Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageThreat Intel Desk
Threat Intel

OkoBot: new sophisticated malware framework targets cryptocurrency users

Kaspersky details OkoBot, a modular Windows framework that exfiltrates crypto seed phrases and hijacks Chromium sessions — relevant to any enterprise permitting browser-based financial tooling.

Summary written by editorial AI · Source link below

Filed by Securelist (Kaspersky)1 min readRead at source ↗

Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the Rilide stealer.

Editorial Analysis

Why it matters

Enterprises allowing browser-based crypto or financial tools face seed-phrase theft and session hijacking from modular frameworks that can be retooled for broader credential theft.

What to do

Review endpoint policies for unsanctioned crypto wallet extensions and enforce browser-extension whitelisting on corporate devices.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Securelist (Kaspersky)

External link — opens at Securelist (Kaspersky) in a new tab.

§
Continue with

More from the Threat Intel Desk