Kabaski disclosed that a malicious software called OkoBot has been active for more than a year, with the main objective of stealing encrypted wallets and login vouchers. According to researchers, this chain of attacks consists of approximately 20 modules and victims have been identified in Brazil, Viet Nam, Canada, Mexico and Turkey.
Concealed software disseminated by GitHub
According to the researchers, the attackers disguised the malicious program as normal software distribution, including an installation package that impersonated Microsoft SQL Server Management Studio. One of the transmission channels is the GitHub code warehouse.
OkoBot also combines CrickFix social work. The victim will see a false tip, verify or repair and be directed to execute the order on his/her equipment. Once the order is running, the malicious program will be installed without the knowledge of the user.
Fake-recovering page-targeting notes
In the identified module, SeedHunter displays a fake wallet to restore the interface and impersonates the pages of hardware wallets like Ledger and Trezor. If the user enters a recovery phrase on the page, the information is sent directly to the assailant.
Another module, MC Keyloger, records keyboard input and monitors clipboard contents, which can be used to intercept passwords, copied wallet addresses and other vouchers. The module, OkoSpyware, also tracks wallet passwords and records videos of open windows to further expand the disclosure of information.
Kabaski indicated that, once the assistive notes were leaked, the assailant could take over the corresponding wallet and transfer the assets. As block-chain transfers are often irreversible, stolen funds are often difficult to recover.
Developers and executives are targets.
It was also mentioned that similar ClickFix attacks had recently been used against encryption practitioners. According to CertiK, Lazarus had sent a forged online meeting invitation to executives of financial technology and encryption companies and had induced victims to post so-called repair or authentication orders in the MacOS terminal, thereby installing a stealth program.
In addition, the developers ' tools have become an entry point for attacks. TrapDoor, previously disclosed, has been disseminated through a poisoned software package, which targets encryption, DeFi, AI and security infrastructure developers and attempts to steal wallet data, API keys, cloud vouchers and SSH access rights.
Such cases show that the attackers no longer rely solely on a single fishing page, but instead combine disguised software, social workers ' directives and multi-module stealth tools to expand penetration of wallet assets and business systems.
