Beyond the Breaking News

Kaspersky Uncovers Malware Framework Targeting Crypto Investors

United States News News

Kaspersky Uncovers Malware Framework Targeting Crypto Investors
United States Latest News, United States Headlines

Cybersecurity firm Kaspersky warned of a new malware framework targeting cryptocurrency investors through ClickFix attacks and trojanized GitHub apps.

Cybersecurity company Kaspersky said a newly identified malware framework is targeting cryptocurrency investors through social engineering tactics and trojanized GitHub apps. Dubbed “OkoBot,” the malware initiates an infection chain that starts with social engineering tactics such as ClickFix, which tricks users into running malicious commands, or trojanized GitHub apps that deliver a backdoor to infected devices, the cybersecurity company wrote in a Wednesday The malware can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets.

Kaspersky said it identified multiple attacks involving this malware family since January 2026. Kaspersky added that the malware framework evolved from “TookPS,” a malware campaign first identified in 2025 that distributed a Trojan downloader through fake software websites, and that it opens the door to copycat attacks. It differs from prior campaigns by orchestrating all 20 malicious payloads via an SSH tunnel, which enables the remote transport of data from infected computers to remote machines controlled by attackers.

Fake LinkedIn recruitment campaigns target Web3 developers with malware Separately, a new malware campaign is seeking to infiltrate the devices of Web3 developers via fake LinkedIn recruitment opportunities, according to SlowMist. Attackers contact blockchain developers via LinkedIn, posing as Web3 recruiters.

They then send fake GitHub repositories to victims, claiming they contained the minimum viable product that needed to be tried before the interview, the blockchain security company said in a Saturday The workflow closely resembles a legitimate technical interview where developers pull code, install dependencies and launch a project, which makes it difficult to notice the attack, according to SlowMist. The malware aims to deliver a complete “remote access trojan” that infects devices, enabling attackers to steal project keys, cloud credentials, or wallet extension data from these developers.

“This attack is not an isolated case,” wrote SlowMist, adding that recent incidents illustrate that “attackers are increasingly leveraging scenarios such as recruitment, code reviews and project collaborations to trick developers into actively running malicious repositories. ”macOS users, aiming to steal their credentials and hijack their Telegram sessions to ultimately trick investors into entering their wallet recovery phrases through fake websites.

GooglePlease follow us on Google to support us
We have summarized this news so that you can read it quickly. If you are interested in the news, you can read the full text here. Read more:

Cointelegraph /  🏆 562. in US

 

United States Latest News, United States Headlines

Similar News: You can also read news stories similar to this one that we have collected from other news sources.

Enso Uncovers 'Toxic Pools' That Can Mislead DeFi Transaction SimulationsEnso Uncovers 'Toxic Pools' That Can Mislead DeFi Transaction SimulationsEnso has identified a previously undocumented class of malicious DeFi liquidity pools that can display accurate prices during transaction simulations before delivering worse execution once trades are confirmed on-chain.
Read more »

Kaspersky Uncovers One of Most Dangerous Crypto-Stealing Bots for Wallet OwnersKaspersky Uncovers One of Most Dangerous Crypto-Stealing Bots for Wallet OwnersLearn what not to do to protect your crypto wallet as Kaspersky warns of OkoBot, a dangerous new malware hijacking official apps to drain funds.
Read more »

This new Mac malware won’t let you use your computer until you surrender your passwordThis new Mac malware won’t let you use your computer until you surrender your passwordClickLock is a new macOS malware that repeatedly kills system processes and tricks victims into entering their login password to steal sensitive data.
Read more »

Florida man arrested for allegedly stealing over $200,000 in crypto using Steam game malwareFlorida man arrested for allegedly stealing over $200,000 in crypto using Steam game malwareThe alleged thieves infected 8,000 devices.
Read more »



Render Time: 2026-08-11 16:42:09