< Back to all clusters
[TECHNOLOGY] · Nigeria · 5 sources

Cybercriminal Malware Chains Bypass MFA and Hijack Crypto Wallets

Security researchers have documented how infostealer malware harvests saved passwords, session cookies and device fingerprints, then resells the logs to ransomware affiliates. DarkOwl reports that the stolen session cookies let attackers import valid MFA tokens, granting access without triggering new authentication challenges. Verizon’s 2025 breach report found 88 % of web‑application breaches involved such stolen credentials, which are reused in credential‑stuffing attacks against corporate SSO portals and cloud services.

Kaspersky’s Global Research and Analysis Team has uncovered the OkoBot framework, an extensible malware platform targeting cryptocurrency users in more than 25 countries. Its SeedHunter component injects malicious code into wallets such as Ledger and Trezor, displaying fake recovery‑phrase prompts to steal seed phrases. Victims are typically infected via phishing or trojanized software repositories. Once the recovery phrase is obtained, attackers gain full control of the wallet and can transfer digital assets.

Both reports highlight a growing cyber‑crime ecosystem where stolen authentication data and sophisticated malware are leveraged to bypass multi‑factor protections and steal valuable assets worldwide.

Entities: DarkOwl · Dmitry Galov · Kaspersky · OkoBot · Verizon