Última hora
DEKrieg in Nahost: Irans Nachbarn suchen Alternativrouten zur Straße von HormusUSSupreme Court to Review Alaska Pilot's Claim Over Plane Seizure for BeerFRL'UE propose de suspendre les amendes sur les émissions de méthane pour les importateurs d'hydrocarburesUSAmerican Oystercatcher Population Recovers, Faces New Threats from Climate Change and ESA ChangesFRAndy Burnham nommé Premier ministre du Royaume-Uni par Charles IIICN中聯油脂七批原油苯並芘超標 食藥署將修法加強食安管理UKOfcom Launches Investigation into Married at First Sight UK Following Rape AllegationsRUДональд Трамп пригрозил Ирану жестким ответом за убийство американских солдатARالولايات المتحدة تعتزم إرسال طائرات مقاتلة إضافية إلى الشرق الأوسطINBangladesh Army Chief Visits Turkiye for Military Training and Hardware PartnershipsDEKrieg in Nahost: Irans Nachbarn suchen Alternativrouten zur Straße von HormusUSSupreme Court to Review Alaska Pilot's Claim Over Plane Seizure for BeerFRL'UE propose de suspendre les amendes sur les émissions de méthane pour les importateurs d'hydrocarburesUSAmerican Oystercatcher Population Recovers, Faces New Threats from Climate Change and ESA ChangesFRAndy Burnham nommé Premier ministre du Royaume-Uni par Charles IIICN中聯油脂七批原油苯並芘超標 食藥署將修法加強食安管理UKOfcom Launches Investigation into Married at First Sight UK Following Rape AllegationsRUДональд Трамп пригрозил Ирану жестким ответом за убийство американских солдатARالولايات المتحدة تعتزم إرسال طائرات مقاتلة إضافية إلى الشرق الأوسطINBangladesh Army Chief Visits Turkiye for Military Training and Hardware Partnerships
Newsgather
AtrásKaspersky Uncovers OkoBot Crypto Malware, SlowMist Warns of Web3 Dev Attacks
Kaspersky Uncovers OkoBot Crypto Malware, SlowMist Warns of Web3 Dev Attacks
En desarrollo
Cointelegraphhace 18 horasTecnología2 min de lectura

Kaspersky Uncovers OkoBot Crypto Malware, SlowMist Warns of Web3 Dev Attacks

En resumen

  • Kaspersky identified "OkoBot," a new malware framework targeting crypto investors by stealing wallet data and credentials.
  • Separately, SlowMist warned of fake LinkedIn recruitment campaigns delivering remote access trojans to Web3 developers, posing significant cybersecurity risks.

Resumen generado por IA

Por qué importa

Kaspersky uncovered OkoBot, an evolved malware from TookPS (first identified in 2025), which targets cryptocurrency investors. Separately, SlowMist reported new malware campaigns using fake LinkedIn recruitment to target Web3 developers.

Tamaño de fuente

Kaspersky has uncovered a new malware framework targeting cryptocurrency investors.

Dubbed “OkoBot,” the malware initiates an infection chain that starts with social engineering tactics such as ClickFix, which tricks users into running malicious commands, or trojanized GitHub apps that deliver a backdoor to infected devices, the cybersecurity company wrote in a Wednesday report.

The malware can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets. Kaspersky said it identified multiple attacks involving this malware family since January 2026.

Kaspersky added that the malware framework evolved from “TookPS,” a malware campaign first identified in 2025 that distributed a Trojan downloader through fake software websites, and that it opens the door to copycat attacks.

It differs from prior campaigns by orchestrating all 20 malicious payloads via an SSH tunnel, which enables the remote transport of data from infected computers to remote machines controlled by attackers.

Fake LinkedIn recruitment campaigns target Web3 developers with malware

Separately, another new malware campaign is seeking to infiltrate the devices of Web3 developers via fake LinkedIn recruitment opportunities, according to SlowMist.

Attackers contact blockchain developers via LinkedIn, posing as Web3 recruiters. They then send fake GitHub repositories to victims, claiming they contained the minimum viable product that needed to be tried before the interview, the blockchain security company said in a Saturday report.

The workflow closely resembles a legitimate technical interview where developers pull code, install dependencies and launch a project, which makes it difficult to notice the attack, according to SlowMist.

The malware aims to deliver a complete “remote access trojan” that infects devices, enabling attackers to steal project keys, cloud credentials, or wallet extension data from these developers.

“This attack is not an isolated case,” wrote SlowMist, adding that recent incidents illustrate that “attackers are increasingly leveraging scenarios such as recruitment, code reviews and project collaborations to trick developers into actively running malicious repositories.”

The report came a day after SlowMist warned of a separate malware campaign targeting macOS users, aiming to steal their credentials and hijack their Telegram sessions to ultimately trick investors into entering their wallet recovery phrases through fake websites.

Preguntas abiertas

  • How many investors/developers have been affected?
  • What specific crypto assets are most vulnerable?
  • Are there new mitigation strategies being developed?

Temas relacionados

This article was originally published by Cointelegraph.

Noticias relacionadas

Contractor linked to North Korea worked on MetaMask code
Tecnología·hace 20 horas

Contractor linked to North Korea worked on MetaMask code

A contractor, later linked to North Korea, worked on MetaMask code for Consensys from March to April before access was terminated. Consensys's investigation found no asset or data misappropriation, malicious code, or impact on user safety. The incident highlights the need for rigorous third-party contractor security, including identity verification, least-privilege access, and continuous monitoring.

CryptoSlate
2 min de lectura
Más sobre este temakaspersky