New OkoBot framework deploys 20 payloads to steal data, crypto
ID: c1e25f87-213a-548f-a211-0a060604dbcf
STIX ID: report--c1e25f87-213a-548f-a211-0a060604dbcf
Feed Name: Bleeping Computer
OkoBot is a multi-stage malicious framework observed by Kaspersky that has been active for over a year and uses ClickFix attacks and trojanized GitHub repositories to deliver more than 20 payloads aimed at stealing cryptocurrency wallet seed phrases, credentials, cookies and other sensitive data; notable modules include SeedHunter (wallet seed theft), ext daemon (browser extension injection), MC Keylogger and OkoSpyware, and the campaign has global victims (notably Brazil) with provided IOCs and telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
