Kaspersky exposes malware framework built to drain crypto wallets

Cybersecurity researchers at Kaspersky have identified a new malware framework specifically designed to steal cryptocurrency assets from investors. The malware, called OkoBot, uses a combination of social engineering tricks and trojanized apps to get inside victims’ devices, and it has been active since at least January 2026.

According to Cointelegraph, Kaspersky’s research team published its findings this week, describing a sophisticated infection chain that begins with tactics like ClickFix, a method that tricks users into manually running malicious commands on their own machines. Attackers also distribute trojanized apps through GitHub, where developers and crypto users often go to find legitimate software.

Once inside a device, OkoBot is capable of doing serious damage. It can steal crypto wallet files, harvest browser data and saved credentials, inject malicious browser extensions, and capture wallet application windows to intercept assets. What makes this framework especially concerning is how it manages all 20 of its malicious payloads: everything runs through an SSH tunnel, which lets attackers quietly pull data from infected machines to servers they control.

Kaspersky also noted that OkoBot appears to have grown out of an earlier campaign called TookPS, which was first spotted in 2025. That earlier operation spread a Trojan downloader through fake software download pages. The evolution from TookPS to OkoBot suggests a more organized threat actor, and Kaspersky warned that the framework’s design makes it easy for others to copy.

Crypto investors have been a prime target for malware campaigns for years, but the tactics are getting harder to spot. Frameworks like OkoBot blend into normal user behavior, making it difficult for even cautious users to realize they’ve been compromised until it’s too late.

At the same time, a separate campaign is targeting Web3 developers directly. Blockchain security firm SlowMist flagged an operation where attackers pose as Web3 recruiters on LinkedIn, reaching out to blockchain developers with job opportunities. Once contact is made, they send victims a link to a fake GitHub repository, claiming it’s a product demo the candidate needs to run before their interview.

The process looks almost identical to a real technical interview:

  • The developer pulls code from the repository
  • They install the listed dependencies
  • They launch the project as instructed

At that point, the malware runs. The payload is a remote access trojan that gives attackers full access to the infected machine, letting them steal project keys, cloud credentials, and wallet extension data.

SlowMist pointed out that this is not an isolated case, and that attackers are increasingly using professional scenarios like recruitment drives, code reviews, and project collaborations to get developers to run malicious code willingly. That social context is what makes it so effective. A developer who would never click a suspicious email link might not think twice about running code as part of an interview process.

This report came just a day after SlowMist issued a separate warning about a malware campaign targeting macOS users, designed to steal credentials and hijack Telegram sessions. That campaign ultimately directed victims to fake websites where they were prompted to enter their wallet recovery phrases, handing attackers complete control over their funds.

Taken together, these campaigns point to a clear pattern: attackers are becoming more targeted and more patient. Rather than relying on mass phishing blasts, they are building convincing scenarios around the actual habits of crypto users and developers. That shift makes traditional security advice, like avoiding suspicious links, much less effective on its own.