Kaspersky disclosed a novel malware framework called OkoBot actively targeting cryptocurrency investors since January 2026. The malicious software uses social engineering and fake GitHub projects to compromise devices and exfiltrate sensitive data.
OkoBot Infection Techniques and Capabilities
The attack chain includes convincing victims to run harmful commands through ClickFix social engineering. Fake applications hosted on GitHub serve as backdoors. Once installed, OkoBot steals crypto wallet files, user credentials, and browsing data. It also injects malicious browser extensions and captures wallet app windows to facilitate asset theft.
Kaspersky highlighted that OkoBot is an evolution of the TookPS campaign spotted in 2025 involving Trojans distributed via fake software download sites. The new malware orchestrates about twenty payloads through SSH tunnels, enabling remote data transfer and stealthy communication with compromised machines.
This technical advancement allows attackers to adapt operations and impersonate legitimate network traffic, increasing the threat's complexity compared to previous campaigns.
also cybersecurity firm SlowMist warned about a separate campaign targeting Web3 developers with fake LinkedIn job offers, marking a shift toward more sophisticated attack vectors within the crypto space.



