Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
2 clusters · 10 sources · 2 days · First seen · Last updated
Categories: TECHNOLOGY
Crypto wallet malware attacks
Entities: Kaspersky · SparkKitty · OkoBot · DarkOwl · Verizon
Overview
In late July 2026 security researchers reported a rise in sophisticated malware aimed at stealing cryptocurrency assets. The first report described the OkoBot framework, which harvests saved passwords, session cookies and device fingerprints to bypass multi‑factor authentication and directly compromise hardware wallets such as Ledger and Trezor. Its SeedHunter component injects malicious code that prompts users for recovery phrases, enabling attackers to transfer funds from compromised wallets.
Two days later, a new mobile threat called SparkKitty was identified. Distributed through seemingly legitimate apps on both the Apple App Store and Google Play, the malware gains access to the device’s photo gallery and uses optical character recognition to locate seed phrases stored in screenshots or photos. When a phrase is found, it is exfiltrated to command‑and‑control servers, allowing the theft of the associated crypto wallets. The campaign underscores the risk of keeping recovery words in digital form and highlights a shift toward leveraging app‑store distribution and image‑scanning techniques.
Together, the snapshots illustrate an expanding cyber‑crime ecosystem in which attackers combine credential‑stuffing, MFA bypass, and novel seed‑phrase harvesting methods to target cryptocurrency users worldwide.
Timeline
-
2 days ago
[TECHNOLOGY] 5 sourcesSparkKitty Malware Harvests Crypto Wallet Seed Phrases from App StoresSparkKitty malware uses OCR to steal crypto wallet seed phrases from photos on iOS and Android, spreading via apps on the Apple App Store and Google Play, prompting security warnings.
-
3 days ago
[TECHNOLOGY] 5 sourcesCybercriminal Malware Chains Bypass MFA and Hijack Crypto WalletsInfostealer logs sold to ransomware groups enable MFA bypass, while Kaspersky’s OkoBot framework injects code into crypto wallets to steal seed phrases, exposing global cyber‑crime threats.
Sources
chip.com.tr · countryrebel.com · crypto.news · cryptobriefing.com · invitehealth.substack.com · jimcueva.com · memeburn.com · nigeriacommunicationsweek.com.ng · premierfurnishings.com · saferworld.org.uk