Kaspersky uncovers new malware framework targeting cryptocurrency users across 25 countries

Kaspersky has identified a new malware framework called OkoBot that targets cryptocurrency users across 25 countries. The framework uses sophisticated methods, including social engineering and browser-based spyware, to steal credentials and digital assets.
Kaspersky, a cybersecurity firm, has uncovered a sophisticated malware framework designed to steal cryptocurrency from unsuspecting users. The firm warns that the campaign remains active and has already affected hundreds of victims in more than 25 countries. The malware, dubbed OkoBot, is a previously undocumented framework comprising more than 20 malicious components capable of stealing cryptocurrency wallets, harvesting seed phrases, capturing keystrokes, recording videos, downloading malicious browser extensions and executing remote commands on infected devices. According to researchers from Kaspersky’s Global Research and Analysis Team (GReAT), the framework employs a tool known as TookPS to extract cryptocurrency wallet seed phrases while a newly identified OkoSpyware module monitors Chromium-based browsers and injects additional malware, including the Rilide banking trojan. The security firm said the campaign primarily targets cryptocurrency users, with the highest number of victims recorded in Brazil, Vietnam, Canada, Mexico and Türkiye.
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in