CoinTrust

OkoBot Malware Campaign Targets Crypto Investors and Web3 Developers

Malware

Cybersecurity firm Kaspersky has identified a sophisticated malware framework known as OkoBot that is targeting cryptocurrency investors through advanced social engineering techniques. The company reported that the malware is capable of stealing digital assets, sensitive credentials, and cryptocurrency wallet information while introducing new methods that make attacks more difficult to detect and prevent.

According to Kaspersky, the infection process begins with deceptive tactics designed to persuade victims to execute malicious commands. These methods include ClickFix schemes, which manipulate users into running harmful commands themselves, as well as compromised GitHub applications that install backdoors on targeted devices. The company stated that it has observed multiple attacks involving the OkoBot malware family since January 2026, indicating that the campaign has become increasingly active.

The OkoBot framework is designed to steal cryptocurrency wallet files, browser data, login credentials, and wallet application information while installing malicious browser extensions capable of facilitating digital asset theft.

Kaspersky reported that OkoBot evolved from the TookPS malware campaign first identified in 2025. That earlier campaign relied on counterfeit software websites to distribute Trojan downloaders, but the latest framework introduces a more sophisticated architecture that could also encourage similar attacks by other threat actors.

SSH-Based Infrastructure Introduces a New Attack Method

One of the key differences between OkoBot and previous malware campaigns lies in its communication infrastructure. Rather than deploying each malicious component independently, the framework coordinates approximately 20 separate malicious payloads through an SSH tunnel. Kaspersky explained that this approach enables attackers to securely transfer stolen information from compromised systems to remote servers under their control while making malicious activity more difficult to monitor.

The use of encrypted SSH tunnels represents an evolution in malware design by allowing attackers to centrally manage multiple malicious modules during an active infection. This architecture also enables cybercriminals to collect sensitive information more efficiently while maintaining persistent access to infected devices.

Fake Recruitment Campaigns Target Blockchain Developers

In a separate development, blockchain security firm SlowMist disclosed another malware campaign aimed specifically at Web3 developers through fraudulent recruitment efforts conducted on LinkedIn.

According to the report, attackers impersonate recruiters seeking blockchain developers for employment opportunities. During the recruitment process, victims receive links to fraudulent GitHub repositories that are presented as minimum viable products requiring evaluation before technical interviews. Because developers commonly download source code, install dependencies, and execute software during legitimate hiring assessments, the attack closely resembles a standard recruitment workflow.

SlowMist explained that this realistic process significantly reduces suspicion among experienced developers, increasing the likelihood that malicious code will be executed voluntarily.

The fake recruitment campaign ultimately installs a remote access Trojan capable of stealing project credentials, cloud service access keys, and cryptocurrency wallet extension data from compromised developer systems.

The security firm indicated that these incidents are part of a broader trend rather than isolated attacks. It reported that cybercriminals are increasingly exploiting recruitment processes, software code reviews, and project collaboration opportunities to persuade developers to run malicious repositories themselves.

The findings were released shortly after SlowMist disclosed another malware operation targeting macOS users. That campaign sought to compromise user credentials and hijack Telegram sessions before directing victims to counterfeit websites designed to collect cryptocurrency wallet recovery phrases.

The emergence of multiple coordinated malware campaigns highlights a growing cybersecurity threat to both cryptocurrency investors and Web3 developers, with attackers increasingly relying on trusted platforms and legitimate-looking workflows to compromise sensitive digital assets.

Exit mobile version