Recent findings from blockchain security firm SlowMist reveal a new macOS malware that exploits Telegram sessions to target cryptocurrency wallets. This sophisticated information-stealing malware can hijack authenticated sessions, potentially granting attackers unauthorized access to users’ accounts and digital assets. The implications of this discovery are significant for cybersecurity decision-makers, as it highlights vulnerabilities in widely used applications and the evolving tactics of cybercriminals.
Malware Capabilities and Targeted Assets
The malware specifically targets macOS Keychain, Safari cookies, Apple Notes, and local data from Telegram Desktop, along with databases from various digital currency wallets. SlowMist’s analysis indicates that the malware collects passwords and session data, enabling attackers to access sensitive information without needing to initiate a new login.
Exploitation of Existing Sessions
One of the most alarming aspects of this malware is its ability to bypass Telegram’s two-step verification. SlowMist confirmed that the malware exploits already authenticated local sessions, allowing attackers to regain access to accounts without requiring additional verification steps. This method undermines the effectiveness of two-factor authentication, as the malware does not trigger the usual security protocols during session restoration.
Attack Chain and Techniques
The malware employs a coordinated attack chain that combines various techniques to compromise digital currency accounts. It targets wallets such as Exodus, Atomic, Electrum, Wasabi, and Monero, and also seeks data from hardware wallet applications like Ledger Live and Trezor Suite. By integrating social engineering tactics with authenticated session hijacking, attackers can create a comprehensive account takeover strategy.
Recommendations for Users
In light of these findings, SlowMist urges users to take proactive measures to protect their accounts. Recommendations include:
- Terminating all existing Telegram sessions from a trusted device and establishing a new login.
- Generating a new recovery phrase and transferring assets to new addresses if an account has been compromised.
- Rotating passwords stored in macOS Keychain, Apple Notes, and browsers.
- Reviewing the login status of Telegram clients on secondary devices.
Conclusion
The emergence of this macOS malware underscores the need for heightened vigilance among users of digital currency wallets and messaging applications. As cyber threats continue to evolve, maintaining updated software and employing robust security practices is essential to safeguarding digital assets.
For a detailed report on this malware, visit CoinGeek.


