OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter) — Threadlinqs Intelligence
As of 2026-07-15, OkoBot: Multi-Stage Malware Framework Targeting Cryptocurrency Wallets (TookPS/HDUtil/Volume2/SeedHunter) is a critical-severity malware threat attributed to a Russia-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 45 indicators of compromise.
Threat ID: TL-2026-1363 · Severity: CRITICAL · Status: ACTIVE · Category: MALWARE
Attribution: Russia · FINANCIAL
Kaspersky Securelist details OkoBot, a modular Windows infection chain (TookPS downloader, HDUtil launcher, Volume2 plugin dispatcher, SeedHunter, MC Keylogger, OkoSpyware) that harvests browser data,
OkoBot is a modular cryptocurrency-theft framework tracked by Kaspersky since a March 2025 TookPS downloader campaign. Initial access is achieved via ClickFix social-engineering lures and trojanized software distributed through GitHub, most notably a legitimate copy of Audacity recompiled with a malicious implant and repackaged to impersonate SQL Server Management Studio (SSMS) so it surfaces in search-engine results. TookPS is a malicious PowerShell downloader (detected by Kaspersky as Trojan-Downloader.Win32.TookPS) that establishes outbound SSH connections, forwards SSH daemon ports, and schedules tasks (including a persistence task named 'Apple Sync' that re-establishes a reverse SSH tunnel hourly) to pull down further payloads and exfiltrate data over SFTP.
In the April 2025 redesign, TookPS delivers HDUtil, a VMProtect-packed auxiliary launcher retrieved over SFTP. HDUtil enumerates the host (active sessions, graphics adapters) and executes further modules via a 'target' command. It performs privilege escalation using a 2019 Project Zero-documented UAC bypass abusing Windows RPC and the auto-elevated msconfig.exe binary, and can enable RDP access by modifying the firewall, adding accounts to the Remote Desktop Users group, and patching termsrv.dll to allow concurrent RDP sessions. Each infected host is fingerprinted using an MD5 HWID hash cached at %PROGRAMDATA%\hwid.dat, which also doubles as the RC4 key used to encrypt exfiltrated wallet seed-phrase backups.
By March 2026 the actor streamlined the chain: TookPS and HDUtil were dropped in favor of deploying Volume2 directly. Volume2 is a legitimate open-source volume-control utility whose DLL search order is hijacked with a malicious protobuf.dll (later renamed version.dll) that acts as the framework's plugin dispatcher. It decrypts and loads implants using AES-GCM, then communicates outbound over HTTP with AES-CBC-encrypted JSON, polling its C2 roughly every 20 seconds for tasking.
Volume2 injects several second-stage implants into legitimate processes: ext_daemon, a browser-extension loader functionally identical to extl.exe that installs a malicious extension (associated with the Rilide family, advertised on Russian-language cybercrime forums) into Chromium-based browsers (Chrome, Edge, Brave) to steal session data and credentials; SeedHunter, which specifically targets Trezor Suite and Ledger Wallet/Live desktop applications plus Exodus and Litecoin QT to locate and exfiltrate wallet seed phrases and keystore material; MC Keylogger, which captures keystrokes, clipboard contents, connected USB device metadata, and periodic screenshots; and OkoSpyware, which uses a bundled FFmpeg binary to record screen video and keystrokes specifically while cryptocurrency wallet applications or KeePassXC/1Password password-manager windows are in focus. Exfiltrated artifacts (keylogs, screenshots, video recordings) are uploaded via HTTP POST to an ir-post.php endpoint on operator infrastructure.
Infrastructure is geoblocked so victim traffic originating from Russia and CIS countries is rejected, and SeedHunter's source contains Russian-language developer comments, together suggesting a Russian-speaking threat actor; Kaspersky stops short of formal attribution to a named group. Victims cluster heavily in Brazil, Vietnam, Canada, Mexico, and Turkiye, with hundreds of confirmed infections across more than 25 countries during the January-June 2026 active phase.
Weaknesses (CWE)
CWE-506, CWE-427, CWE-269, CWE-311
Target sectors: cryptocurrency, finance, individual-consumers, fintech
Target regions: brazil, vietnam, canada, mexico, Turkiye, Latin America, North America, Southeast Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 45 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, CRITICAL, threat intelligence, cybersecurity, T1566, T1189, T1059.001, T1059.003, T1053.005, T1053.005, T1136.001, T1133, T1176, T1548.002