Nigeria Communications Week·3 min read·hard

Kaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware

Kaspersky Reveals a New Malicious Framework Targeting Cryptocurrency Users with the Use of OkoSpyware
AI Summary

Kaspersky researchers have identified a new malware framework called OkoBot that targets cryptocurrency users across 25 countries. The framework uses sophisticated modules like OkoSpyware to steal seed phrases, credentials, and monitor browser activity.

At its recent annual Cyber Security Weekend for the Middle East, Turkiye and Africa (META) region, Kaspersky Global Research and Analysis Team (GReAT) shared insights about the new OkoBot campaign targeting cryptocurrency users. The new sophisticated framework employs TookPS to exfiltrate seed phrases and uses a new OkoSpyware module to monitor Chromium-based browsers and deploy various malware strains, including the Rilide stealer. It has already targeted hundreds of victims across over 25 countries, with the highest number of affected end users recorded in Brazil, Vietnam, Canada, Mexico and Turkiye. According to Kaspersky experts, the threat remains active and primarily poses a risk to cryptocurrency users. In January 2026, experts from the Kaspersky Global Research and Analysis Team (GReAT) identified multiple attacks involving a previously unknown malware capable of capturing the contents of cryptocurrency wallet windows. Dubbed Okobot, the new sophisticated malware framework comprises more than 20 malicious payloads and implants designed to perform a wide range of functions, including collecting local files, executing remote commands, downloading arbitrary browser extensions, stealing cryptocurrency wallets, harvesting seed phrases and credentials, recording video and carrying out other malicious activities. One of the new implants used in the campaign is a loader that modifies browser memory to load and hide malicious extensions. OkoBot also includes a new OkoSpyware module, which captures keystrokes and the video stream of a target application’s window. Advertisement Currently available information does not allow the campaign to be attributed to any known crimeware actor with high confidence. However, the techniques and infostealer involved are widely used by Russian-speaking threat actors, and technical analysis has also revealed code artifacts in Russian. The initial infection typically occurs through two main vectors: ClickFix attacks, in which threat actors use social engineering to trick users into running malicious code, and malware distributed via GitHub under the guise of legitimate software. During the investigation, researchers identified one such case involving a fake installer for SQL Server Management Studio (SSMS), a widely used Microsoft database management tool. The malicious framework includes SeedHunter, a malware component that monitors active system processes and injects an implant into Trezor Suite, Ledger Wallet, and Ledger Live, – official applications used to manage cryptocurrency assets. When it detects a connected Trezor or Ledger hardware wallet, it triggers the hooked functions to display a hard-coded phishing page aimed at stealing the user’s seed phrase, using a distinct layout for each wallet type. “The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026. The observed infection vectors strongly suggest that developers are among its primary targets. Of particular concern is the malware’s continued evolution, which indicates that the framework is being actively maintained. As distribution efforts persist, the campaign has the potential to reach more users and expand into additional countries in the near term,” says Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team. Advertisement Kindly share this post Related Topics: Don't Miss Firm to recruit over 100 professionals to boost NRS e-Invoicing compliance

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologycrypto

Get the full story

Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.

Create free account

Already have an account? Sign in