Kaspersky's 'OkoBot' Threat: A New Mirage for Crypto Investors?
Kaspersky, kripto yatırımcıları hedef alan yeni bir kötü amaçlı yazılım çerçevesi olan 'OkoBot'u ortaya çıkardı. Sosyal mühendislik taktikleri ve troj

Cybersecurity firm Kaspersky has identified a new malware framework called 'OkoBot' targeting cryptocurrency investors through social engineering tactics and trojanized GitHub apps. The malware initiates an infection chain using methods like ClickFix, which tricks users into executing malicious commands, followed by deploying a backdoor to harvest crypto wallet files, browser data, and credentials. It also injects malicious extensions and captures wallet application windows to steal assets. Since January 2026, multiple attacks linked to this malware family have been detected. OkoBot evolved from the 'TookPS' campaign, first identified in 2025, and uses an SSH tunnel to orchestrate 20 malicious payloads remotely.
SlowMist emphasized that such attacks are not isolated, with hackers increasingly leveraging recruitment, code reviews, and collaboration scenarios to trick developers into running malicious code. Additionally, a macOS-focused campaign was reported, aiming to steal credentials and hijack Telegram sessions to redirect investors to phishing sites.
Berk Arıcan Note: The crypto ecosystem faces a critical vulnerability in user security. Frameworks like OkoBot pose risks beyond technical flaws, exploiting psychological manipulation. Combined with token unlock risks and liquidity leaks, such vulnerabilities could trigger significant market volatility. Investors must avoid sharing seed phrases and exercise caution with open-source projects.
Related News & Analysis
View All →
Polymarket Secures $1B Funding: 1789 Capital and Trump Jr. Connection

BlackRock Powers $217M Bitcoin ETF Surge as Altcoin Funds Keep Their Momentum

Bitcoin’s Rally: Is the Crypto Renaissance Worth the Wait?

Lazarus Group Moves $30M Through Hyperliquid: A New Shock in Crypto Security

MSCI’s “Strategy‑Exclusion” Filter Triggers Michael Saylor’s Alarm

Ethena Pay: 6% Yield, 5% Cashback – Redefining Digital Banking with Stablecoins
Latest Market News
All News →![[TARFN] TARFİN TARIM A.Ş.
Özel Durum Açıklaması (Genel) - Yurt İçinde Borçlanma Aracı İhracına İlişkin Yönetim Kurulu Kararı](/_next/image?url=%2Fuploads%2Fkap-default.png&w=3840&q=75)
[TARFN] TARFİN TARIM A.Ş. Özel Durum Açıklaması (Genel) - Yurt İçinde Borçlanma Aracı İhracına İlişkin Yönetim Kurulu Kararı

BORSA İSTANBUL BISTECH DEVRE KESİCİ UYGULAMASI Pay Bazında Devre Kesici Bildirimi / OBAMS - OBAMS.E işlem sırasında Pay Bazında Devre Kesici Uygulaması devreye girmiştir
Erdogan-Putin Summit: Akkuyu Nuclear Plant Sparks Energy Revolution
![[ENJSA] ENERJİSA ENERJİ A.Ş.
Pay Dışında Sermaye Piyasası Aracı İşlemlerine İlişkin Bildirim (Faiz İçeren) - TRSENSA32710 ISIN Kodlu Tahvilin 6. Kupon Faiz Oranının Belirlenmesi.](/_next/image?url=%2Fuploads%2Fkap-default.png&w=3840&q=75)
[ENJSA] ENERJİSA ENERJİ A.Ş. Pay Dışında Sermaye Piyasası Aracı İşlemlerine İlişkin Bildirim (Faiz İçeren) - TRSENSA32710 ISIN Kodlu Tahvilin 6. Kupon Faiz Oranının Belirlenmesi.

U.S. Tightens Iran Sanctions, Reroutes 84 Commercial Vessels
![[EBEBK] EBEBEK MAĞAZACILIK A.Ş.
Kurumsal Yönetim Bilgi Formu (Güncelleme) - Pay Sahipleri - Şirket Genel Bilgi Formu](/_next/image?url=%2Fuploads%2Fkap-default.png&w=3840&q=75)