bleeping-computer · Crawled Jul 16, 2026
New OkoBot framework deploys 20 payloads to steal data, crypto
7 IoCs
Read original article ↗
AI Summary
A new malicious framework named OkoBot has been active since January 2026, delivering over 20 payloads to steal cryptocurrency wallet seed phrases, credentials, and sensitive data. It spreads via ClickFix attacks and malicious GitHub repositories hosting trojanized software. The infection chain begins with the TookPS PowerShell script, which installs an SSH bot to deploy further modules. Victims are primarily in Brazil, with secondary targets in Vietnam, Canada, Mexico, and Turkey, and evidence suggests the threat actor may be Russian-speaking due to geoblocking and code comments.
AI-extracted · verify before operational use