Kaspersky reveals that new malware framework "OkoBot" specializes in stealing cryptocurrencies
Cybersecurity company Kaspersky disclosed in a report released on Wednesday that it had discovered a new malware framework called "OkoBot" that specifically targets cryptocurrency investors.
Malware evolution: Targeting wallets and credentials
According to Kaspersky, OkoBot initiates the infection process through social engineering strategies, such as deploying the "ClickFix" policy to induce users to run malicious commands. The malware can also be spread through Trojans disguised as GitHub apps, which implant backdoors into devices to steal sensitive information.
Once installed, OkoBot can extract cryptocurrency wallet files, browser data, and user account credentials. The framework can also inject harmful browser extensions and capture wallet application windows, allowing attackers to steal digital assets.
Kaspersky reported that since January 2026, multiple attacks involving the OkoBot family have been detected. The company observed that OkoBot is an evolution of the "TookPS" malware activity that was first discovered in 2025, which used fake software websites to distribute Trojan downloaders. By extending these strategies, OkoBot provides an entry point for potential imitation operations.
A distinctive feature of OkoBot is that it coordinates 20 separate malicious payloads via an SSH tunnel. This approach allows attackers to remotely transfer data directly from infected systems to external machines under their control, simplifying the theft of user information and digital assets.
Micro Dictionary: SSH tunneling-a secure network protocol that establishes encrypted connections between devices that is often used by attackers to secretly transfer data between an infected system and a command-control server during network intrusions.
Kaspersky emphasized that OkoBot activity tunnels all malicious payload through SSH, allowing attackers to directly access and steal sensitive cryptocurrency data from compromised systems.
Fake Web3 recruitment information and malware targeting developers
In another development, blockchain security company SlowMist warned Web3 developers about a new advanced threat spread through LinkedIn fake recruitment campaigns.
The attacker pretended to be a Web3 recruiter on LinkedIn, contacted blockchain developers and offered job offers. They then provided links to the fake GitHub repository, claiming it contained the minimum viable product needed for technical interviews. This strategy mimics the real interview process, causing developers to download, install, and execute malicious code without suspicion.
These malicious files are designed to deliver remote access Trojans, giving attackers full control of infected devices. Once access is gained, attackers can steal project keys, cloud service credentials, and cryptocurrency wallet extension data.
SlowMist said such activities are becoming increasingly common, with attackers using multiple professional scenarios such as recruitment, code review and collaboration projects to trick developers into activating malicious warehouses.
According to SlowMist, attackers are now "using scenarios such as recruitment, code review, and project collaboration to trick developers into proactively running malicious warehouses," making such attacks difficult to detect.
Just a day before Saturday's report was released, SlowMist also warned about a related malware activity targeting macOS users that was designed to steal user credentials and hijack Telegram sessions. These attacks ultimately lead victims to fake websites, requiring them to enter wallet recovery phrases, putting investors 'funds at risk.
Micro Dictionary: SlowMist-a blockchain security company focusing on blockchain ecosystem audits, threat monitoring, and Web3 project vulnerability detection.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following