MacOS malware hijacks Telegram sessions and attacks cryptocurrency wallets: SlowMist

Featured in:
abcd

Information-stealing malware on macOS can hijack Telegram Desktop sessions and compromise cryptocurrency wallets, according to blockchain security firm SlowMist.

The malware collects data from macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and databases associated with over a dozen cryptocurrency wallets.

sadasda

After collecting passwords and authenticated sessions, the malware copies authenticated Telegram Desktop users’ session data, wallet databases, and browser wallet extension data.

Slow Fog he said attackers can then attempt to decrypt stolen wallet databases offline using passwords harvested from the infected device, or replace legitimate Ledger and Trezor apps with phony versions that trick users into entering recovery phrases. The security company recreated the attack chain in an isolated environment.

MacOS malware code used to steal keys and passwords. Source: SlowMist

Related: Artificial Intelligence Didn’t Cause DeFi’s ‘Hackpocalypse’, Says Dragonfly Partner

MacOS malware attacks popular cryptocurrency wallets

According to SlowMist, the malware combines multiple techniques into a coordinated attack chain, allowing attackers to apply different methods to compromise cryptocurrency accounts and wallets.

According to SlowMist, the malware targets software wallets including Exodus, Atomic, Electrum, Wasabi and Monero, as well as hardware wallet applications such as Ledger Live and Trezor Suite. It also searches for wallet data held by full node clients, including Bitcoin Core, Litecoin Core, Dash Core, and Dogecoin Core.

According to SlowMist, Telegram’s two-step verification does not prevent the attack because the malware reuses the authenticated local session instead of creating a novel login. In the tests, researchers restored stolen Telegram Desktop session data on another Mac without entering a phone number, verification code, or two-step verification password.

SlowMist urged users who suspect their devices have been compromised to immediately end their existing Telegram sessions, establish a novel trusted login, and change both their Telegram two-step verification password and their Telegram Desktop password. The company also recommended generating a novel recovery phrase on a neat device and moving all resources to novel addresses.

Warehouse: Does the Botanix failure prove that Bitcoiners don’t care about DeFi?

abcd
sadasda

Find us on

Latest articles

Related articles

See more articles

The American arbitration giant launches a specialized panel to...

The American Arbitration Association (AAA), one of the world's largest providers of private dispute resolution services, has...

Crypto is entering its biggest consolidation phase in history,...

The ARK Invest analyst says the cryptocurrency industry is entering what he believes is its largest phase...

Hungary lifts cryptographic controls after granting first MiCA license

Hungary is rolling back strict cryptocurrency rules as CoinCash prepares to resume services after receiving authorization under...

AmericanFortress offers quantum-secure cryptocurrency wallet protection without fund migration

Blockchain security company AmericanFortress has unveiled a cryptographic scheme it says can protect existing cryptocurrency wallets against...

The Real Reason DeFi Projects That Survived the 2022...

When DeFi dashboard Zapper announced this month that it would be shutting down after nearly seven years,...

Binance extorts data from its employees every month, India...

Binance "red teams" employ their own staff every month to keep hackers at bayCryptocurrency exchange Binance has...