Information-stealing malware on macOS can hijack Telegram Desktop sessions and compromise cryptocurrency wallets, according to blockchain security firm SlowMist.
The malware collects data from macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and databases associated with over a dozen cryptocurrency wallets.
After collecting passwords and authenticated sessions, the malware copies authenticated Telegram Desktop users’ session data, wallet databases, and browser wallet extension data.
Slow Fog he said attackers can then attempt to decrypt stolen wallet databases offline using passwords harvested from the infected device, or replace legitimate Ledger and Trezor apps with phony versions that trick users into entering recovery phrases. The security company recreated the attack chain in an isolated environment.
MacOS malware code used to steal keys and passwords. Source: SlowMist
Related: Artificial Intelligence Didn’t Cause DeFi’s ‘Hackpocalypse’, Says Dragonfly Partner
MacOS malware attacks popular cryptocurrency wallets
According to SlowMist, the malware combines multiple techniques into a coordinated attack chain, allowing attackers to apply different methods to compromise cryptocurrency accounts and wallets.
According to SlowMist, the malware targets software wallets including Exodus, Atomic, Electrum, Wasabi and Monero, as well as hardware wallet applications such as Ledger Live and Trezor Suite. It also searches for wallet data held by full node clients, including Bitcoin Core, Litecoin Core, Dash Core, and Dogecoin Core.
According to SlowMist, Telegram’s two-step verification does not prevent the attack because the malware reuses the authenticated local session instead of creating a novel login. In the tests, researchers restored stolen Telegram Desktop session data on another Mac without entering a phone number, verification code, or two-step verification password.
SlowMist urged users who suspect their devices have been compromised to immediately end their existing Telegram sessions, establish a novel trusted login, and change both their Telegram two-step verification password and their Telegram Desktop password. The company also recommended generating a novel recovery phrase on a neat device and moving all resources to novel addresses.
Warehouse: Does the Botanix failure prove that Bitcoiners don’t care about DeFi?
