macOS malware hijacks Telegram sessions and targets crypto wallets, SlowMist says

macOS malware hijacks Telegram sessions and targets crypto wallets, SlowMist says

The attack can reuse Telegram Desktop sessions and harvest wallet data, while security researchers advise treating infected Macs as untrusted and moving assets to newly generated wallets.

BTC
DOGE
LTC

Fact Check
The primary SlowMist Medium report and the Cointelegraph article both confirm every element of the claim. SlowMist documents that the malware copies Telegram Desktop tdata session files to log into accounts on another machine without re-authentication, targets 16+ crypto wallets (Exodus, Atomic, Electrum, Ledger Live, Trezor Suite, etc.), and that mitigation includes moving assets to a newly generated recovery phrase on a clean device. This matches the claim precisely.
    Reference12
Summary

A macOS information-stealing malware can take over Telegram Desktop sessions and compromise cryptocurrency wallets by pulling data from the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and databases tied to more than a dozen wallets, blockchain security firm SlowMist said. The malware copies authenticated Telegram session data, wallet databases and browser wallet extension data, giving attackers several ways to pursue accounts and funds. SlowMist said the attack can work even when Telegram two-step verification is enabled because it reuses an already authenticated local session rather than creating a new login. In tests, researchers restored stolen Telegram Desktop session data on another Mac without entering a phone number, verification code or two-step verification password. The malware targets software wallets including Exodus, Atomic, Electrum, Wasabi and Monero, along with hardware wallet applications such as Ledger Live and Trezor Suite. It also looks for wallet data stored by full-node clients, including Bitcoin Core, Litecoin Core, Dash Core and Dogecoin Core. SlowMist said attackers may try to decrypt stolen wallet databases offline using passwords harvested from the infected device or swap legitimate wallet apps for fake ones that prompt users to reveal their recovery phrases. Researchers advised suspected victims to treat infected devices as untrusted, terminate existing Telegram sessions, change both Telegram two-step verification and application passwords, and generate a new recovery phrase on a clean device before moving assets to newly created wallets.

Terms & Concepts
  • macOS Keychain: Apple password and credential storage system
  • full-node clients: Software that stores the full blockchain and keeps a complete transaction history
  • recovery phrase: Backup words used to restore access to a crypto wallet