Kaspersky uncovers new malware framework targeting cryptocurrency users across 25 countries

Kaspersky has identified a new malware framework called OkoBot that targets cryptocurrency users across 25 countries. The framework uses sophisticated methods, including social engineering and browser-based spyware, to steal credentials and digital assets.
Why it matters
The emergence of comprehensive, multi-component malware frameworks highlights the increasing sophistication of cyber threats targeting the cryptocurrency ecosystem.
Kaspersky, a cybersecurity firm, has uncovered a sophisticated malware framework designed to steal cryptocurrency from unsuspecting users. The firm warns that the campaign remains active and has already affected hundreds of victims in more than 25 countries. The malware, dubbed OkoBot, is a previously undocumented framework comprising more than 20 malicious components capable of stealing cryptocurrency wallets, harvesting seed phrases, capturing keystrokes, recording videos, downloading malicious browser extensions and executing remote commands on infected devices. According to researchers from Kaspersky’s Global Research and Analysis Team (GReAT), the framework employs a tool known as TookPS to extract cryptocurrency wallet seed phrases while a newly identified OkoSpyware module monitors Chromium-based browsers and injects additional malware, including the Rilide banking trojan. The security firm said the campaign primarily targets cryptocurrency users, with the highest number of victims recorded in Brazil, Vietnam, Canada, Mexico and Türkiye.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in