Close Menu
Altcoinvest
    What's Hot

    Stablecoin card spending crosses $10.9B

    August 30, 2026

    Bitcoin’s Moment Has Come For The Far East: Metaplanet CEO

    August 30, 2026

    Strategy Bitcoin Buying May Resume After Saylor ‘We’re Back’ Signal

    August 30, 2026
    Facebook X (Twitter) Instagram
    Altcoinvest
    • Bitcoin
    • Altcoins
    • Exchanges
    • Youtube
    • Crypto Wallets
    • Learn Crypto
    • bitcoinBitcoin(BTC)$78,848.000.74%
    • ethereumEthereum(ETH)$2,504.001.88%
    • tetherTether(USDT)$1.00-0.01%
    • binancecoinBNB(BNB)$699.590.86%
    • rippleXRP(XRP)$1.410.57%
    • usd-coinUSDC(USDC)$1.00-0.01%
    • solanaSolana(SOL)$105.710.27%
    • tronTRON(TRX)$0.3403360.29%
    • Figure HelocFigure Heloc(FIGR_HELOC)$1.00-4.31%
    • HyperliquidHyperliquid(HYPE)$82.62-0.50%
    Altcoinvest
    Home»Crypto Wallets»Kaspersky Uncovers Malware Framework Targeting Crypto Investors
    Kaspersky Uncovers Malware Framework Targeting Crypto Investors
    Crypto Wallets

    Kaspersky Uncovers Malware Framework Targeting Crypto Investors

    July 18, 2026
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Kaspersky has uncovered a new malware framework targeting cryptocurrency investors.

    Dubbed “OkoBot,” the malware initiates an infection chain that starts with social engineering tactics such as ClickFix, which tricks users into running malicious commands, or trojanized GitHub apps that deliver a backdoor to infected devices, the cybersecurity company wrote in a Wednesday report.

    The malware can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets. Kaspersky said it identified multiple attacks involving this malware family since January 2026.

    Kaspersky added that the malware framework evolved from “TookPS,” a malware campaign first identified in 2025 that distributed a Trojan downloader through fake software websites, and that it opens the door to copycat attacks.

    It differs from prior campaigns by orchestrating all 20 malicious payloads via an SSH tunnel, which enables the remote transport of data from infected computers to remote machines controlled by attackers.

    Original OkoBot infection chain. Source: Kaspersky

    Fake LinkedIn recruitment campaigns target Web3 developers with malware

    Separately, a new malware campaign is seeking to infiltrate the devices of Web3 developers via fake LinkedIn recruitment opportunities, according to SlowMist.

    Attackers contact blockchain developers via LinkedIn, posing as Web3 recruiters. They then send fake GitHub repositories to victims, claiming they contained the minimum viable product that needed to be tried before the interview, the blockchain security company said in a Saturday report.

    The workflow closely resembles a legitimate technical interview where developers pull code, install dependencies and launch a project, which makes it difficult to notice the attack, according to SlowMist.

    Related: UK sentences 2 hackers tied to $115M crypto ransom scheme

    The malware aims to deliver a complete “remote access trojan” that infects devices, enabling attackers to steal project keys, cloud credentials, or wallet extension data from these developers.

    “This attack is not an isolated case,” wrote SlowMist, adding that recent incidents illustrate that “attackers are increasingly leveraging scenarios such as recruitment, code reviews and project collaborations to trick developers into actively running malicious repositories.”

    The report came a day after SlowMist warned of a separate malware campaign targeting macOS users, aiming to steal their credentials and hijack their Telegram sessions to ultimately trick investors into entering their wallet recovery phrases through fake websites.

    Magazine: Does Botanix’s failure prove Bitcoiners don’t care about DeFi?

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Strategy Bitcoin Buying May Resume After Saylor ‘We’re Back’ Signal

    August 30, 2026

    Sber Plans Bitcoin, Ether and USDT-Backed Loans

    August 30, 2026

    Real Trump Coins Denies Launching GOLD Token

    August 30, 2026

    Polygon Patches DoS Risks in Austin, Kyoto Hard Forks

    August 29, 2026
    Add A Comment

    Comments are closed.

    Tweets by InfoAltcoinvest

    Top Posts

    Strategy Bitcoin Buying May Resume After Saylor ‘We’re Back’ Signal

    August 30, 2026

    Sber Plans Bitcoin, Ether and USDT-Backed Loans

    August 30, 2026

    Real Trump Coins Denies Launching GOLD Token

    August 30, 2026

    Amazon Warning Triggered Anthropic AI Crackdown

    June 14, 2026

    Bank Manager Allegedly Drains $154,410 From 12 Customer Accounts in Ohio

    May 1, 2026

    Europe Warns AI Threatens Financial Stability

    July 6, 2026

    Fidelity Investments strategist sees resilient markets despite geopolitical turbulence

    April 12, 2026

    Altcoinvest is a leading platform dedicated to providing the latest news and insights on the dynamic world of cryptocurrencies.

    We're social. Connect with us:

    Facebook X (Twitter)
    Top Insights

    Stablecoin card spending crosses $10.9B

    August 30, 2026

    Bitcoin’s Moment Has Come For The Far East: Metaplanet CEO

    August 30, 2026

    Strategy Bitcoin Buying May Resume After Saylor ‘We’re Back’ Signal

    August 30, 2026
    Get Informed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.


    Facebook X (Twitter)
    • Home
    • About us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    © 2026 altcoinvest.com

    Type above and press Enter to search. Press Esc to cancel.