securelist · Crawled Jul 31, 2026
OkoBot: new sophisticated malware framework targets cryptocurrency users
38 IoCs
Read original article ↗
AI Summary
OkoBot is a sophisticated malware framework targeting cryptocurrency users, active since January 2026. It uses a multi-stage infection chain initiated by the malicious PowerShell script TookPS, delivered via fake software repositories or phishing. The framework deploys over 20 malicious payloads through an SSH tunnel, enabling UAC bypass, browser extension injection, keylogging, screen recording, and seed phrase theft from Ledger and Trezor wallets. The campaign remains active and has infected hundreds of victims across more than 25 countries, with evidence suggesting Russian-speaking threat actor involvement.
AI-extracted · verify before operational use
Indicators of Compromise 38 extracted
| Type | Value | Detail |
|---|---|---|
| MD5 | b07d451ee65a1580f20a784c8f0e7a46 | Details → |
| MD5 | 187a1f68ae786e53d3831166dc84e6d2 | Details → |
| MD5 | d84e8dc509308523e0209d3cd3544619 | Details → |
| MD5 | 83e6b8fcb92a0b13e109301f8ff649cf | Details → |
| MD5 | 7306885bb4c98f2a9f056104cf092bc9 | Details → |
| MD5 | b4c2e16cdb513be4dc798f88e2527334 | Details → |
| MD5 | 2157d2429124ad28db7a26f2477cb985 | Details → |
| MD5 | 77cecf5e2a622ae07d8ae9913457ab57 | Details → |
| MD5 | e0c3bc27a65750e740c4f1719e531c7d | Details → |
| MD5 | 3d2b43f91f65bfbf36a9c71b6b418876 | Details → |
| MD5 | 70fef9fd6e351f4d53cfeee8dcdfcd99 | Details → |
| MD5 | acd31c9941b6c1cabd4e45e6877b9038 | Details → |
| MD5 | dd52f5108a176c62ad807c327734ad12 | Details → |
| MD5 | ac93a821617aea1f56d4bc0bef4af327 | Details → |
| MD5 | 11dbc8a2bea04b15f8f68f3f01e8faf9 | Details → |
| Domain | 2baserec2[.]guru | Details → |
| Domain | recavb22[.]online | Details → |
| Domain | kbeautyreviews[.]com | Details → |
| Domain | coffeesaloon[.]online | Details → |
| Domain | livewallpapers[.]online | Details → |
| Domain | thatwascringe[.]com | Details → |
| Domain | moonsand[.]store | Details → |
| IP | 104[.]243[.]43[.]16 | Details → |
| IP | 104[.]243[.]32[.]213 | Details → |
| IP | 62[.]210[.]188[.]209 | Details → |
| Filename | %USERPROFILE%\.ssh\go.bat | Details → |
| Filename | %PROGRAMDATA%\HDVideo\HDUtil.exe | Details → |
| Filename | %PROGRAMDATA%\hwid.dat | Details → |
| Filename | %PROGRAMDATA%\oko_ver | Details → |
| Filename | %TEMP%\extl.exe | Details → |
| Filename | %APPDATA%\hwid.dat | Details → |
| MD5 | 77cecf5e2a62ae07d8ae9913457ab57 | Details → |
| MD5 | 70fef9fd6e35f4d53cfeee8dcdfcd999 | Details → |
| Filename | go.bat | Details → |
| Filename | HDUtil.exe | Details → |
| Filename | hwid.dat | Details → |
| Filename | oko_ver | Details → |
| Filename | extl.exe | Details → |