
Kaspersky Discovers Malware Framework Targeting Crypto Investors
Vexoda Newsroom
Cybersecurity firm Kaspersky has identified a new malware framework called OkoBot that targets cryptocurrency investors through social engineering and trojanized GitHub apps, highlighting the growing
Kaspersky has recently uncovered a sophisticated malware campaign targeting cryptocurrency investors. Dubbed 'OkoBot,' this framework employs a multi-pronged approach involving social engineering tactics such as ClickFix, which tricks users into running malicious commands, and trojanized GitHub apps that deliver backdoors to infected devices.
The OkoBot malware can harvest sensitive information from crypto wallets, steal browser data, inject malicious extensions, and capture wallet application windows. Since January 2026, Kaspersky has identified multiple attacks involving this family of malware, underscoring the growing threat it poses to cryptocurrency users.
OkoBot builds upon earlier campaigns like TookPS by orchestrating all 20 malicious payloads via an SSH tunnel, enabling remote data exfiltration from infected computers. This method allows attackers to steal assets and compromise user credentials without immediate detection.
Separately, a new malware campaign is targeting Web3 developers through fake LinkedIn recruitment opportunities. Attackers pose as recruiters and send fake GitHub repositories containing trojanized code, making it difficult for victims to spot the malicious intent during what appears to be legitimate technical interviews.
The recent attacks highlight how hackers are increasingly leveraging social engineering tactics in conjunction with technological sophistication. These methods not only compromise individual users but also threaten broader ecosystems by targeting developers and their projects.
For traders and investors, these developments underscore the importance of maintaining robust cybersecurity measures. This includes using secure software updates, being cautious about suspicious online interactions, and regularly backing up important data to prevent potential losses.
Traders should monitor emerging trends in malware tactics closely as they evolve rapidly. Staying informed through reliable sources like Kaspersky’s reports will help traders stay ahead of evolving threats.
Source: Cointelegraph. Summarized and rewritten by the Vexoda Newsroom. This is market news, not financial advice.