OkoBot Malware Deploys ClickFix Browser Extensions to Harvest Crypto Wallet Credentials
What Happened — OkoBot, a malware family disclosed by Kaspersky, is delivered via a counterfeit installer named ClickFix. Once executed, ClickFix drops hidden browser extensions that sit inside popular crypto‑wallet browsers (Chrome, Edge, etc.) and silently record activity inside wallet applications, exfiltrating wallet files, seed phrases and passwords.
Why It Matters for Compliance & Audit Readiness —
- The attack bypasses weak logical‑access controls, directly violating SOC 2 CC6.1 (Logical Access) requirements.
- Continuous monitoring of endpoint and browser‑extension activity is essential to produce defensible audit evidence of access‑control effectiveness.
- Security‑awareness training that warns users against installing unverified software is a critical control to reduce credential‑compromise risk.
Who Is Affected — Crypto‑exchange platforms, digital‑wallet providers, fintech services, and individual cryptocurrency investors.
Recommended Actions — Map the incident to SOC 2 access‑control criteria, enforce MFA for wallet access, block installation of unsigned browser extensions, implement continuous endpoint‑monitoring for anomalous extensions, and run targeted security‑awareness drills on malicious‑software social engineering. Source: https://hackread.com/okobot-malware-clickfix-browser-extensions-crypto-data/
Technical Notes — OkoBot uses the ClickFix dropper to install covert Chrome/Edge extensions that hook into wallet‑app processes, capturing seed phrases and password files. No public CVE is associated; the vector is a malicious software distribution campaign. Source: https://hackread.com/okobot-malware-clickfix-browser-extensions-crypto-data/