Kaspersky reported a new malware framework named OkoBot that targets cryptocurrency investors, with attacks observed since January 2026.
Kaspersky reported a new malware framework named OkoBot that targets cryptocurrency investors, with attacks observed since January 2026.
The malware spreads through social engineering tactics such as ClickFix, which convinces users to execute malicious commands, and through compromised GitHub repositories that appear to be legitimate development tools. It can extract wallet files, browser data and credentials, inject malicious extensions, and capture wallet application windows to facilitate theft.
Kaspersky said the framework originated from the TookPS campaign identified in 2025, which previously used a fake software downloader. OkoBot differs by coordinating up to 20 payloads through an SSH tunnel that transports data to attacker‑controlled servers. A separate campaign documented by SlowMist targets Web3 developers via deceptive LinkedIn recruitment messages that direct victims to malicious GitHub repositories presenting a minimum viable product. The approach mimics standard technical interview procedures, making detection difficult. The malware aims to provide a remote access trojan that steals project keys, cloud credentials, and wallet extension data. SlowMist noted that recent incidents illustrate attackers increasingly exploiting recruitment, code review and collaboration scenarios to trick developers. A day earlier, SlowMist warned of another campaign that targets macOS users, seeking to steal credentials and hijack Telegram sessions to obtain wallet recovery phrases through counterfeit websites.
The report highlights the growing use of social engineering in supply chain attacks against the cryptocurrency sector.
- Publisher
- cointelegraph
- Reliability
- high
- Published
- 7/19/2026, 10:00:35 AM
- Retrieved
- 7/19/2026, 10:00:35 AM
- Relevance
- 80%
- Confidence
- 85%

