OkoBot: new sophisticated malware framework targets cryptocurrency users
Kaspersky identified OkoBot, a sophisticated multi-stage malware framework delivered via the TookPS PowerShell downloader and orchestrated over an attacker-controlled SSH tunnel, targeting cryptocurrency users. The framework comprises over 20 interconnected payloads that perform UAC bypass, RDP hijacking, browser-extension based credential theft (Rilide), hardware-wallet seed-phrase phishing (SeedHunter), keylogging, and screen/video capture (OkoSpyware), all coordinated through a plugin dispatcher communicating over HTTP/HTTPS C2 channels. The campaign has been active since at least March 2025, continues to evolve its tooling, and shows indicators (geoblocking, Russian code comments, use of Rilide) consistent with Russian-speaking cybercriminal operators.
- domain2baserec2[.]guruTookPS downloader C2/hosting domain for initial malicious PowerShell script
- domaincoffeesaloon[.]onlineTookPS downloader C2/hosting domain
- domainkbeautyreviews[.]comTookPS downloader C2/hosting domain
- domainlivewallpapers[.]onlineC2 server used by the Volume2 plugins dispatcher
- domainmoonsand[.]storeC2 server used by the SeedHunter module to phish hardware wallet seed phrases and exfiltrate stolen data
- domainrecavb22[.]onlineTookPS downloader C2/hosting domain
- domainthatwascringe[.]comC2 server used by the Volume2 plugins dispatcher
- ip104[.]243[.]32[.]213SSH bot back-connection infrastructure used to deliver malicious modules via SFTP
- ip104[.]243[.]43[.]16SSH bot back-connection infrastructure used to deliver malicious modules via SFTP
- ip62[.]210[.]188[.]209SSH bot back-connection infrastructure used to deliver malicious modules via SFTP
- md511dbc8a2bea04b15f8f68f3f01e8faf9extl.exe - browser extension loader/DLL injector delivering the Rilide stealer
- md5187a1f68ae786e53d3831166dc84e6d2protobuf.dll - malicious plugins dispatcher loader
- md52157d2429124ad28db7a26f2477cb985Plugins dispatcher environment enumerator plugin
- md53d2b43f91f65bfbf36a9c71b6b418876ext_daemon.exe - browser extension loader implant delivered via process injector
- md570fef9fd6e351f4d53cfeee8dcdfcd99seedhunter_x64.exe - hardware wallet seed-phrase phishing implant
- md57306885bb4c98f2a9f056104cf092bc9Plugins dispatcher PowerShell wrapper plugin
- md577cecf5e2a622ae07d8ae9913457ab57Plugins dispatcher dropper plugin used to fetch/execute additional payloads
- md583e6b8fcb92a0b13e109301f8ff649cfversion.dll - renamed protobuf.dll dispatcher loader (post-March 2026)
- md5ac93a821617aea1f56d4bc0bef4af327HDUtil.exe - SSH bot launcher utility used to deploy modules and perform UAC bypass
- md5acd31c9941b6c1cabd4e45e6877b9038keylog_x64.dll - MC Keylogger implant capturing keystrokes, clipboard, screenshots
- md5b07d451ee65a1580f20a784c8f0e7a46protobuf.dll - malicious plugins dispatcher loader
- md5b4c2e16cdb513be4dc798f88e2527334Plugins dispatcher CMD wrapper plugin
- md5d84e8dc509308523e0209d3cd3544619protobuf.dll - malicious plugins dispatcher loader
- md5dd52f5108a176c62ad807c327734ad12oko.dll - OkoSpyware implant capturing video and keystrokes of targeted wallet/password manager windows
- md5e0c3bc27a65750e740c4f1719e531c7dPlugins dispatcher process injector plugin
Detection / HunterAnthropic
What Happened
Security researchers discovered a large, sophisticated hacking toolkit called OkoBot that specifically targets people who use cryptocurrency wallets. Victims are tricked into running fake or trojanized software downloads (like a fake database management tool posted on GitHub, or 'ClickFix' scam pop-ups), which secretly install a remote-control connection on their computer. Once installed, attackers can remotely access the machine, install hidden malicious browser add-ons, log keystrokes, record video of wallet apps, and trick users into typing their wallet recovery phrases into fake screens, all with the goal of stealing cryptocurrency and other sensitive data. This has already affected hundreds of victims across more than 25 countries and is still actively being used and updated by the attackers. Individuals and organizations should avoid downloading software from unofficial sources, be suspicious of copy-paste 'fix it yourself' instructions from webpages, and never enter a hardware wallet recovery phrase into any website or unexpected prompt.
Key Takeaways
- OkoBot is a newly identified modular malware framework (20+ payloads) targeting cryptocurrency wallet users, delivered via the TookPS PowerShell downloader and orchestrated over an attacker-controlled SSH tunnel.
- Initial infection occurs via ClickFix social-engineering lures and trojanized software (a fake SQL Server Management Studio package on GitHub built from legitimate Audacity code with malicious code injected).
- The framework abuses a Windows RPC/msconfig.exe UAC bypass technique (documented by Project Zero in 2019) and patches termsrv.dll to enable concurrent RDP sessions for hands-on-keyboard access.
- Modules include a Chromium browser-extension loader that silently installs hidden malicious extensions (delivering the Rilide stealer), a hardware-wallet seed-phrase phisher (SeedHunter) targeting Trezor/Ledger, a keylogger, and a video/keystroke capture tool (OkoSpyware) aimed at crypto wallets and password managers.
- The campaign has been active for over a year (since March 2025), continues to evolve (e.g., protobuf.dll renamed to version.dll in March 2026), and geoblocks Russia/CIS IPs, suggesting Russian-speaking operators; victims span 25+ countries with concentration in Brazil, Vietnam, Canada, Mexico, and Türkiye.
Affected Systems
- Microsoft Windows (all versions supporting RDP/termsrv.dll patching)
- Chromium-based browsers (Google Chrome, Microsoft Edge)
- Cryptocurrency wallet software (Exodus, Litecoin QT, Trezor Suite, Ledger Wallet, Ledger Live)
- Password managers (KeePassXC, 1Password)
- End users/consumers searching for or downloading software such as SQL Server Management Studio
Vulnerabilities (CVEs)
None identified.
Attack Chain
- Initial Access: Victim runs a ClickFix lure or downloads trojanized software (e.g., a fake SSMS package on GitHub built from Audacity code) triggering the TookPS PowerShell downloader
- Establish Foothold: TookPS installs SSH, connects to an attacker-controlled SSH server, and forwards the local SSH daemon port; an automated SSH bot connects back and harvests system info, wallet files, and credentials
- Privilege Escalation & Persistence: SSH bot disables Windows Defender notifications, opens RDP firewall ports, adds a Remote Desktop Users account, patches termsrv.dll for multi-session RDP, and creates a scheduled task ('Apple Sync') to maintain a reverse SSH tunnel
- Payload Deployment: SSH bot retrieves modules over SFTP and executes them via the HDUtil launcher, using an optional UAC bypass (Windows RPC/msconfig.exe) for elevated execution
- Secondary Implants: Browser extension loader (extl.exe) injects into Chromium browsers to silently install the Rilide stealer; Volume2/plugins dispatcher decrypts and loads additional plugins (CMD/PowerShell wrappers, dropper, process injector) that deliver ext_daemon, SeedHunter, MC Keylogger, and OkoSpyware
- Collection & Exfiltration: Keylogger/OkoSpyware/SeedHunter capture keystrokes, screenshots, clipboard data, wallet seed phrases, and video of targeted wallet/password-manager windows; artifacts are sent to C2 endpoints (e.g., ir-post.php) and then deleted from disk, with command history cleared
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
- Platforms: Kaspersky Threat Intelligence Reporting service
The article states that a comprehensive IoC list and decryption scripts are available to customers of the Kaspersky Threat Intelligence Reporting service; no detection rule content (YARA/Sigma/Snort/KQL/etc.) is published in the public article itself.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Medium | Many stages (process injection into browsers, UAC bypass via msconfig.exe, DLL loading of protobuf.dll/version.dll, termsrv.dll replacement) are observable via process, module-load, and file-integrity telemetry if EDR has strong visibility into process injection, DLL loads, and file modifications in system directories; however, heavy VMProtect obfuscation and in-memory unpacking may evade static/signature detection. |
| Network Visibility | Medium | SSH tunneling, SFTP module delivery, and HTTP/HTTPS C2 beaconing every 20 seconds could be visible to network monitoring with TLS inspection or JA3/certificate fingerprinting, but encrypted payloads and generic-looking HTTPS traffic to newly registered domains may blend with normal traffic without domain reputation or DNS monitoring. |
| Detection Difficulty | Hard | The framework uses heavy VMProtect obfuscation, in-memory unpacking, HWID-gated execution to evade sandboxes, hash-based/pattern-based function resolution instead of static imports, AES-encrypted C2 traffic, and abuse of legitimate binaries (Volume2, patched Audacity, termsrv.dll), all of which complicate both static and behavioral detection. |
Required Log Sources
- Windows Security Event Logs (account creation, RDP logons - Event IDs 4624/4625/4720/4732)
- Sysmon Event ID 1 (process creation) and Event ID 7 (image/DLL load)
- Sysmon Event ID 3 (network connection) for SSH/SFTP and HTTP beaconing
- Scheduled Task creation logs (Event ID 4698)
- File integrity monitoring on System32 (termsrv.dll replacement)
- Browser extension installation/management logs
- DNS query logs for newly observed/low-reputation domains
- PowerShell script block logging (Event ID 4104)
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Look for termsrv.dll being replaced or modified outside of normal Windows Update activity, which would indicate an attempt to enable concurrent RDP sessions for unauthorized remote access. | File integrity monitoring / Sysmon Event ID 11 (file create) on System32\termsrv.dll | Persistence / Lateral Movement Enablement (T1021.001) | Low - legitimate modification of this system file is rare outside OS patching |
| Hunt for scheduled tasks with generic or unusual names (e.g., benign-sounding names unrelated to installed software) that execute SSH or tunneling binaries on an hourly cadence. | Event ID 4698 (scheduled task creation), Task Scheduler operational logs | Persistence (T1053.005) | Medium - some legitimate sync utilities use similar naming; verify binary path and command line |
| Investigate processes that spawn msconfig.exe followed shortly by an unsigned or unusual child process, which could indicate an auto-elevation UAC bypass technique. | Process creation and parent-child relationships (Sysmon Event ID 1) | Privilege Escalation (T1548.002) | Low - msconfig.exe spawning unrelated processes is uncommon in normal usage |
| Monitor for newly installed Chromium/Edge browser extensions that do not appear in the standard extension management UI or that are installed from non-default directories such as a custom 'Local Extension Settings' path. | Browser extension management logs, file system monitoring on %APPDATA% for .crx unpacking | Persistence / Collection (T1176) | Medium - requires baseline of legitimate extension installation paths in the environment |
| Hunt for repeated HTTP/HTTPS beaconing at a fixed short interval (approximately every 20 seconds) to external hosts, particularly from processes not typically associated with network communication (e.g., dispatcher-loaded DLLs). | Network connection logs, proxy logs, EDR network events tied to process ancestry | Command and Control (T1071.001) | Medium - some legitimate telemetry/heartbeat software uses similar short polling intervals |
Control Gaps
- Standard antivirus/signature-based detection is likely insufficient against VMProtect-protected, heavily obfuscated modules
- Search engine trust in top-ranked GitHub repositories can bypass user skepticism and basic download-source vetting controls
- Default UAC settings do not block auto-elevated binary abuse (msconfig.exe RPC bypass)
- Standard browser extension review/allowlisting may not catch extensions installed programmatically via hooked internal Chromium functions
Key Behavioral Indicators
- Presence of an HWID validation file (hwid.dat) in %PROGRAMDATA% or %APPDATA% used to gate malware execution
- Unexpected replacement or timestamp change of termsrv.dll enabling multiple concurrent RDP sessions
- Scheduled tasks maintaining recurring SSH/tunnel connections on an hourly basis
- DLL loads of a library masquerading as protobuf.dll or version.dll exporting an unusual function used to decrypt an embedded payload
- Creation of temporary files following naming patterns such as media_<timestamp>, sc_<timestamp>.jpg, bf_<timestamp>.jpg, oko_<timestamp>.json, or sh_<timestamp>.json
- Browser extensions installed into a non-default 'Local Extension Settings' directory rather than the standard Chromium extension path
False Positive Assessment
Medium - several detection indicators (scheduled tasks, DLL naming, browser extension installation paths, beaconing intervals) require environment-specific baselining to avoid false positives, as some legitimate software may exhibit superficially similar behaviors (e.g., legitimate sync tools, telemetry heartbeats, or extension management tools).
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting; if confirmed OkoBot activity is found, consider isolating the affected host from the network to prevent further data exfiltration and lateral RDP access.
- Consider auditing scheduled tasks and Remote Desktop Users group membership on potentially affected hosts for unauthorized entries.
- If your EDR/AV supports it, consider scanning for and quarantining unsigned DLLs impersonating protobuf.dll/version.dll and unexpected termsrv.dll modifications.
- Consider resetting credentials and rotating any cryptocurrency wallet seed phrases or private keys that may have been entered on a potentially compromised device.
Infrastructure Hardening
- Evaluate enforcing application allowlisting to prevent execution of unsigned or unknown launcher utilities such as HDUtil-style binaries.
- Consider restricting outbound SSH/SFTP connections from standard user workstations to only approved destinations where feasible.
- Evaluate whether RDP access can be restricted to VPN-only or jump-host architectures with MFA enforcement, where supported by your environment.
- Consider monitoring or blocking auto-elevated binaries (e.g., msconfig.exe) from spawning unexpected child processes via application control policies.
User Protection
- Consider deploying browser extension allowlisting/management policies to prevent silent installation of unauthorized extensions.
- Evaluate endpoint protection capable of detecting in-memory unpacking/injection behaviors rather than relying solely on static signatures.
- Consider enabling PowerShell script block logging and constrained language mode where applicable to increase visibility into downloader activity.
- If your organization issues hardware crypto wallets, consider providing guidance that seed phrases should never be entered into any software prompt or webpage.
Security Awareness
- Consider training users to verify software sources directly from official vendor websites rather than search engine results or third-party GitHub repositories, especially for tools like SQL Server Management Studio.
- Consider awareness training on 'ClickFix' style social engineering, where users are instructed to copy-paste and run commands from a webpage.
- Reinforce messaging that hardware wallet recovery/seed phrases should never be typed into any application, browser prompt, or 'recovery' tool.
- Consider periodic phishing/social-engineering simulations focused on fake software installation guides and crypto wallet recovery scams.
MITRE ATT&CK Mapping
Initial Access
Persistence
Privilege Escalation
Stealth
Credential Access
Lateral Movement
Collection
Command and Control
Exfiltration
Additional IOCs
- Urls:
github.com/ssms-cli/SSMS- GitHub repository masquerading as legitimate SSMS software; actually trojanized Audacity used for initial infectiongithub.com/ssms-cli/SSMS/releases/tag/20.2- GitHub release page hosting the trojanized installer used to deliver TookPS
- File Hashes:
B07D451EE65A1580F20A784C8F0E7A46(MD5) - protobuf.dll - malicious plugins dispatcher loader187A1F68AE786E53D3831166DC84E6D2(MD5) - protobuf.dll - malicious plugins dispatcher loaderD84E8DC509308523E0209D3CD3544619(MD5) - protobuf.dll - malicious plugins dispatcher loader83E6B8FCB92A0B13E109301F8FF649CF(MD5) - version.dll - renamed protobuf.dll dispatcher loader (post-March 2026)7306885BB4C98F2A9F056104CF092BC9(MD5) - Plugins dispatcher PowerShell wrapper pluginB4C2E16CDB513BE4DC798F88E2527334(MD5) - Plugins dispatcher CMD wrapper plugin2157D2429124AD28DB7A26F2477CB985(MD5) - Plugins dispatcher environment enumerator plugin77CECF5E2A622AE07D8AE9913457AB57(MD5) - Plugins dispatcher dropper plugin used to fetch/execute additional payloadsE0C3BC27A65750E740C4F1719E531C7D(MD5) - Plugins dispatcher process injector plugin3D2B43F91F65BFBF36A9C71B6B418876(MD5) - ext_daemon.exe - browser extension loader implant delivered via process injector70FEF9FD6E351F4D53CFEEE8DCDFCD99(MD5) - seedhunter_x64.exe - hardware wallet seed-phrase phishing implantACD31C9941B6C1CABD4E45E6877B9038(MD5) - keylog_x64.dll - MC Keylogger implant capturing keystrokes, clipboard, screenshotsDD52F5108A176C62AD807C327734AD12(MD5) - oko.dll - OkoSpyware implant capturing video and keystrokes of targeted wallet/password manager windowsAC93A821617AEA1F56D4BC0BEF4AF327(MD5) - HDUtil.exe - SSH bot launcher utility used to deploy modules and perform UAC bypass11DBC8A2BEA04B15F8F68F3F01E8FAF9(MD5) - extl.exe - browser extension loader/DLL injector delivering the Rilide stealer
- File Paths:
%USERPROFILE%\.ssh\go.bat- Script used by SSH bot to configure/maintain SSH tunnel persistence%PROGRAMDATA%\HDVideo\HDUtil.exe- Location of dropped HDUtil launcher module%PROGRAMDATA%\hwid.dat- HWID validation file checked by framework modules before execution%PROGRAMDATA%\oko_ver- Version marker file dropped by the OkoBot framework%TEMP%\extl.exe- Dropped browser extension loader/DLL injector executable%APPDATA%\hwid.dat- Alternate HWID validation file location used by framework modules
- Command Lines:
- Purpose: Execute a delivered module via the SSH-bot deployed launcher, optionally with automatic UAC bypass and background execution | Tools:
HDUtil.exe,msconfig.exe| Stage: Privilege Escalation / Execution |HDUtil.exe target [nouac [user=<user>]] [noattach] <file> - Purpose: Deploy the Volume2 plugins dispatcher module with elevated privileges and no attached console | Tools:
HDUtil.exe,Volume2.exe| Stage: Payload Deployment |HDUtil.exe target nouac noattach Volume2.exe - Purpose: Enumerate active graphical/RDP sessions on the compromised host for reconnaissance | Tools:
HDUtil.exe| Stage: Discovery |HDUtil.exe enumsessions
- Purpose: Execute a delivered module via the SSH-bot deployed launcher, optionally with automatic UAC bypass and background execution | Tools:
- Other:
Apple Sync- Scheduled task name created to maintain a reverse SSH tunnel forwarding the local RDP port hourly