← Back to Feed

OkoBot: new sophisticated malware framework targets cryptocurrency users

July 15, 2026 · Kaspersky (Securelist) · Severity: HIGH

In January 2026, Kaspersky identified a sophisticated malware framework, dubbed OkoBot, targeting cryptocurrency users. The malware captures cryptocurrency wallet contents and orchestrates attacks via an SSH tunnel, delivering over 20 malicious payloads, including TeviRAT, keyloggers, and stealers. The infection chain begins with the execution of the TookPS PowerShell script, which installs SSH on the victim’s machine and connects to an attacker-controlled server. The campaign is active and detected by Kaspersky products under various threat names, such as Trojan-Downloader.Win32.TookPS.* and Backdoor.Win32.TeviRat.*. Initial infections occur through ClickFix attacks or malware masquerading as legitimate software, such as a fake SQL Server Management Studio package distributed via GitHub. The OkoBot framework represents a significant evolution from previous TookPS campaigns, which began in March 2025. Unlike earlier versions, OkoBot automates payload delivery through an SSH bot, covering the full attack lifecycle from initial infection to data exfiltration. The malware harvests sensitive information, including cryptocurrency wallet files, browser cookies, and credentials, via an SSH tunnel. This campaign highlights the growing sophistication of cryptocurrency-targeted malware, posing a serious threat to users’ digital assets and privacy. The use of GitHub and search engine indexing to distribute malicious software further underscores the importance of vigilance when downloading and installing software.

Introduction

In January 2026, we identified multiple attacks involving unknown malware that captures the contents of cryptocurrency wallet windows. During the investigation, we reconstructed the complete infection chain, which consisted of four tightly linked stages initiated by the execution of the previously described malicious PowerShell script TookPS. However, this campaign differs from previous activity in that it uses a new framework to deliver all malicious modules and orchestrate them via an SSH tunnel. In total, the framework includes more than 20 malicious payloads and implants, covering a wide variety of functions. At the time of writing, the threat remains active.

Kaspersky’s products detect this threat as Trojan-Downloader.Win32.TookPS.*, Trojan.Win64.BypassUAC.*, Trojan-Banker.Script.Agent.gen, Trojan.Win32.Dllhijack.*, Backdoor.Win32.TeviRat.*, Trojan-PSW.Win64.Stealer.*, Trojan-Spy.Win64.Keylogger.*, Trojan-Spy.Win64.Agent.*, Trojan.Win64.Agent.*.

Background

TookPS is a downloader used for retrieving malicious commands and scripts from attacker-controlled servers to further propagate attacks. The first campaign using TookPS was discovered in March 2025. At that time, malicious scripts delivered a Python‑based infostealer along with a script that installed and configured an SSH tunnel on the victim’s machine. The next wave appeared in April 2025: the payload was changed, and TookPS was used to deliver the TeviRAT malware with the same SSH installer.

Then at the end of April 2025, TookPS underwent minor changes, yet its attack chain was completely redesigned. Unlike previous incidents, in this case, TookPS was used solely for the initial infection, with an automated SSH bot responsible for payload delivery. This new malicious campaign has multiple stages that cover the full attack lifecycle, from initial infection to persistence and data exfiltration. Among various malware strains, at one of the stages, the TeviRAT backdoor is delivered to the compromised host, ultimately fetching another version of a TookPS script.

We dubbed this updated TookPS campaign “OkoBot”.

Original OkoBot infection chain

Original OkoBot infection chain

We will break down this chain in greater detail later in the article. However, this is not the only version of OkoBot we were able to find. Already in March 2026, we discovered a new phase in the development of the framework, with Volume2 now being installed directly using TookPS. The HDUtil launcher → extl injector → Rilide chain was found to be abandoned in this newer version since it was replaced in full by the identical ext_daemon Volume2 plugin. TeviRAT was also removed, most likely because its functions were covered by the new plugins dispatcher.

New OkoBot infection chain

New OkoBot infection chain

Initial infection

The initial infection is primarily delivered through two vectors: a ClickFix attack, and malware distributed through GitHub that masquerades as legitimate software. One such example is the fake SQL Server Management Studio (SSMS) package distributed through GitHub. In fact, it is actually the legitimate Audacity — a popular audio editor — compiled with a malicious implant embedded in one of its libraries. Because the repository was indexed by most search engines and appeared at the top of the results for the query SSMS, the malware looked legitimate and quickly earned users’ trust.

Malicious application distribution report

Malicious application distribution report

This repository was created at the end of March 2025 and existed until June of that year. It consisted of a single file, README.md, which provided a fake SSMS installation guide written in an official style and likely derived from excerpts of Microsoft’s documentation. However, the download link for the program, located at the beginning of the guide, pointed to the latest release in the same repository.

Both infection vectors trigger the execution of the malicious script TookPS, which installs SSH on the victim’s system, establishes a connection to the attacker-controlled SSH server and subsequently forwards the SSH daemon port. Following a delay, an automated SSH bot connects to the forwarded port.

Back connection

The automated SSH bot collects system information such as usernames, antivirus software installed, the IP address, and OS version. It harvests cryptocurrency wallet files, browser cookies, profiles, and other credentials through an SSH tunnel. For subsequent delivery of

Key Takeaways

  • OkoBot is a sophisticated malware framework targeting cryptocurrency users with advanced techniques.
  • The malware focuses on stealing crypto assets, posing significant financial risks to victims.
  • Kaspersky's analysis reveals OkoBot's complexity, urging enhanced security for crypto transactions.
☕ Buy a Coffee