OkoBot Malware Targets Cryptocurrency Users with Sophisticated Framework
Kaspersky researchers have identified a sophisticated malicious framework targeting cryptocurrency users worldwide. Dubbed OkoBot, this campaign has been active for over a year and has already infected hundreds of victims across 25 countries.
The malware framework employs several techniques to compromise devices, including the use of OkoSpyware to monitor Chromium-based browsers and deploy various malware strains. One of its primary goals is to steal cryptocurrency wallets by hijacking official applications used to manage assets such as Trezor Suite, Ledger Wallet, and Ledger Live.
The initial infection typically occurs through social engineering attacks or by downloading malicious software from GitHub under the guise of legitimate programs. In one case, researchers identified a fake installer for SQL Server Management Studio (SSMS), a widely used Microsoft database management tool.
Kaspersky experts recommend users exercise caution when dealing with unknown code and use strong security solutions to prevent infections. They also advise managing sensitive data securely by using trusted password managers and enabling multi-factor authentication wherever possible.