The cryptocurrency sector continues to attract cybercriminals, who perfect their methods to deceive their victims. This time, Kaspersky highlights a new malware framework designed to compromi
The cryptocurrency sector continues to attract cybercriminals, who perfect their methods to deceive their victims. This time, Kaspersky highlights a new malware framework designed to compromise digital wallets and steal sensitive data. Analysis shows attackers combine social engineering, fake GitHub projects, and remote access techniques to infiltrate devices. Meanwhile, another campaign targets Web3 developers through fake job offers posted on LinkedIn, revealing an evolution of threats.
In brief
- Kaspersky identified OkoBot, a new malware framework targeting cryptocurrency investors since January 2026.
- The malware uses social engineering, ClickFix, and fake GitHub repositories to compromise victims’ devices.
- Once installed, OkoBot can steal crypto wallet files, user credentials, and browsing data.
- Meanwhile, SlowMist alerts about a separate campaign trapping Web3 developers through fake job offers on LinkedIn.
Kaspersky Unveils the Operation of the OkoBot Malware
According to the cybersecurity company Kaspersky, the new malicious framework, named OkoBot, relies on a carefully prepared infection chain. Attackers notably use social engineering techniques such as ClickFix to convince their targets to execute malicious commands. They also distribute fake applications hosted on GitHub to introduce a backdoor on compromised devices.
Once installed, the malware collects several types of sensitive data. It can retrieve cryptocurrency wallet files, user credentials, as well as browsing information. It also injects malicious extensions into the browser and captures wallet application windows to facilitate the theft of digital assets.
Kaspersky indicates in its report that it has observed several attacks using this malware family since January 2026. The company also specifies that this new threat comes from the evolution of TookPS, a campaign detected in 2025 that already distributed a Trojan through fake software download sites.
Start your crypto adventure safely with KrakenThis link uses an affiliate program.A Technical Evolution That Strengthens Attackers’ Capabilities
The new framework presents a significant difference compared to previous campaigns. According to Kaspersky, the twenty malicious payloads are orchestrated through an SSH tunnel. This method allows attackers to remotely transfer data collected from infected computers to their own infrastructures.
This architecture also facilitates imitation attacks. Cybercriminals can thus adapt their operations and maintain discreet communication with compromised machines. This technical evolution illustrates the growing sophistication of tools used against cryptocurrency investors.
However, infection methods rely on an identical principle. Victims are first led to trust an application or procedure that appears legitimate. They then perform actions themselves that open the door to malware, making attack detection more difficult.
Web3 Developers Also Targeted by Fake LinkedIn Offers
Meanwhile, according to observations from the blockchain and Web cybersecurity company SlowMist, a separate campaign targets Web3 developers. Attackers contact their victims on LinkedIn posing as blockchain recruitment specialists. They then send fake GitHub repositories presented as projects to test before a job interview.
The scenario mimics the usual steps of a technical interview. Developers download the code, install dependencies, then launch the project without suspecting the presence of malware. Once active, it deploys a remote access Trojan capable of stealing project keys, cloud credentials, or wallet extension data.
SlowMist emphasizes that this method is not an isolated incident. Cybercriminals now exploit recruitment contexts, code reviews, or collaboration to push their targets to execute malicious repositories. Kaspersky and SlowMist describe different approaches but based on the same goal: gaining access to sensitive data of crypto ecosystem actors.
These publications show that malicious campaigns evolve rapidly and increasingly rely on credible interactions with their victims. They also confirm that crypto investors as well as Web3 developers remain preferred targets, while social engineering techniques continue to play a central role in observed attacks.