Kaspersky says a malware framework called OkoBot has moved into an active phase and is putting hundreds of cryptocurrency users at risk across 25 countries. According to the company’s Global Research and Analysis Team, the campaign focuses on wallet owners by tampering with official software used to manage digital assets.

How the malware steals funds

Kaspersky said OkoBot targets users of Ledger Live, Ledger Wallet and Trezor Suite. Instead of attacking through obviously fake wallet software, the malware is designed to intercept the functions of those official applications and show a counterfeit verification window. The goal is to trick victims into giving up sensitive information that can then be used to drain funds.

The report presents the campaign as a shift in attacker tactics. Analysts said the operators are now going after people who may believe they are already well protected, rather than relying only on simple scams aimed at less experienced users.

Who is being targeted

The company said the attackers are deliberately focusing on IT specialists and software developers. In the cases described by Kaspersky, the initial infection happens when malware is disguised as widely used work tools and then distributed through GitHub.

That distribution method matters because the intended targets are more likely to download utilities, scripts or development tools from online repositories as part of their normal work. Kaspersky did not say in the extracted report how many repositories were involved, but it warned that the current campaign has already exposed hundreds of users.

Security advice from Kaspersky

Kaspersky highlighted three steps it said users should follow to reduce the risk of compromise. First, seed phrases should never be entered using a PC keyboard. Second, users should avoid running third-party scripts downloaded from the internet. Third, systems should be checked for hidden remote desktop access, specifically RDP.

Those recommendations reflect the methods described in the report: theft through fake prompts inside trusted wallet software, infection through outside tools, and possible remote access that can help attackers maintain control of a compromised machine.

Why Kaspersky expects the campaign to spread

Kaspersky GReAT said OkoBot is built as a modular framework with more than 20 components. The company said those modules include the Rilide infostealer and an espionage-focused component called OkoSpyware. Based on that structure, analysts expect the campaign’s geographic footprint to widen beyond the places currently reporting the highest infection numbers.

The countries identified as current hotspots are Brazil, Vietnam, Canada, Mexico and Turkey. Kaspersky’s assessment does not claim that the activity will remain limited to those markets; instead, it suggests the malware’s design gives the operators room to expand further.

Kaspersky’s warning adds to broader concern around malware campaigns that no longer rely only on counterfeit wallet apps or phishing pages, but instead interfere with legitimate tools that users trust. In this case, the company’s report centers on OkoBot’s active deployment, its focus on developers and IT workers, and the risk posed to crypto holders who use mainstream wallet-management software.

Source: u.today