EN ▼
Favorites
My Favorites
View All
Market Cap Price 24h%

Disclaimer: Content does not constitute investment advice. Trading involves risks—please invest with caution!

Kaspersky exposes OkoBot malware to steal encrypted assets, Slowfog Technology warns of fake Web3 re

2026-07-19 00:06:44
Bookmark

Kaspersky reveals that new malware framework "OkoBot" specializes in stealing cryptocurrencies

Cybersecurity company Kaspersky disclosed in a report released on Wednesday that it had discovered a new malware framework called "OkoBot" that specifically targets cryptocurrency investors.

Malware evolution: Targeting wallets and credentials

According to Kaspersky, OkoBot initiates the infection process through social engineering strategies, such as deploying the "ClickFix" policy to induce users to run malicious commands. The malware can also be spread through Trojans disguised as GitHub apps, which implant backdoors into devices to steal sensitive information.

Once installed, OkoBot can extract cryptocurrency wallet files, browser data, and user account credentials. The framework can also inject harmful browser extensions and capture wallet application windows, allowing attackers to steal digital assets.

Kaspersky reported that since January 2026, multiple attacks involving the OkoBot family have been detected. The company observed that OkoBot is an evolution of the "TookPS" malware activity that was first discovered in 2025, which used fake software websites to distribute Trojan downloaders. By extending these strategies, OkoBot provides an entry point for potential imitation operations.

A distinctive feature of OkoBot is that it coordinates 20 separate malicious payloads via an SSH tunnel. This approach allows attackers to remotely transfer data directly from infected systems to external machines under their control, simplifying the theft of user information and digital assets.

Micro Dictionary: SSH tunneling-a secure network protocol that establishes encrypted connections between devices that is often used by attackers to secretly transfer data between an infected system and a command-control server during network intrusions.

Kaspersky emphasized that OkoBot activity tunnels all malicious payload through SSH, allowing attackers to directly access and steal sensitive cryptocurrency data from compromised systems.

Fake Web3 recruitment information and malware targeting developers

In another development, blockchain security company SlowMist warned Web3 developers about a new advanced threat spread through LinkedIn fake recruitment campaigns.

The attacker pretended to be a Web3 recruiter on LinkedIn, contacted blockchain developers and offered job offers. They then provided links to the fake GitHub repository, claiming it contained the minimum viable product needed for technical interviews. This strategy mimics the real interview process, causing developers to download, install, and execute malicious code without suspicion.

These malicious files are designed to deliver remote access Trojans, giving attackers full control of infected devices. Once access is gained, attackers can steal project keys, cloud service credentials, and cryptocurrency wallet extension data.

SlowMist said such activities are becoming increasingly common, with attackers using multiple professional scenarios such as recruitment, code review and collaboration projects to trick developers into activating malicious warehouses.

According to SlowMist, attackers are now "using scenarios such as recruitment, code review, and project collaboration to trick developers into proactively running malicious warehouses," making such attacks difficult to detect.

Just a day before Saturday's report was released, SlowMist also warned about a related malware activity targeting macOS users that was designed to steal user credentials and hijack Telegram sessions. These attacks ultimately lead victims to fake websites, requiring them to enter wallet recovery phrases, putting investors 'funds at risk.

Micro Dictionary: SlowMist-a blockchain security company focusing on blockchain ecosystem audits, threat monitoring, and Web3 project vulnerability detection.

Disclaimer:

All content published on this website, including hyperlinks, related applications, forums, blogs, and other media accounts, originates from third-party platforms and their users. CoinMarketInsight makes no representations or warranties of any kind regarding the website or its content. All blockchain-related data and materials are provided for informational and research purposes only and do not constitute financial, legal, or investment advice. Users and third parties are solely responsible for the content they publish. CoinMarketInsight shall not be liable for any losses arising from the use of this website. You should exercise caution and conduct your own independent research, review, analysis, and verification before making any decisions.

Read Full Article
More News
TOP

TOP