Kaspersky said a new malware framework called OkoBot is targeting cryptocurrency investors through social engineering tactics and trojanized GitHub applications. The framework can steal crypto wallet files, browser data, and user credentials, then inject malicious extensions and capture wallet application windows to take assets. The cybersecurity firm said it has identified multiple attacks involving the malware family since January 2026. Kaspersky also said OkoBot evolved from TookPS, a malware strain first identified in 2025 that was previously distributed through fake software websites carrying trojan downloaders. In a separate disclosure, SlowMist said another wave of malicious activity is targeting Web3 developers through fake LinkedIn job opportunities. According to SlowMist, attackers pose as Web3 recruiters and send fraudulent GitHub repositories, luring developers into pulling code, installing dependencies, and running projects that can steal project keys, cloud credentials, or wallet extension data.
Kaspersky said a new malware framework known as OkoBot is being used to target cryptocurrency investors through social engineering and trojanized GitHub applications.
According to the cybersecurity company, the malware can steal crypto wallet files, browser data, and user credentials. It can also inject malicious extensions and capture wallet application windows to steal assets.
Multiple attacks found since January 2026
Kaspersky said it has identified multiple attacks involving the malware family since January 2026. The framework evolved from TookPS, which was first identified in 2025 and had previously been distributed through fake software websites that delivered trojan downloaders.
SlowMist reports separate campaign aimed at Web3 developers
SlowMist separately disclosed a new wave of malicious activity that is infiltrating Web3 developers' devices through fake LinkedIn job opportunities. In that campaign, attackers impersonate Web3 recruiters and send fraudulent GitHub repositories, prompting developers to pull code, install dependencies, and run the project. The end result, according to SlowMist, is the theft of project keys, cloud credentials, or wallet extension data.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.