Loading market data...

Kaspersky Uncovers OkoBot Malware That Hijacks Official Apps to Drain Crypto Wallets

Kaspersky Uncovers OkoBot Malware That Hijacks Official Apps to Drain Crypto Wallets

Kaspersky has identified a new malware strain called OkoBot that targets cryptocurrency wallet owners. The security firm describes it as one of the most dangerous crypto-stealing bots currently in the wild. OkoBot works by hijacking official apps, then draining funds from victims' wallets.

How OkoBot works

According to Kaspersky's findings, OkoBot doesn't rely on fake apps or phishing links alone. Instead, it takes over legitimate applications already installed on a device. Once inside, the malware intercepts wallet credentials and transaction approvals, siphoning crypto without the user noticing until it's too late. The exact infection vector hasn't been detailed, but the method marks a shift from earlier clipboard-swapping or keylogging approaches.

Why it's dangerous

Kaspersky's warning places OkoBot among the most aggressive threats for wallet owners. Because it operates inside trusted apps, standard security checks often miss it. Users may not realize their funds are being drained until they check their balance. The timing is especially bad for a market that's already on edge about exchange hacks and phishing campaigns.

What users should avoid

Kaspersky's report includes advice on what not to do to stay safe. The firm urges users to avoid downloading apps from unofficial sources, clicking on unsolicited links, and granting unnecessary permissions to apps. It also recommends keeping wallet software updated and using hardware wallets for larger holdings. No specific list of affected apps has been released, but the general guidance applies to anyone holding crypto on a mobile device.

Kaspersky hasn't said whether OkoBot has been removed from any app stores or if it's spreading through a particular campaign. The company is expected to release more technical details in the coming weeks.