A macOS information-stealing malware strain can take over Telegram Desktop sessions and go after a wide range of cryptocurrency wallet data, according to blockchain security firm SlowMist. The researchers said the malware is designed to collect both account credentials and locally stored wallet files, creating multiple paths for attackers to access messaging accounts and crypto holdings.

How the malware works

SlowMist said the malware gathers data from several parts of a Mac system, including the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and wallet databases linked to more than a dozen wallets. After harvesting passwords and authenticated local sessions, it copies Telegram Desktop session files, wallet databases and browser wallet extension data.

That combination is significant because it may allow attackers to work with stolen information without needing to immediately defeat live account protections. In the wallet case, the report said attackers can try to decrypt the stolen databases offline using passwords collected from the infected device.

Telegram session hijack risk

The Telegram component of the malware centers on reusing an already authenticated local session rather than logging in through Telegram’s normal verification flow. SlowMist said this means Telegram’s two-step verification does not stop the attack if the malware has already copied valid session data from Telegram Desktop.

In tests described by the researchers, stolen Telegram Desktop session data was restored on another Mac and used without entering a phone number, a verification code or a two-step verification password. That suggests a compromised machine can expose an active desktop session even when stronger account protections are enabled.

Wallets and apps in scope

SlowMist said the malware targets a broad set of crypto products. The list includes software wallets such as Exodus, Atomic, Electrum, Wasabi and Monero. It also goes after hardware wallet companion apps including Ledger Live and Trezor Suite.

According to the report, attackers may also replace legitimate Ledger and Trezor applications with fake versions in order to trick victims into entering their recovery phrases. Beyond consumer wallet apps, the malware searches for wallet-related data used by full-node clients such as Bitcoin Core, Litecoin Core, Dash Core and Dogecoin Core.

Recommended response

SlowMist urged affected users to cut off any potentially compromised Telegram access by terminating existing sessions and creating a new trusted login. The firm also recommended changing Telegram’s two-step verification settings and the Telegram Desktop Passcode.

For wallet security, the researchers advised users to generate a new recovery phrase on a clean device and move assets to new addresses. That guidance reflects the possibility that both passwords and wallet files may already have been copied, leaving existing setups unsafe even if the malware is later removed.

The findings point to a broader risk for Mac users in crypto: local session files and wallet databases can become as valuable to attackers as passwords themselves. In this case, SlowMist’s warning suggests that once a machine is infected, the threat can extend beyond data theft to direct account reuse and attempts to seize control of wallet access.

Source: cointelegraph.com