Kaspersky, a cybersecurity firm, has uncovered a sophisticated malware framework designed to steal cryptocurrency from unsuspecting users.
The firm warns that the campaign remains active and has already affected hundreds of victims in more than 25 countries.
The malware, dubbed OkoBot, is a previously undocumented framework comprising more than 20 malicious components capable of stealing cryptocurrency wallets, harvesting seed phrases, capturing keystrokes, recording videos, downloading malicious browser extensions and executing remote commands on infected devices.
According to researchers from Kaspersky’s Global Research and Analysis Team (GReAT), the framework employs a tool known as TookPS to extract cryptocurrency wallet seed phrases while a newly identified OkoSpyware module monitors Chromium-based browsers and injects additional malware, including the Rilide banking trojan.
The security firm said the campaign primarily targets cryptocurrency users, with the highest number of victims recorded in Brazil, Vietnam, Canada, Mexico and Türkiye.







