OkoBot operators
Reports
3
First seen
Jul 15, 2026
Last seen
Jul 16, 2026
Motivation
Financial
Targeting
Sectors
Top ATT&CK techniques
T1566 Phishing ×3T1059.001 PowerShell ×3T1562.001 Impair Defenses: Disable or Modify Tools ×3T1195 Supply Chain Compromise ×3T1555 Credentials from Password Stores ×2T1056.004 Phishing for Information ×2T1113 Screen Capture ×1T1053 Scheduled Task/Job ×1T1047 Windows Management Instrumentation ×1T1041 Exfiltration Over C2 Channel ×1T1547.009 Boot or Logon Autostart Execution: Services ×1T1055 Process Injection ×1
Indicators
filename ×19hash_md5 ×15domain ×7ip_v4 ×3
Indicator values are available on Pro and via the API.
Recent reports
High