Cybersecurity firm Kaspersky has identified a new malware framework, dubbed "OkoBot," that is actively targeting cryptocurrency investors.

The malware initiates infection through social engineering tactics like ClickFix, which tricks users into running malicious commands, or through trojanized GitHub apps that deliver a backdoor. Once installed, OkoBot can harvest crypto wallet files, browser data, user credentials, and even capture wallet application windows to steal digital assets. Kaspersky has tracked attacks involving this malware since January 2026.

The framework evolved from an earlier malware campaign known as "TookPS." A key difference is its use of an SSH tunnel to orchestrate all 20 malicious payloads, enabling the secure transport of stolen data to attacker-controlled servers.

- Figure 1 -
- Figure 1 -

In a separate threat, security firm SlowMist has detailed a malware campaign targeting Web3 developers through fake LinkedIn recruitment opportunities. Attackers pose as recruiters and send victims GitHub repositories containing malicious code disguised as a minimum viable product for a job interview. This attack delivers a "remote access trojan" to steal project keys, cloud credentials, and wallet extension data.

SlowMist warns that attackers are increasingly leveraging recruitment, code reviews, and project collaboration scenarios to trick developers into running malicious repositories.