EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Kaspersky warns of malware framework targeting cryptocurrency investors

2026-07-19 00:06:37
Bookmark

Cybersecurity researchers warn: New malware targets cryptocurrency holders and developers

Cybersecurity researchers have recently discovered a wave of malware attacks targeting cryptocurrency-related software holders, developers and consultants. Kaspersky pointed out that it has discovered a new malware framework called OkoBot, which combines social engineering and data theft capabilities specifically targeted cryptocurrency investors. At the same time, SlowMist also warned of another independent intrusion-attackers used seemingly formal recruitment messages on LinkedIn to induce Web3 developers to run malicious code hosted on GitHub. Together, these two incidents indicate that attackers are increasingly using daily office processes (such as interviews, code testing, application installation) as a carrier for malware dissemination.

Core Points

OkoBot aims to steal cryptocurrency-related information by stealing wallet files, browser information, login credentials, and injected browser or extended activity data. Kaspersky said that multiple OkoBot-related attacks have been observed since January 2026, and that the framework has evolved from a previous attack activity called TookPS. According to reports, OkoBot's infrastructure routes all payloads through SSH tunnels, allowing remote data transmission to systems controlled by attackers. Slowfog Technology reported a Linkedin-based "recruiter" fraud-in which attackers sent malicious GitHub repositories disguised as technical interview tasks to Web3 developers. This recruitment process is highly similar to real developer interviews, reducing the vigilance of victims and increasing the probability of them running malicious code.

OkoBot steals targeted cryptocurrency holders through wallets and browsers

In a report released this week, Kaspersky described OkoBot as a malware framework that uses social engineering and "malicious application" dissemination strategies to launch the chain of infections. According to Kaspersky, initial intrusion methods include techniques such as ClickFix-designed to trick users into executing harmful commands, and trojanized GitHub apps-that can implant backdoors on infected devices. Once the system is under the control of an attacker, Kaspersky said OkoBot is able to collect sensitive information directly related to cryptocurrency holdings. The company reported that the malware could: steal cryptocurrency wallet files; extract browser data and user credentials; inject malicious extensions; and capture wallet application windows, possibly carrying out theft through screen or session-related data. Kaspersky also pointed out that since January 2026, multiple attacks using the malware family have been identified. For investors, the actual risk is not only that wallets may be accessed, but also that browser activity and stored authentication data may be used to speed up account takeovers or transfers.

How infrastructure works: Payload orchestration via SSH

A significant detail in Kaspersky's analysis is that OkoBot is different from previous attack activities in managing malicious payloads. Kaspersky said the framework coordinates all 20 malicious payloads through an SSH tunnel, thereby supporting the remote transfer of data from an infected computer to a system controlled by an attacker. This is critical because it points to an operating mode in which an attacker maintains strong control over subsequent stages after the initial breach. Instead of relying solely on static behavior, a tunneled architecture helps attackers adjust policies based on victims and collect information more reliably-depending on what the malware finds on each host. Kaspersky also described OkoBot as an evolved version of TookPS. TookPS was a malware activity first discovered in 2025, distributing Trojan downloaders through fake software websites. By evolving from earlier methods of transmission and adding more coordinated payload processing, the OkoBot framework appears to aim to improve infection success and post-invasion effectiveness.

LinkedIn recruitment fraud induces Web3 developers to run malicious code warehouses

Independent research by Slowfog focuses on another group of targets: Web3 developers. In a report released by the company on Saturday, it pointed out that attackers used LinkedIn messages to pose as Web3 recruiters to reach developers. Slowfog Technology's description of the attack process suggests that the attacker deliberately chose a highly trusted and familiar entry point. After initial contact, victims receive a seemingly fake GitHub repository, packaged as a "minimum viable product" and require developers to install and try it before the interview. Slowfog Technology believes that this technique is effective because it mimics the real technical interview process. The report points out that legitimate developer workflows often include pulling code, installing dependencies, and launching projects-steps that victims naturally perform when preparing for interviews. In this environment, malicious code is not easily detectable, especially when victims do not believe that a warehouse "associated" with a recruitment conversation poses a security risk.

What does the attacker aim to steal from the developer system

Slowfog Technology said the ultimate goal is to implant a complete remote access Trojan into victim devices. Once a Trojan is established, attackers can steal sensitive material related to development and operations, including project keys, cloud credentials, or data related to wallet extensions. Slowfog also emphasized that this recruitment technique is part of a larger trend: Attackers are increasingly using scenarios such as recruitment, code review and project collaboration to trick developers into running malicious warehouses. In other words, this is not just cheating, but also timing-waiting for the moment when the developer is most likely to execute code during normal work. It is worth noting that before issuing the LinkedIn warning, Slowfog Technology also reported another attack against macOS users. The early campaign was designed to steal credentials and hijack Telegram sessions to coerce victims into submitting wallet recovery phrases through fake websites. Although the tactics, techniques, and procedures (TTP) of different attack activities differ, they all point to the same fundamental threat: Attackers are systematically combining social engineering with credential theft to ultimately undermine access to cryptocurrencies.

Future Outlook

Looking ahead, both reports warn readers to be wary of more "seemingly legal" intrusion paths-especially those requiring code execution through recruiters, interview processes, or third-party warehouses. For investors and developers, the immediate question is not just whether malware exists, but whether attackers can leverage everyday trust and authenticated sessions to quickly gain access to secret information related to wallets.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP