macOS malware steals Telegram sessions, targets crypto wallets

Researchers found macOS info‑stealer copies Telegram Desktop sessions, extracts passwords and wallet data, and can give attackers access to software and hardware crypto wallets.

A macOS information‑stealing malware copies Telegram Desktop session data and harvests passwords and wallet databases, researchers at SlowMist found. The collected material can allow attackers to access both software and hardware cryptocurrency wallets.

The malware extracts data from the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and multiple wallet-related databases. After collecting passwords and session tokens, it copies local Telegram session files, wallet databases and browser extension wallet data so attackers can reuse them elsewhere.

SlowMist’s analysis shows the malware targets several popular software wallets including Exodus, Atomic, Electrum, Wasabi and Monero. It also searches for data from hardware wallet companion apps such as Ledger Live and Trezor Suite and scans full-node client folders for Bitcoin Core, Litecoin Core, Dash Core and Dogecoin Core.

Researchers reproduced the attack chain in an isolated environment and observed multiple paths the malware can follow to compromise funds. “Telegram two-step verification does not prevent the attack because the malware reuses an authenticated local session instead of creating a new login,” the team wrote. In tests they restored a stolen Telegram Desktop session on another Mac without entering a phone number, verification code or two-step verification password.

With stolen wallet databases and harvested passwords, attackers can attempt offline decryption of files. The researchers also warned that attackers could replace legitimate Ledger and Trezor applications with counterfeit versions that prompt users to enter recovery phrases, which would expose private keys.

SlowMist advised users who suspect compromise to terminate existing Telegram sessions, create a new trusted login and change both the Telegram two-step verification password and the Telegram Desktop passcode. The firm recommended generating a new recovery phrase on a clean device and transferring funds to new addresses, and to follow wallet vendor guidance when regenerating keys.

The report notes the malware targets local files and active sessions rather than breaking cryptographic systems; its effectiveness depends on obtaining secrets stored on the infected machine.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author