< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

2 clusters · 10 sources · 2 days · First seen · Last updated

Categories: TECHNOLOGY

Crypto wallet malware attacks

Entities: Kaspersky · SparkKitty · OkoBot · DarkOwl · Verizon

Overview

In late July 2026 security researchers reported a rise in sophisticated malware aimed at stealing cryptocurrency assets. The first report described the OkoBot framework, which harvests saved passwords, session cookies and device fingerprints to bypass multi‑factor authentication and directly compromise hardware wallets such as Ledger and Trezor. Its SeedHunter component injects malicious code that prompts users for recovery phrases, enabling attackers to transfer funds from compromised wallets.

Two days later, a new mobile threat called SparkKitty was identified. Distributed through seemingly legitimate apps on both the Apple App Store and Google Play, the malware gains access to the device’s photo gallery and uses optical character recognition to locate seed phrases stored in screenshots or photos. When a phrase is found, it is exfiltrated to command‑and‑control servers, allowing the theft of the associated crypto wallets. The campaign underscores the risk of keeping recovery words in digital form and highlights a shift toward leveraging app‑store distribution and image‑scanning techniques.

Together, the snapshots illustrate an expanding cyber‑crime ecosystem in which attackers combine credential‑stuffing, MFA bypass, and novel seed‑phrase harvesting methods to target cryptocurrency users worldwide.

Timeline

  1. 2 days ago

    [TECHNOLOGY] 5 sources
    SparkKitty Malware Harvests Crypto Wallet Seed Phrases from App Stores

    SparkKitty malware uses OCR to steal crypto wallet seed phrases from photos on iOS and Android, spreading via apps on the Apple App Store and Google Play, prompting security warnings.

  2. 3 days ago

    [TECHNOLOGY] 5 sources
    Cybercriminal Malware Chains Bypass MFA and Hijack Crypto Wallets

    Infostealer logs sold to ransomware groups enable MFA bypass, while Kaspersky’s OkoBot framework injects code into crypto wallets to steal seed phrases, exposing global cyber‑crime threats.

Sources

chip.com.tr · countryrebel.com · crypto.news · cryptobriefing.com · invitehealth.substack.com · jimcueva.com · memeburn.com · nigeriacommunicationsweek.com.ng · premierfurnishings.com · saferworld.org.uk