The global cybersecurity landscape for decentralized finance has faced a significant escalation in complexity as two major security firms, Kaspersky and SlowMist, released detailed reports regarding highly targeted malware campaigns aimed at cryptocurrency investors and Web3 developers. These operations, characterized by the use of advanced social engineering and novel technical exfiltration methods, represent a growing trend where attackers prioritize high-value targets within the blockchain ecosystem over broad, indiscriminate phishing. The discovery of the "OkoBot" framework by Kaspersky and the identification of recruitment-based social engineering by SlowMist highlight a pivot toward long-term infiltration and the exploitation of professional trust.
The Emergence of OkoBot: A Multi-Payload Threat Framework
Kaspersky’s recent investigation has brought to light a new and formidable malware framework dubbed "OkoBot." Identified as being active since at least January 2026, OkoBot is not a singular piece of malware but a comprehensive toolkit designed to facilitate the total compromise of a victim’s digital assets. According to the cybersecurity firm, the framework is the spiritual and technical successor to "TookPS," a malware campaign first documented in 2025. While TookPS relied on more traditional Trojan downloaders distributed via fraudulent software websites, OkoBot represents a significant evolution in both delivery and operational stealth.
The infection chain for OkoBot typically begins with sophisticated social engineering tactics. One of the primary methods identified is "ClickFix." This technique involves presenting users with a simulated technical error—often a fake browser or system update prompt—that instructs the user to "fix" the issue by running a specific command. In reality, the user is tricked into executing a malicious PowerShell script or command-line instruction that downloads the initial OkoBot stager. Alternatively, the attackers utilize trojanized GitHub applications. By offering seemingly legitimate tools for crypto management or development, the threat actors deliver a backdoor directly to the devices of unsuspecting users who believe they are installing verified open-source software.
Once a device is compromised, OkoBot’s capabilities are extensive. The framework is designed to harvest cryptocurrency wallet files, extract sensitive browser data including cookies and saved passwords, and steal user credentials. Furthermore, it can inject malicious extensions into web browsers to intercept real-time transactions and capture wallet application windows to monitor private keys or seed phrases as they are entered.
Technical Innovation: SSH Tunneling as a Stealth Mechanism
What sets OkoBot apart from its predecessors and many contemporary malware families is its sophisticated command-and-control (C2) architecture. Kaspersky’s analysis revealed that the framework orchestrates up to 20 distinct malicious payloads via an SSH (Secure Shell) tunnel. This technical choice is highly strategic. SSH is a standard protocol used by system administrators for secure remote management, and its traffic is often permitted through corporate and personal firewalls without heavy scrutiny.
By tunneling data through SSH, the attackers can bypass traditional network intrusion detection systems that might flag unusual HTTP or FTP traffic. This enables the remote transport of massive amounts of stolen data from the infected computer to attacker-controlled machines with a high degree of anonymity and encryption. The use of an SSH tunnel also allows for a persistent, bidirectional connection, giving the threat actors the ability to push new payloads or updates to the malware in real-time, effectively turning the infected machine into a remote-controlled node within the OkoBot network.
Targeting the Architects: The LinkedIn Recruitment Scam
While OkoBot targets the broader investor base, a separate and equally dangerous campaign has been identified by the blockchain security firm SlowMist, specifically targeting Web3 developers. This campaign utilizes LinkedIn, the professional networking platform, as its primary hunting ground. Attackers pose as recruiters for prominent Web3 or blockchain projects, reaching out to developers with lucrative job opportunities or high-profile collaboration requests.

The deception is meticulously crafted to mimic the standard technical hiring process. After an initial period of rapport-building, the "recruiter" sends the developer a link to a GitHub repository, claiming it contains a "Minimum Viable Product" (MVP) or a coding challenge that the candidate must review or run before a formal interview. Because the request aligns perfectly with the expectations of a technical interview—where developers are routinely asked to pull code, install dependencies, and launch projects—victims are less likely to suspect foul play.
SlowMist’s Saturday report emphasizes that once the developer clones the repository and executes the code, a Remote Access Trojan (RAT) is deployed. This RAT grants the attackers full control over the developer’s environment. In the context of Web3 development, the stakes are exceptionally high. A compromised developer machine can provide attackers with access to private project keys, cloud infrastructure credentials (such as AWS or Azure tokens), and sensitive wallet extension data. This type of "supply chain" infiltration can lead to the compromise of entire blockchain protocols if the developer has administrative access to production code or smart contract deployment keys.
Analysis of Implications: The Professionalization of Crypto-Cybercrime
The reports from Kaspersky and SlowMist suggest a broader shift in the threat landscape. Cybercriminals are no longer relying solely on "spray and pray" tactics; they are instead investing time in understanding the workflows of their targets.
- Exploitation of Trust and Workflow: The LinkedIn recruitment campaign is particularly effective because it weaponizes the professional aspirations of developers. By embedding malware within a standard industry practice (the technical interview), attackers reduce the friction of the infection process.
- Evolution of Persistence: The transition from TookPS to OkoBot shows that malware authors are focused on longevity. The move to SSH tunneling indicates a desire to maintain access to infected systems for months or even years, allowing for the slow exfiltration of data rather than a one-time "smash and grab" attack.
- Targeting the Ecosystem’s Infrastructure: By focusing on developers, threat actors are moving upstream. Stealing a single user’s seed phrase is profitable, but gaining access to a developer’s GitHub or cloud environment could potentially allow an attacker to drain millions from a protocol’s liquidity pools or treasury.
Chronology of Recent Events
The timeline of these discoveries illustrates a persistent and intensifying effort by threat actors:
- 2025: The "TookPS" campaign is first identified, establishing the groundwork for multi-payload delivery via fraudulent software sites.
- January 2026: Kaspersky begins identifying the first wave of attacks involving the "OkoBot" framework, noting an increase in sophistication and the introduction of SSH tunneling.
- Early 2026: SlowMist observes a spike in macOS-specific malware targeting crypto investors, focusing on Telegram session hijacking and credential theft via fake websites.
- Recent Weeks: The LinkedIn recruitment campaign targeting Web3 developers reaches a peak, prompting SlowMist to issue a formal warning regarding "GitHub poisoning" disguised as recruitment.
- Wednesday: Kaspersky officially releases its report on the OkoBot framework, warning of the potential for "copycat attacks" due to the framework’s modular nature.
Official Responses and Defensive Recommendations
In response to these findings, security experts are urging both individual investors and corporate entities to adopt more stringent security protocols. Kaspersky has noted that the evolution of OkoBot opens the door for other criminal groups to adopt similar SSH-based exfiltration methods, suggesting that network administrators should begin monitoring for unusual SSH outbound traffic from non-administrative workstations.
SlowMist has advised Web3 developers to exercise extreme caution when interacting with recruiters on social media. They recommend that any code provided for an interview should be reviewed in a sandboxed environment or a dedicated virtual machine that is completely isolated from production credentials and personal crypto wallets. "This attack is not an isolated case," SlowMist warned, noting that the trend of using recruitment and code reviews as a vector for malware is "increasingly prevalent."
As the cryptocurrency market continues to mature, the tools used by those seeking to exploit it are becoming indistinguishable from professional-grade software. The findings from Kaspersky and SlowMist serve as a critical reminder that in the world of Web3, technical proficiency must be matched by a heightened state of adversarial awareness. The convergence of social engineering and high-level technical execution means that a single clicked link or a cloned repository can result in the total loss of assets and professional integrity.







