According to the Kabaski Global Research and Analysis Team, OkoBot malware against encrypted asset holders is at an active dissemination stage. According to researchers, hundreds of users in 25 countries are at risk of asset theft, and the attacker ' s round has clearly adjusted his methods to begin targeting people who would have thought they were better protected.
Disguised official wallet application interface
The main practice of such malicious software is to hijack the normal functions of official applications such as Legger Live, Ledger Wallet and Térezor Suite, and then pop up fake authentication windows and induce users to enter sensitive information. The researchers stated that the wallet assets could be removed once the user had handed over the recovery phrase or performed the operation in the wrong interface.
- Do not enter notes via computer keyboard
- Do not run third-party scripts from unknown sources
- Checks whether the system has hidden RDP remote access
The attack entrance is disguised as a common software.
According to researchers, this round of attacks was deliberately directed at IT practitioners and software developers. The attackers will disguise the malice program as a common software, which will then be disseminated through such channels as GitHub, to induce target downloads to be installed.
Kabaski has discovered that the fake Microsoft SQL Server Management Studio (SSMS) installation package was implanted with the relevant malicious code. This means that the attackers no longer rely solely on traditional fishing pages, but instead move the delivery chain ahead to a more commonly exposed software acquisition process.
Modular structure to expand range of attacks
According to the report, OkoBot uses a modular structure that contains more than 20 components, including the Riliide Information Stealing Program and OkoSpyware Monitoring Module. As these modules continue to spread, researchers expect further expansion from Brazil, Viet Nam, Canada, Mexico and Turkey, which are currently at high levels.
Kabaski also mentioned that the attackers may continue to introduce new hidden extensions to the Chromium kernel browser, involving products such as Chrome and Edge. Such extensions can be completely hidden from the list of installed plugins, and users may not be able to detect anomalies directly, even if they are recruited.
Possible shift to access rights for the sale of injured equipment
According to researchers, the final phase of the attack may not be confined to the theft of wallet assets. Once the malicious process has been put in place in the system, the new administrator account will be created in secret and the long-term remote control route will be established through RDP.
This means that access to the victim ' s computer itself may also be packaged for sale to other attackers, and the risk is further extended from one-sided currency theft to the long-term out of control of the equipment.
