Kaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware

Kaspersky researchers have identified a new malware framework called OkoBot that targets cryptocurrency users across 25 countries. The framework uses sophisticated modules like OkoSpyware to steal seed phrases, credentials, and monitor browser activity.
Why it matters
The emergence of advanced infostealers targeting digital assets poses a significant threat to the security of the global cryptocurrency ecosystem.
At its recent annual Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region, Kaspersky Global Research and Analysis Team (GReAT) shared insights about the new OkoBot campaign targeting cryptocurrency users. The new sophisticated framework employs TookPS to exfiltrate seed phrases and uses a new OkoSpyware module to monitor Chromium-based browsers and deploy various malware strains, including the Rilide stealer. It has already targeted hundreds of victims across over 25 countries, with the highest number of affected end users recorded in Brazil, Vietnam, Canada, Mexico and Turkiye. According to Kaspersky experts, the threat remains active and primarily poses a risk to cryptocurrency users. In January 2026, experts from the Kaspersky Global Research and Analysis Team (GReAT) identified multiple attacks involving a previously unknown malware capable of capturing the contents of cryptocurrency wallet windows.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in