New OkoBot framework deploys 20 payloads to steal data, crypto

2026-07-16T19:23:41Za93ac3b1146942bb3c87c488900e9c626fb29679c9ae2d3b361518ecaed93dde
23andmeaccount-takeoveractive-exploitationasyncapicisacryptocurrency-theftinfo-stealernpmokobotoracle-e-business-suiteransomwarescattered-spidersharepointspirals-ransomwarestarland-ratsupply-chaintrojanized-installersvulnerability-researchwindows-end-of-supportzero-dayzoom

What happened

This BleepingComputer digest highlights multiple active and high-risk threats: a new OkoBot framework delivering 20+ payloads to steal crypto wallet seed phrases, credentials and other data; supply-chain and trojanized-distribution attacks (AsyncAPI npm packages, trojanized WebEx/Zoom installers pushing the Starland RAT); a fast-acting Spirals ransomware group that completes intrusion-to-encryption under 24 hours; and multiple actively exploited, high-impact vulnerabilities (CISA-ordered emergency patch for an Oracle E-Business Suite flaw, and CISA warnings for on-premises SharePoint exploits,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
a93ac3b1146942bb3c87c488900e9c626fb29679c9ae2d3b361518ecaed93dde
Enrichment time
2026-07-16T19:23:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.