
Kaspersky warns of malware targeting crypto investors
- Kaspersky has uncovered a new malware framework that targets cryptocurrency investors through fake apps and social engineering.
- The malware can steal wallet files, seed phrases, passwords and browser data from infected devices.
- The campaign has already affected users in more than 25 countries and remains active, according to Kaspersky.
Cybersecurity firm Kaspersky has identified a malware framework called OkoBot that targets cryptocurrency investors through fake GitHub apps and social engineering attacks.
The malware uses tactics such as ClickFix scams and trojanised software to trick victims into installing a backdoor on their devices.
Once installed, OkoBot can steal cryptocurrency wallet files, browser data, passwords and seed phrases while injecting malicious browser extensions.
Kaspersky said the malware contains more than 20 payloads and can also target Ledger and Trezor hardware wallets with fake recovery pages designed to steal seed phrases.
"The OkoBot campaign has been active for more than a year and remained ongoing as of July 2026," said Dmitry Galov, Head of the Russia and CIS unit at Kaspersky's Global Research and Analysis Team.
Kaspersky said it has identified victims in more than 25 countries, with Brazil, Vietnam, Canada, Mexico and Türkiye reporting the highest numbers.
The company warned crypto investors to download software only from trusted sources and protect wallet seed phrases from phishing attacks.