OkoBot Malware Framework Overview
OkoBot is a malware framework targeting Windows systems since April 2025, featuring over 20 payloads and implants. It includes the SeedHunter module…
OkoBot is a malware framework targeting Windows systems since April 2025, featuring over 20 payloads and implants. It includes the SeedHunter module…
SeedHunter is a module of the OkoBot framework that injects into legitimate wallet apps (Trezor Suite, Ledger Wallet, Ledger Live) to display…
TookPS is a PowerShell downloader used as the initial payload for OkoBot. It has been active since March 2025, delivered via fake…
Rilide is a Chromium-based information stealer used by Russian-speaking threat actors since April 2023. It is installed as a hidden browser extension…
OkoSpyware is a surveillance module within OkoBot that monitors for over 100 executables (e.g., Exodus, 1Password), records screens to MP4 using FFmpeg,…
MC Keylogger is a module in OkoBot that captures keyboard input, clipboard data, USB device activity, and takes screenshots every five minutes.
GlassWorm is a malware that uses USB device detection to trigger phishing windows on Windows systems, similar to SeedHunter but with a…
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws Ravie LakshmananJul 15, 2026Vulnerability / Browser Security Mozilla has released updates…
Thirteen malicious Firefox extensions are modified Rabby Wallet builds that exfiltrate serialized keyrings before local encryption, compromising wallet security.
Bootkitty is a UEFI bootkit that can be deployed by exploiting vulnerable UEFI shim bootloaders to bypass Secure Boot and gain persistent…