MacOS Malware Steals Telegram Sessions and Crypto Wallet Data
A new macOS malware has been discovered by blockchain security firm SlowMist, which targets Telegram sessions and digital currency wallets. The malware collects passwords and authenticated sessions in Telegram and copies user data from popular cryptocurrency wallets such as Exodus, Atomic, Electrum, Wasabi, and Monero. It also searches for stored credentials in applications like Ledger Live and Trezor Suite.
SlowMist's analysis revealed that the attackers use a combination of techniques to compromise digital currency accounts and wallets. They exploit an already authenticated local session instead of initiating a new login, which means Telegram's two-step verification does not prevent this attack. The malware can decrypt stolen wallet databases offline, allowing attackers to gain unauthorized access to user accounts and digital assets.
The firm urges users to take precautions to avoid getting attacked, including keeping their macOS and applications up to date, downloading software from trusted sources, and regularly monitoring for unauthorized changes to applications. SlowMist also recommends generating new recovery phrases, transferring assets to new addresses, and rotating passwords stored in macOS Keychain, Apple Notes, and browsers.