Kaspersky reports OkoBot malware actively stealing crypto wallets and seed phrases across 25+ countries with hundreds of victims.
Regulation & Gov ·
Kaspersky security researchers have identified OkoBot malware as an active threat stealing cryptocurrency wallets and seed phrases from victims across more than 25 countries, with hundreds of people affected by the campaign. The malware operates as a framework designed specifically to target and exfiltrate the credentials and recovery phrases that grant control over crypto assets.
The attack exploits a core vulnerability in cryptocurrency systems: once a private key or seed phrase is compromised, there is no reversible transaction mechanism to recover stolen funds, since blockchain settlements are final and control of assets depends entirely on possession of these cryptographic secrets. Malware represents one of several methods—alongside phishing, social engineering, and insider abuse—through which attackers systematically target digital asset holders.
The exact scope of OkoBot's technical capabilities, the identity of the operators, and which countries experienced the heaviest concentration of victims remain unclear from available reporting. Attribution details and any connection to known threat groups have not been disclosed.