
The attack can reuse Telegram Desktop sessions and harvest wallet data, while security researchers advise treating infected Macs as untrusted and moving assets to newly generated wallets.
A macOS information-stealing malware can take over Telegram Desktop sessions and compromise cryptocurrency wallets by pulling data from the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and databases tied to more than a dozen wallets, blockchain security firm SlowMist said. The malware copies authenticated Telegram session data, wallet databases and browser wallet extension data, giving attackers several ways to pursue accounts and funds. SlowMist said the attack can work even when Telegram two-step verification is enabled because it reuses an already authenticated local session rather than creating a new login. In tests, researchers restored stolen Telegram Desktop session data on another Mac without entering a phone number, verification code or two-step verification password. The malware targets software wallets including Exodus, Atomic, Electrum, Wasabi and Monero, along with hardware wallet applications such as Ledger Live and Trezor Suite. It also looks for wallet data stored by full-node clients, including Bitcoin Core, Litecoin Core, Dash Core and Dogecoin Core. SlowMist said attackers may try to decrypt stolen wallet databases offline using passwords harvested from the infected device or swap legitimate wallet apps for fake ones that prompt users to reveal their recovery phrases. Researchers advised suspected victims to treat infected devices as untrusted, terminate existing Telegram sessions, change both Telegram two-step verification and application passwords, and generate a new recovery phrase on a clean device before moving assets to newly created wallets.