Close Menu
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    The Gulf WeeklyThe Gulf Weekly
    • Home
    • UAE
    • KSA
    • GCC
    • Technology
    • Lifestyle
    • Sports
    The Gulf WeeklyThe Gulf Weekly
    Home»Technology»Kaspersky reveals a new malicious framework targeting cryptocurrency users with the use of OkoSpyware

    Kaspersky reveals a new malicious framework targeting cryptocurrency users with the use of OkoSpyware

    Editorial TeamBy Editorial TeamAugust 4, 2026
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Kaspersky Global Research and Analysis Team (GReAT) revealed insights about the new OkoBot campaign targeting cryptocurrency users.

    The new sophisticated framework employs TookPS to exfiltrate seed phrases and uses a new OkoSpyware module to monitor Chromium-based browsers and deploy various malware strains, including the Rilide stealer. It has already targeted hundreds of victims across over 25 countries, with the highest number of affected end users recorded in Brazil, Vietnam, Canada, Mexico and Turkiye. According to Kaspersky experts, the threat remains active and primarily poses a risk to cryptocurrency users.

    In January 2026, experts from the Kaspersky Global Research and Analysis Team (GReAT) identified multiple attacks involving a previously unknown malware capable of capturing the contents of cryptocurrency wallet windows. Dubbed Okobot, the new sophisticated malware framework comprises more than 20 malicious payloads and implants designed to perform a wide range of functions, including collecting local files, executing remote commands, downloading arbitrary browser extensions, stealing cryptocurrency wallets, harvesting seed phrases and credentials, recording video and carrying out other malicious activities. One of the new implants used in the campaign is a loader that modifies browser memory to load and hide malicious extensions. OkoBot also includes a new OkoSpyware module, which captures keystrokes and the video stream of a target application’s window.

    Currently available information does not allow the campaign to be attributed to any known crimeware actor with high confidence. However, the techniques and infostealer involved are widely used by Russian-speaking threat actors, and technical analysis has also revealed code artifacts in Russian.

    The initial infection typically occurs through two main vectors: ClickFix attacks, in which threat actors use social engineering to trick users into running malicious code, and malware distributed via GitHub under the guise of legitimate software. During the investigation, researchers identified one such case involving a fake installer for SQL Server Management Studio (SSMS), a widely used Microsoft database management tool.

    The malicious framework includes SeedHunter, a malware component that monitors active system processes and injects an implant into Trezor Suite, Ledger Wallet, and Ledger Live, – official applications used to manage cryptocurrency assets. When it detects a connected Trezor or Ledger hardware wallet, it triggers the hooked functions to display a hard-coded phishing page aimed at stealing the user’s seed phrase, using a distinct layout for each wallet type.

    “The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026. The observed infection vectors strongly suggest that developers are among its primary targets. Of particular concern is the malware’s continued evolution, which indicates that the framework is being actively maintained. As distribution efforts persist, the campaign has the potential to reach more users and expand into additional countries in the near term”, says Dmitry Galov, Head of the Russia and CIS unit at Kaspersky Global Research and Analysis Team.

    To stay safe, Kaspersky experts recommend users:

    • Never follow instructions from unverified sources to deploy unknown code on a device, whether given directly or found in guides. Attackers often use this tactic to infect systems, which can lead to data loss and even loss of control over the device.
    • Use a strong security solution on all computers and mobile devices, such as Kaspersky Premium. It will warn you and prevent an infection.
    • Manage sensitive data securely: avoid storing passwords or recovery phrases in your photo gallery or notes; instead, use a dedicated, trusted password manager such as Kaspersky Password Manager.
    • Never disable antivirus or security tools to install software and exercise caution when downloading game mods, cheats or third-party utilities.
    • Keep operating systems and applications updated, use strong, unique passwords and enable multi-factor authentication wherever possible.

    Image Credit: Kaspersky 


    Source: Tahawul Tech

    Related Posts

    Bodour Al Qasimi accepts patronage of Magdi Yacoub Institute

    August 4, 2026

    OMODA 4 Unveils ‘The Super AI Cockpit That Truly Understands Global Youth’ Ahead of UAE Debut

    August 4, 2026

    GCG Enterprise Solutions expands enterprise AV portfolio with Crestron partnership

    August 4, 2026
    Don't Miss

    Najran’s 4,400 greenhouses produce more than 37,000 tons of crops

    KSA August 4, 2026

    NAJRAN — More than 4,400 greenhouses in Najran produce over 37,000 tons of tomatoes and…

    Kaspersky reveals a new malicious framework targeting cryptocurrency users with the use of OkoSpyware

    August 4, 2026

    Bodour Al Qasimi accepts patronage of Magdi Yacoub Institute

    August 4, 2026

    34 new supplementary grants approved for Sharjah retirees

    August 4, 2026
    Our Picks

    Najran’s 4,400 greenhouses produce more than 37,000 tons of crops

    August 4, 2026

    Kaspersky reveals a new malicious framework targeting cryptocurrency users with the use of OkoSpyware

    August 4, 2026

    Bodour Al Qasimi accepts patronage of Magdi Yacoub Institute

    August 4, 2026

    34 new supplementary grants approved for Sharjah retirees

    August 4, 2026
    2026. All rights reserved.
    • UAE
    • KSA
    • GCC
    • Technology
    • Lifestyle
    • Sports
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.