A macOS malware sample analyzed by blockchain security firm SlowMist can take over Telegram sessions by copying local account files and can also tamper with cryptocurrency wallet software, according to the company’s findings. The malware was linked to a campaign involving a fake BuilDAO community application and appears designed to steal both messaging access and wallet-related data from Mac users.

How the infection chain worked

SlowMist traced the attack to a campaign reported on July 8 that used a fake BuilDAO app hosted through Google Sites. Victims were sent to a fabricated OAuth security check and then told either to download an AppleScript file or paste a command into Terminal. Once the command was run, it installed a universal Mach-O payload that could operate on both Intel-based Macs and Apple silicon systems.

The researchers said the malware resembled variants of Atomic macOS Stealer, but gathered a wider range of information than standard credential theft tools. According to the report, the sample collected Keychain files, browser passwords, cookies, Apple Notes data, Telegram files, and content from at least 16 desktop wallet applications. SlowMist said the targeted wallet software included Electrum, Exodus, Atomic Wallet, Bitcoin Core, Ledger Live, Trezor Suite, and Sparrow. Its browser checks also searched for hundreds of wallet extension identifiers.

Telegram session theft without a new login

A central concern in SlowMist’s analysis was Telegram access. The firm said the malware did not need to break Telegram’s two-factor protections directly. Instead, it stole the local “tdata” directory that stores an already authorized session on desktop.

In testing, researchers copied those files to another compatible Mac and were able to open the same Telegram account without entering a phone number, login code, or two-step verification password. SlowMist said this worked because the stolen files represented an active authenticated session rather than fresh credentials. The firm also warned that restored access may not immediately show up as a newly logged-in device, which could delay discovery by the victim.

Wallet data theft and app replacement

SlowMist described two separate methods used against crypto wallets. The first involved stealing encrypted wallet databases while also gathering likely passwords from Keychain, browsers, Apple Notes, and a fake administrator prompt. In one test, researchers said they recovered an Atomic Wallet database and decrypted it offline with one of the harvested passwords, illustrating how wallet files and reused credentials could be combined.

The second method went further by replacing legitimate applications. According to SlowMist, the malware removed installed copies of Ledger Live, Ledger Wallet, and Trezor Suite and substituted lookalike versions using familiar names and icons. Those counterfeit apps could present attacker-controlled pages asking users to enter recovery phrases, PINs, or passphrases, even though they were not performing real hardware communication or local signing.

Response advice from SlowMist

SlowMist said the campaign relied mainly on social engineering rather than a macOS software vulnerability. For users who may have been exposed, the firm recommended ending all Telegram sessions from a trusted device, changing security credentials, and replacing any reused passwords. Where wallet compromise is possible, it advised creating a new recovery phrase on a clean device and moving assets.

The findings add to a growing pattern of Mac-focused malware that targets both communications accounts and cryptocurrency storage, especially through fake apps and fraudulent security prompts. In this case, SlowMist’s warning centered on how stolen local Telegram session files and swapped wallet software could give attackers access without triggering the usual login flow users expect.

Source: Coin Edition