Cybersecurity firm Kaspersky has identified a sophisticated malware framework named OkoBot, designed to hijack cryptocurrency wallets and monitor user browser activity.
The tool represents a new vector in the ongoing threat landscape for digital asset holders, focusing on direct theft and surveillance rather than just phishing.
The emergence of OkoBot underscores the persistent risks facing the cryptocurrency sector, where security breaches remain a primary concern for investors and regulators alike.
This development follows recent warnings from the Financial Action Task Force (FATF), which highlighted how organized crime syndicates are exploiting regulatory loopholes to launder billions through crypto channels.
The threat environment has been particularly volatile in 2026, with state-sponsored hacking groups from North Korea responsible for approximately two-thirds of all global cryptocurrency thefts in the first half of the year.
The OkoBot framework adds another layer of complexity to this landscape, targeting individual users directly through their devices.