Wednesday, August 26, 2026|20°C Partly Cloudy
Next edition scheduled
Your Personal Daily Intelligence
Edition 2026-07-19

CRYPTO

Kaspersky Identifies OkoBot Malware Using 20 Modules to Steal Crypto Wallet Recovery Phrases

Kaspersky reported that a malware campaign named OkoBot, active for more than a year, uses roughly 20 modules to steal cryptocurrency wallet recovery phrases and has compromised...

By cryptonews · 38d ago · Source: cryptonews

Full article

Kaspersky reported that a malware campaign named OkoBot, active for more than a year, uses roughly 20 modules to steal cryptocurrency wallet recovery phrases and has compromised users in Brazil, Vietnam, Canada, Mexico and Turkey. The software distributes through GitHub repositories, disguising itself as legitimate tools such as Microsoft SQL Server Management Studio. OkoBot leverages the ClickFix social‑engineering method, presenting victims with fake error messages or repair instructions that prompt them to execute malicious commands, thereby installing the malware without their knowledge. Modules include SeedHunter, which displays a fake wallet interface for Ledger and Trezor devices, MC Keylogger, which records keystrokes and clipboard activity, and OkoSpyware, which monitors screen content. The report published by Bits.media indicated that the operators block IP addresses from Russia and other Commonwealth of Independent States countries. Kaspersky warned that once a recovery phrase is exposed, blockchain transactions are generally irreversible, leaving victims with limited prospects of recovering lost funds.

Source transparency

Publisher
cryptonews
Reliability
high
Published
7/19/2026, 10:00:35 AM
Retrieved
7/19/2026, 10:00:35 AM
Relevance
80%
Confidence
85%
Read original at cryptonews

Botwin's Morning Wire publishes the full source article for reading convenience. Please visit the publisher for the original presentation and any updates.