New macOS malware exploits Telegram sessions to target cryptocurrency wallets, warns SlowMist

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Recent findings from blockchain security firm SlowMist reveal a new macOS malware that exploits Telegram sessions to target cryptocurrency wallets. This sophisticated information-stealing malware can hijack authenticated sessions, potentially granting attackers unauthorized access to users’ accounts and digital assets. The implications of this discovery are significant for cybersecurity decision-makers, as it highlights vulnerabilities in widely used applications and the evolving tactics of cybercriminals.

Malware Capabilities and Targeted Assets

The malware specifically targets macOS Keychain, Safari cookies, Apple Notes, and local data from Telegram Desktop, along with databases from various digital currency wallets. SlowMist’s analysis indicates that the malware collects passwords and session data, enabling attackers to access sensitive information without needing to initiate a new login.

Exploitation of Existing Sessions

One of the most alarming aspects of this malware is its ability to bypass Telegram’s two-step verification. SlowMist confirmed that the malware exploits already authenticated local sessions, allowing attackers to regain access to accounts without requiring additional verification steps. This method undermines the effectiveness of two-factor authentication, as the malware does not trigger the usual security protocols during session restoration.

Attack Chain and Techniques

The malware employs a coordinated attack chain that combines various techniques to compromise digital currency accounts. It targets wallets such as Exodus, Atomic, Electrum, Wasabi, and Monero, and also seeks data from hardware wallet applications like Ledger Live and Trezor Suite. By integrating social engineering tactics with authenticated session hijacking, attackers can create a comprehensive account takeover strategy.

Recommendations for Users

In light of these findings, SlowMist urges users to take proactive measures to protect their accounts. Recommendations include:

  • Terminating all existing Telegram sessions from a trusted device and establishing a new login.
  • Generating a new recovery phrase and transferring assets to new addresses if an account has been compromised.
  • Rotating passwords stored in macOS Keychain, Apple Notes, and browsers.
  • Reviewing the login status of Telegram clients on secondary devices.

Conclusion

The emergence of this macOS malware underscores the need for heightened vigilance among users of digital currency wallets and messaging applications. As cyber threats continue to evolve, maintaining updated software and employing robust security practices is essential to safeguarding digital assets.

For a detailed report on this malware, visit CoinGeek.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Red Hat releases important kernel security update for RHEL 8.6 Advanced and Extended Support

Red Hat has announced a significant kernel security update for its Red Hat Enterprise Linux (RHEL) 8.6 Advanced Mission Critical Update Support and RHEL...

Syria seeks to transform Russian military bases into training centers

Syria is seeking to transform Russian military bases into training centers for its own armed forces, as part of a broader strategy to eliminate...

Armenian National Sentenced to Two Years for Role in Ryuk Ransomware Attacks

An Armenian national has been sentenced to two years in U.S. federal prison after pleading guilty to charges related to multiple ransomware attacks. Karen...

Japan’s Digital Agency Confirms Data Breach Exposing 246,000 Records

In a significant cybersecurity incident, Japan's Digital Agency has confirmed a data breach that exposed approximately 246,000 records. This breach, attributed to a vulnerability...