New OkoBot framework deploys 20 payloads to steal data, crypto
2026-07-16T19:23:41Z•a93ac3b1146942bb3c87c488900e9c626fb29679c9ae2d3b361518ecaed93dde
23andmeaccount-takeoveractive-exploitationasyncapicisacryptocurrency-theftinfo-stealernpmokobotoracle-e-business-suiteransomwarescattered-spidersharepointspirals-ransomwarestarland-ratsupply-chaintrojanized-installersvulnerability-researchwindows-end-of-supportzero-dayzoom
What happened
This BleepingComputer digest highlights multiple active and high-risk threats: a new OkoBot framework delivering 20+ payloads to steal crypto wallet seed phrases, credentials and other data; supply-chain and trojanized-distribution attacks (AsyncAPI npm packages, trojanized WebEx/Zoom installers pushing the Starland RAT); a fast-acting Spirals ransomware group that completes intrusion-to-encryption under 24 hours; and multiple actively exploited, high-impact vulnerabilities (CISA-ordered emergency patch for an Oracle E-Business Suite flaw, and CISA warnings for on-premises SharePoint exploits,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- a93ac3b1146942bb3c87c488900e9c626fb29679c9ae2d3b361518ecaed93dde
- Enrichment time
- 2026-07-16T19:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.