
Why the Bot Has So Many Modules
OkoBot's strength lies in its modularity. Instead of one bulky pest, the attackers assembled a construction kit in which each bot is responsible for a narrow task. One module steals passwords, another captures the screen, a third watches the clipboard.
This approach makes the bot flexible and resilient. If the antivirus finds one module, the rest keep working, and the operator quickly swaps the detected component for a new one. That is exactly why a modern pest is rarely a loner - behind it there is always a whole set of modules.
What the Theft of a Seed Phrase Threatens
If attackers get hold of the seed phrase, they gain full access to the victim's crypto assets. Data theft of this level is almost always irreversible.
In this case, hackers usually move the funds to addresses they control. Recovering the stolen cryptocurrency after such an attack is practically impossible.
How to Tell a Bot Is Already in the System
Spotting a bot is not easy, but there are indirect signs. The computer starts to slow down, the fan makes noise for no reason, and the antivirus has suddenly switched off - all of this is a reason to suspect an infection. Sometimes the pest gives itself away with strange network activity: the device sends data somewhere, even though you have launched nothing.
The problem is that a good bot disguises itself as system processes. A user may not suspect for months that a spy is working alongside them, calmly collecting seed phrases. That is why regular system checks matter more than the hope of spotting a threat by eye.
Who Is at Risk
According to Kaspersky, most of the affected users are in Brazil, Vietnam, Canada, Mexico, and Turkey. The exact amount of stolen funds is not disclosed.
A curious detail: access to the servers hosting the scripts for the initial stage of the attack is blocked for IP addresses from Russia and the CIS countries. This is a typical signature, when the operators of the pest avoid attention in their own region.
Who Is Behind Such Attacks
Behind malicious bots there are almost always organized groups rather than lone enthusiasts. Development, distribution, and cashing out are often divided among different participants: some write the code, others rent the infrastructure, still others launder the cryptocurrency. Such specialization puts the attacks on a conveyor belt.
Often such tools are sold or leased under a "malware as a service" model. A buyer without deep technical knowledge gets a ready-made control panel and launches their own campaign. That is precisely why the number of attacks is growing: the barrier to entry for newcomers has dropped sharply, and the profit from a single successful seed-phrase theft can pay off months of work.
This Is Not the First Case
Last year, ScamSniffer experts uncovered a similar fraud tactic involving the theft of seed phrases from users of the Phantom Wallet. Hackers created pop-up windows for an "extension update."
After approval, the victim was prompted to enter the seed phrase - and it went straight to the bots. The scheme is almost the same as OkoBot's, just with a different set of pests.
Why Bots Are So Dangerous
The main threat of bots is automation and scale. A single operator controls thousands of infected machines, and a network of such devices forms a botnet. A botnet works around the clock and never tires.
That is exactly why hacking a single password is often enough for a hacker to let the bots reach the wallet. The speed at which the bots act leaves the victim no time to react.
The Flip Side of Automation
Any automation has its pluses and minuses. Its plus is that useful bots save time and effort: they monitor the market, answer questions, and safeguard systems.
The minus is that the same technologies are used by criminals. That same work-accelerating tool, in the hands of malicious operators, turns into a weapon, and an army of bots strikes thousands of people at once.
Network Scanners and Identity Theft
A separate problem is internet bots that mass-scan the network in search of vulnerabilities. Such network bots serve as reconnaissance for future attacks.
Their main goal is the theft of personal data: passwords, keys, payment information. What is collected is passed by such a bot to the operators, who then monetize the stolen goods.
Why a Hardware Wallet Is Not a Cure-All
Many are convinced that a hardware wallet protects against any threat. This is partly true: the private key does not leave the device, and stealing it remotely is difficult. But the SeedHunter story reveals the weak spot - the human.
If the user enters the seed phrase into a fake window themselves, no hardware will save them. Fraudsters strike not at the device but at trust and inattention. That is why a hardware wallet reduces the risks but does not cancel out the basic rules of digital hygiene.
How to Protect Your Crypto Assets
Now about protection. To keep the wallet safe, never enter the seed phrase on websites or in pop-up windows - a real device does not ask for it just like that.
Download programs only from official sources and verify repositories. A hardware wallet, offline storage of the seed phrase, and attention to detail sharply reduce the chance that bots will reach your coins.
Passwords and Basic Digital Hygiene
An additional barrier is a strong password and two-factor authentication. It will not save you from seed phishing directly, but it will complicate the bots' work in other areas.
Regularly update your system and antivirus, do not disable protective notifications, and do not run commands from unverified instructions. These simple rules cut off most such attacks.
What to Do If a Bot Has Already Stolen Data
If there is a suspicion that a bot has reached the wallet, you need to act immediately. Move the assets to a new wallet with a new seed phrase created on a clean device - the pest may already have compromised the old seed phrase.
Then fully scan the system with an antivirus or reinstall it: as long as the infection remains in memory, any new wallet will again be under threat. Remember that one infected module often opens the door to others, so you need to clean the machine entirely.
A Daily Security Checklist
A short list of habits helps reduce the risk to a minimum. Keep the seed phrase offline only and never photograph it. Download wallets and utilities exclusively from official websites, and ignore links from chats and emails.
Check the recipient's address in full, enable two-factor authentication wherever possible, and do not install browser extensions without a real need. Finally, update your system regularly: fresh patches close the holes through which the infection most often creeps in.
Conclusion
The OkoBot story shows how sophisticated modern families of malicious programs and bots have become. One controlling bot, dozens of modules, and a single goal - your seed phrases and the coins in your wallet.
You cannot fully insure yourself, but awareness and basic digital discipline work better than any antivirus. Keep the seed phrase offline, do not trust pop-up windows, and remember: where there is cryptocurrency, there will always be bots ready to steal it at the first slip. Caution and a couple of basic habits save far more than a lost wallet is worth.
What is OkoBot?
OkoBot is a malicious bot discovered by Kaspersky specialists. It distributes around 20 malicious programs that steal seed phrases and account credentials from cryptocurrency wallets, and it had been operating unnoticed for more than a year. It is not a single pest but a platform: one controlling bot hands out tasks to dozens of auxiliary modules.
How does OkoBot get onto a device?
Two main routes. The first is the ClickFix attack - a social engineering technique in which a user is tricked into running a malicious command. The second is fake GitHub repositories disguised as legitimate applications: for example, under the guise of SQL Server Management Studio, an infected version of the Audacity audio editor was distributed with a Trojan inside.
What does the SeedHunter module do?
SeedHunter is the most dangerous module in the bundle. It embeds itself into the Trezor, Ledger Wallet, and Ledger Live wallets and shows a fake screen at the moment the seed phrase is being restored: the victim enters the words, thinking they are dealing with the real app, while the bot intercepts them and passes them to the attackers.
Does a hardware wallet protect against OkoBot?
Only partly. The private key does not leave the device, and stealing it remotely is difficult. But if the user enters the seed phrase into a fake window themselves, no hardware will save them - the attack targets trust and inattention, not the device. A hardware wallet reduces the risks but does not cancel out the basic rules of digital hygiene.
What should I do if a bot has already stolen my data?
Act immediately: move the assets to a new wallet with a new seed phrase created on a clean device, because the old seed phrase may already be compromised. Then fully scan the system with an antivirus or reinstall it - as long as the infection remains in memory, any new wallet will again be under threat.
Crypto markets expert and head of content and marketing at EIDEX. Covers market structure, exchange infrastructure and cross-chain trading - turning on-chain data and market shifts into clear, actionable research for traders.


