Cybersecurity experts warn that cryptocurrency users are facing a new wave of sophisticated attacks through the OkoBot framework, while the Philippines has seen a 28% surge in mobile cyberattacks in Q1 2026.
Crypto Hacks Are Evolving
Kaspersky’s Global Research and Analysis Team revealed the OkoBot campaign, a malicious framework targeting cryptocurrency users worldwide.
It employs modules like OkoSpyware to monitor browsers, steal seed phrases, and hijack wallet applications such as Trezor and Ledger. Hundreds of victims across 25 countries have already been affected, with Brazil, Vietnam, Canada, Mexico, and Türkiye among the hardest hit.
OkoBot is not a single malware but a multi‑payload framework comprising over 20 implants. It can collect local files, execute remote commands, download malicious extensions, and harvest credentials.
Its SeedHunter component specifically targets hardware wallets, tricking users into entering seed phrases on phishing pages. Infection vectors include ClickFix attacks (social engineering) and fake installers distributed via GitHub.
The sophistication of OkoBot lies in its ability to evolve. Researchers note that the framework is actively maintained, meaning its reach and capabilities are expanding. This represents a direct threat to digital assets of crypto users, as once seed phrases are stolen, wallets can be drained irreversibly.
Mobile Cyberattacks Alarmingly on the Rise
In parallel, the Philippines recorded a 28% surge in mobile cyberattacks in Q1 2026. The increased rate is aligned with global trends, where Asia‑Pacific (APAC) has become a hotspot for phishing, malware, and crypto‑related scams.
Crypto scams are increasingly part of the extensive cyberattack landscape. Phishing campaigns, fake wallet apps, and malicious browser extensions are common.
The surge in mobile attacks can be tied to the growing use of smartphones for financial transactions. Attackers exploit this reliance by deploying malware disguised as legitimate apps or updates.
Globally, APAC has seen some of the fastest growth in cyberattacks. Kaspersky reports that countries like Vietnam and the Philippines are particularly vulnerable due to high crypto adoption and mobile penetration. This convergence of factors makes the region a prime target for cybercriminals.
APAC as Hotspot of Attacks
Kaspersky’s telemetry and surveys reveal a sharp rise in cyberattacks across Asia‑Pacific, particularly mobile and crypto‑related threats:
- Philippines: Mobile cyberattacks rose 28% year‑on‑year in Q1 2026, reflecting the country’s rapid adoption of digital wallets and mobile finance.
- Taiwan: Recorded the most dramatic increase, with attacks up 373% compared to Q1 2025.
- Sri Lanka: Saw a 132% increase, highlighting vulnerabilities in emerging digital markets.
- Thailand: Attacks rose 127%, showing that Southeast Asia remains a prime target.
- Bangladesh: Experienced a 108% rise, reflecting growing mobile penetration.
- China: Logged a 69% increase, despite its strong domestic cybersecurity apparatus.
- Overall APAC: Nearly 30,000 mobile threats were blocked from January to March 2026.
Kaspersky’s B2C Pulse Survey also further contextualizes these numbers:
- 77% of APAC’s population is online, outpacing global averages.
- Digital wallets account for about 70% of online payments, making mobile devices the primary gateway to financial transactions.
APAC consumers lead globally in digital activity: 80% shop online (vs. 71% global), 72% use digital finance (vs. 70%), 70% consume digital entertainment (vs. 62%), and 68% rely on digital communication (vs. 61%).
Cybercrime awareness is higher in APAC (35%) than globally (32%), with Thailand (39%) and Malaysia (38%) showing the highest concern.
Common Cyberattacks and How to Avoid Them
Cyberattacks take many forms, each exploiting different vulnerabilities in human behavior, software, or networks. Understanding these attack types is the first step toward prevention.
Phishing Attacks
Phishing remains the most common cyber threat. Attackers send emails, texts, or social media messages that mimic legitimate institutions, tricking users into clicking malicious links or entering credentials on fake websites. These attacks often use urgency—such as “your account will be locked”—to pressure victims.
How to avoid: Always verify the sender’s address, hover over links before clicking, and never input sensitive information on sites reached through unsolicited messages. Use email filters and security software that flag suspicious communications.
Malware and Trojans
Malware includes viruses, worms, and Trojans disguised as legitimate software. Once installed, they can steal data, monitor activity, or lock devices for ransom. Trojans often masquerade as wallet apps or crypto trading tools.
How to avoid: Download apps only from official stores or verified websites. Keep operating systems and antivirus software updated. Avoid disabling security features to install third‑party utilities.
Ransomware
Ransomware encrypts files and demands payment for decryption. In crypto contexts, attackers often demand Bitcoin or stablecoins to unlock data.
How to avoid: Back up files regularly to offline or cloud storage. Do not click on suspicious attachments. Keep systems patched to prevent exploitation of vulnerabilities.
Man‑in‑the‑Middle (MitM) Attacks
MitM attacks intercept communications between users and services, often on unsecured Wi‑Fi networks. Attackers can steal login credentials or alter transactions.
How to avoid: Avoid public Wi‑Fi for financial transactions. Use VPNs to encrypt traffic. Ensure websites use HTTPS before entering sensitive data.
Credential Stuffing and Brute Force
Attackers use stolen credentials from one breach to access accounts elsewhere. Brute force attacks attempt thousands of password combinations until one works.
How to avoid: Use unique, complex passwords for each account. Enable multi‑factor authentication (MFA) to add a second layer of defense. Employ password managers to generate and store credentials securely.
Fake Apps and Wallets
Cybercriminals create counterfeit apps that mimic legitimate wallets or exchanges. Once installed, they harvest credentials or redirect transactions.
How to avoid: Verify apps through official websites or app stores. Check developer information and reviews. Avoid downloading APKs from forums or unverified links.
Social Engineering
Beyond technical exploits, attackers manipulate human psychology. They may pose as customer support agents, friends, or colleagues to gain trust and extract information.
How to avoid: Be skeptical of unsolicited requests for sensitive data. Confirm identities through official channels. Train employees and family members to recognize manipulation tactics.
Supply Chain Attacks
Attackers compromise legitimate software updates or third‑party services to insert malicious code. This is particularly dangerous because victims believe they are installing trusted updates.
How to avoid: Enable automatic updates only from verified vendors. Monitor cybersecurity advisories for compromised software. Use endpoint detection systems that can flag unusual behavior after updates.
Security Starts with You
Being safe from cyberthreats starts with proactive safeguards and cautions:
- Identify suspicious activity by staying alert to unusual emails, pop‑ups, or app behavior.
- Verify authenticity of communications, apps, and websites before engaging.
- Secure devices with updated operating systems, antivirus tools, and firewalls.
- Protect credentials using strong, unique passwords and MFA.
- Encrypt connections with VPNs and avoid unsecured networks.
- Back up data regularly to mitigate ransomware risks.
- Educate yourself and others about social engineering tactics.
- Monitor accounts for unusual activity and report suspicious transactions immediately.
Cybersecurity Safeguards for Financial Consumers
Financial institutions are strengthening defenses through transaction monitoring, anomaly detection, and customer education. Banks and licensed VASPs in the Philippines are required by BSP to implement strict AML/CFT controls, ensuring that suspicious activity is flagged and reported.
Consumers, however, must complement these safeguards with personal vigilance. This means practicing cybersecurity hygiene: using strong, unique passwords, enabling MFA, and being skeptical of unsolicited communications.
In financial transactions, caution is paramount—once funds are stolen via crypto scams, recovery is nearly impossible.
Scared of rising cyber threats? Protect your funds with DOPAY!
DOPAY utilizes sustainable and secure technology to ensure that customers’ data and financial transactions are safe and protected.
With DOPAY’s crypto wallet, you can gain crypto rewards for every trade under our Trade & Earn program. Not just that, with DOPAY’s Refer & Earn program, Filipinos can unlock new doors for earning possibilities with every successful referral.
Download the DOPAY app today!






