How OkoBot Malware Steals Crypto Assets from Investors and Web3 Teams
Cybercriminals are getting smarter at tricking people who hold digital money and build blockchain projects. A new malware family called OkoBot is now hitting both everyday crypto users and skilled developers with clever tricks that are hard to spot.
What Makes OkoBot Different
OkoBot does not just drop one bad file and run. It uses an encrypted SSH tunnel to control about twenty separate harmful programs at once. This setup lets attackers move stolen data safely and stay hidden longer. The malware grabs wallet files, browser passwords, login details, and even adds fake browser extensions that can empty your accounts.
How the Infection Starts
Attackers begin with simple social tricks. One method is called ClickFix. Victims are shown fake error messages and told to copy and paste commands into their computer. Another route uses fake or hacked GitHub apps that install a backdoor right away. These steps started appearing in large numbers from January 2026 onward.
From Older Campaigns to OkoBot
OkoBot grew out of an earlier effort known as TookPS. That version used fake software sites to spread downloaders. The new version is more organized and uses central control through SSH tunnels. This change makes it easier for other bad actors to copy the idea and launch similar attacks.
LinkedIn Traps Aimed at Developers
At the same time, another group is targeting Web3 programmers on LinkedIn. Fake recruiters send messages about job openings. They share links to GitHub pages that look like real test projects. Developers download the code, install needed tools, and run the program exactly as they would in a normal hiring test. The code then installs a remote access tool that steals cloud keys, project passwords, and wallet data.
Why These Attacks Work So Well
- They copy real workflows people already trust.
- They use platforms like GitHub and LinkedIn that feel safe.
- They avoid obvious red flags until it is too late.
Extra Threats on macOS
Similar tricks have also hit Mac users. One campaign steals Telegram sessions and then sends victims to fake sites that ask for wallet recovery phrases. This shows the attackers are testing many routes at once.
How to Stay Safe
Never run commands from pop-up messages. Check every GitHub link before you download code, even during job interviews. Use hardware wallets when possible and keep your browser extensions to a minimum. Turn on two-factor authentication everywhere and watch for sudden requests to run unknown scripts.
The rise of