Hackers Now Tailor Their CVs for Your Crypto Wallet 🪙
Back to feed

Hackers Now Tailor Their CVs for Your Crypto Wallet 🪙

Cybersecurity researchers have detailed two new malware campaigns targeting cryptocurrency users and Web3 developers through social engineering tactics. Kaspersky disclosed on Wednesday a malware framework dubbed "OkoBot" that initiates an infection chain through ClickFix, which tricks users into running malicious commands, or trojanized GitHub apps that deliver a backdoor to infected devices. The malware can harvest crypto wallet files, browser data and user credentials, inject malicious extensions and capture wallet application windows to steal assets. Kaspersky said it identified multiple attacks involving this malware family since January 2026.

According to the cybersecurity company, OkoBot evolved from "TookPS," a malware campaign first identified in 2025 that distributed a Trojan downloader through fake software websites. OkoBot differs from prior campaigns by orchestrating all 20 malicious payloads via an SSH tunnel, which enables the remote transport of data from infected computers to attacker-controlled machines. Kaspersky warned that the framework opens the door to copycat attacks.

Separately, blockchain security firm SlowMist reported on Saturday a separate campaign aimed at Web3 developers through fake LinkedIn recruitment opportunities. Attackers contact blockchain developers via LinkedIn, posing as Web3 recruiters, and then send fake GitHub repositories to victims, claiming they contained the minimum viable product that needed to be tried before the interview. The workflow closely resembles a legitimate technical interview where developers pull code, install dependencies and launch a project, making it difficult to notice the attack.

The malware aims to deliver a complete remote access trojan that infects devices, enabling attackers to steal project keys, cloud credentials, or wallet extension data from these developers. "This attack is not an isolated case," SlowMist wrote, adding that recent incidents illustrate that "attackers are increasingly leveraging scenarios such as recruitment, code reviews and project collaborations to trick developers into actively running malicious repositories."

The SlowMist report came a day after the firm warned of a separate malware campaign targeting macOS users, aiming to steal their credentials and hijack their Telegram sessions to ultimately trick investors into entering their wallet recovery phrases through fake websites.

Share:
Publishercryptonewsroom.xyz
Published—
CategorySecurity

Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.

See our Terms of Service, Privacy Policy, and Editorial Policy.