Kaspersky Uncovers OkoBot Malware Targeting Crypto Investors
Cryptocurrency investors remain high-value targets because wallet files, seed phrases and browser credentials can provide a direct route to digital assets. Kaspersky’s discovery of OkoBot highlights how attackers are adopting modular malware frameworks that combine specialized components, social engineering and trusted development platforms to compromise victims and steal sensitive information.
Kaspersky recently said OkoBot is being distributed through social-engineering lures and malicious programs hosted on GitHub. The framework can coordinate more than 20 programs to collect cryptocurrency wallet files, seed phrases and browser credentials, then exfiltrate the stolen data through an SSH tunnel. The disclosure underscores the continued evolution of cyber threats aimed at cryptocurrency holders.
All Coverage
3 original reportsThe Backstory
The history behind this eventCrypto Users Targeted in Social Engineering Attack Using Obsidian Community Plugins
Cryptocurrency transactions are typically difficult to reverse once recorded on-chain, making industry professionals with access to wallet credentials high-risk targets for social engineering. Chainalysis estimates that compromises of personal crypto wallets caused $713 million in losses in 2025. The incident also shows how legitimate productivity tools such as Obsidian and their community plugins can be turned into entry points for corporate breaches.
Elastic Security Labs disclosed the REF6598 campaign on April 14, 2026. Scammers posed as a venture capital firm, initially contacting finance and crypto professionals on LinkedIn before moving conversations to Telegram and persuading victims to open an attacker-controlled Obsidian cloud vault and sync its plugins. The campaign targeted both Windows and macOS systems and deployed the PHANTOMPULSE remote access trojan. Elastic said it intercepted the attack at an early stage.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.