Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Crypto News

    Kaspersky Flags Malware Framework Aimed at Crypto Investors

    18 July 2026
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Kaspersky Flags Malware Framework Aimed At Crypto Investors
    Kaspersky Flags Malware Framework Aimed At Crypto Investors

    Two separate cybersecurity reports point to a growing trend in crypto-related malware: attackers are no longer relying only on obvious phishing emails. Instead, they are moving closer to the workflows people already useโ€”recruiting pipelines, developer code trials, and wallet-related software behavior.

    Kaspersky says it has uncovered a cryptocurrency-targeting malware framework dubbed โ€œOkoBot,โ€ which initiates an infection chain through social engineering, malicious commands, and trojanized GitHub applications. Separately, SlowMist describes a campaign aimed at Web3 developers that starts with fake LinkedIn recruitment offers and ends with poisoned repositories designed to deliver remote access.

    Key takeaways

    • Kaspersky links the OkoBot framework to wallet theft activity, including harvesting wallet files and capturing browser and credential data.
    • OkoBot is designed to steal assets by injecting malicious browser extensions and collecting wallet application windows, Kaspersky reports.
    • SlowMist warns that fake โ€œrecruitmentโ€ messages are being used to trick developers into running malicious GitHub repositories that resemble legitimate interview tasks.
    • SlowMist says the campaignโ€™s goal is to deliver a remote access trojan that can exfiltrate project keys and cloud or wallet extension data.
    • Both reports emphasize social engineering pathsโ€”ClickFix-like tactics or developer-targeted collaboration scenariosโ€”that make the attacks harder to spot.

    Kaspersky: OkoBot targets crypto investors through wallet and credential theft

    In a report released this week, Kaspersky describes OkoBot as a malware framework built to compromise cryptocurrency investors by chaining together multiple stages of intrusion. The first step is not purely technical; it relies on social engineering methods intended to get victims to act.

    According to Kaspersky, initial access can come from tactics such as ClickFix, a technique that aims to trick users into running malicious commands. Alternatively, attackers may deliver similar outcomes by distributing trojanized GitHub apps that include backdoors once installed.

    After gaining a foothold, Kaspersky says OkoBot has capabilities specifically relevant to crypto users and their systems. The malware can harvest crypto wallet files, collect browser data and user credentials, and manipulate the victimโ€™s environment by injecting malicious extensions. It also reportedly captures wallet application windows, which can give attackers a more direct path to stolen assets than credential theft alone.

    Kaspersky added that it has observed multiple attacks involving the OkoBot malware family since January 2026, suggesting the framework is not a one-off operation but part of an active campaign.

    Evolution from TookPS: more orchestration, more reach

    Kaspersky also frames OkoBot as an evolution of a prior threat. The company says the malware framework evolved from โ€œTookPS,โ€ a campaign first identified in 2025 that distributed a Trojan downloader via fake software websites. That earlier stage matters because it signals a progression in how attackers deliver and manage malicious payloads: from initial trickery and download into a more structured compromise process.

    A distinctive operational detail in Kasperskyโ€™s account is how OkoBot manages its payloads. The report states that it orchestrates all 20 malicious payloads via an SSH tunnel, allowing remote transport of data from infected computers to infrastructure controlled by attackers.

    For investors and defenders, this design choice matters because it can complicate incident response. Data exfiltration over an SSH tunnel may blend with normal encrypted traffic patterns, and the multi-payload architecture suggests victims may not see a single obvious โ€œbinaryโ€ responsible for damage.

    SlowMist: fake LinkedIn recruiting and โ€œtry before interviewโ€ repositories

    In a separate report, SlowMist describes another approach to malware delivery: it targets Web3 developers by disguising an attack as recruitment. Rather than sending victims a generic phishing link, attackers reportedly contact developers through LinkedIn while posing as Web3 recruiters.

    SlowMist says the attackers follow up with instructions to download and run code from fake GitHub repositories. The bait is framed as a realistic recruitment process: the repository is presented as a โ€œminimum viable productโ€ that the developer should try before the interview, which aligns closely with how technical screenings often work.

    The company notes that the workflow looks and feels like a genuine interview assignment: developers are expected to pull code, install dependencies, and launch the project. That resemblance is a key factor in why the attack can be difficult to detectโ€”there may be no obvious sign that a โ€œtry it nowโ€ task is actually weaponized.

    Remote access trojan goals: keys, credentials, and extension data

    According to SlowMist, the end goal of the LinkedIn-and-GitHub tactic is to deliver a complete remote access trojan onto the victimโ€™s device. Once installed, SlowMist says attackers can steal sensitive information relevant to Web3 work, including project keys, cloud credentials, or wallet extension data.

    SlowMist also emphasizes that this is not an isolated tactic. The report argues that attackers are increasingly exploiting scenarios that encourage developers to run codeโ€”such as recruitment tasks, code reviews, and project collaborationsโ€”turning normal professional behavior into an infection vector.

    It is also notable that SlowMistโ€™s write-up arrives amid a broader pattern of recent warnings. The security firm had also previously cautioned about a separate malware campaign targeting macOS users, designed to steal credentials, hijack Telegram sessions, and ultimately pressure victims into entering wallet recovery phrases via fake websites.

    For readers and builders, the common thread across both reports is the same: attackers are calibrating their intrusions to the moments when people are most likely to click โ€œrun,โ€ install, or test codeโ€”whether that happens after a recruiter message on LinkedIn or after a malicious โ€œappโ€ appears to be a legitimate GitHub tool. The next thing to watch is whether these campaigns expand into more standardized tooling for developers and more automation for account-level compromise, since both Kaspersky and SlowMist describe activity that looks organized and iterative rather than sporadic.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Crypto-Backed Pac Cuts Massachusetts Primary Ad Spend

    Crypto-Backed PAC Cuts Massachusetts Primary Ad Spend

    20 minutes ago
    Binance Adds Options On 1,000 Us Stocks And Etfs To Deepen Tradfi Push

    Binance adds options on 1,000 US stocks and ETFs to deepen TradFi push

    1 hour ago
    Kalshi Hands First Lifetime Ban To Republican Over Insider Bets

    Kalshi Hands First Lifetime Ban to Republican Over Insider Bets

    2 hours ago
    Sec Drafts Major Overhaul Of Transfer Agent Rules, Mentions Blockchain

    SEC Drafts Major Overhaul of Transfer Agent Rules, Mentions Blockchain

    3 hours ago
    21 Banks Including Bofa, Citi, And Goldman Plan Stablecoin Launch

    21 Banks Including BofA, Citi, and Goldman Plan Stablecoin Launch

    4 hours ago
    Ethena Introduces Usde Payments App With 6% Rewards Program

    Ethena Introduces USDe Payments App With 6% Rewards Program

    5 hours ago

    Search Crypto News

    Featured Crypto News

    Latest News

    • Crypto-Backed PAC Cuts Massachusetts Primary Ad Spend
    • Binance adds options on 1,000 US stocks and ETFs to deepen TradFi push
    • Kalshi Hands First Lifetime Ban to Republican Over Insider Bets
    • SEC Drafts Major Overhaul of Transfer Agent Rules, Mentions Blockchain
    • 21 Banks Including BofA, Citi, and Goldman Plan Stablecoin Launch
    • Ethena Introduces USDe Payments App With 6% Rewards Program
    • Ripple, SettleMint Team Up to Streamline Tokenized Asset Custody
    • Bitcoin Trades Sideways as Bond Bear Market Lifts JGB Yields
    • Fake โ€œClaudeโ€ Desktop App Distributes Crypto-Stealing Malware
    • Bitcoin Rally Signals Broader Crypto Recovery, Not Regrets

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Bitpanda
    eToro Crypto 300x300

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    ๐Ÿ“ž +971 50 449 2025
    โœ‰๏ธ info@cryptobreaking.com
    ๐Ÿ“Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    AVATRADE
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!