MacOS malware hijacks Telegram sessions and attacks cryptocurrency wallets: SlowMist

Featured in:
abcd

Information-stealing malware on macOS can hijack Telegram Desktop sessions and compromise cryptocurrency wallets, according to blockchain security firm SlowMist.

The malware collects data from macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and databases associated with over a dozen cryptocurrency wallets.

sadasda

After collecting passwords and authenticated sessions, the malware copies authenticated Telegram Desktop users’ session data, wallet databases, and browser wallet extension data.

Slow Fog he said attackers can then attempt to decrypt stolen wallet databases offline using passwords harvested from the infected device, or replace legitimate Ledger and Trezor apps with phony versions that trick users into entering recovery phrases. The security company recreated the attack chain in an isolated environment.

MacOS malware code used to steal keys and passwords. Source: SlowMist

Related: Artificial Intelligence Didn’t Cause DeFi’s ‘Hackpocalypse’, Says Dragonfly Partner

MacOS malware attacks popular cryptocurrency wallets

According to SlowMist, the malware combines multiple techniques into a coordinated attack chain, allowing attackers to apply different methods to compromise cryptocurrency accounts and wallets.

According to SlowMist, the malware targets software wallets including Exodus, Atomic, Electrum, Wasabi and Monero, as well as hardware wallet applications such as Ledger Live and Trezor Suite. It also searches for wallet data held by full node clients, including Bitcoin Core, Litecoin Core, Dash Core, and Dogecoin Core.

According to SlowMist, Telegram’s two-step verification does not prevent the attack because the malware reuses the authenticated local session instead of creating a novel login. In the tests, researchers restored stolen Telegram Desktop session data on another Mac without entering a phone number, verification code, or two-step verification password.

SlowMist urged users who suspect their devices have been compromised to immediately end their existing Telegram sessions, establish a novel trusted login, and change both their Telegram two-step verification password and their Telegram Desktop password. The company also recommended generating a novel recovery phrase on a neat device and moving all resources to novel addresses.

Warehouse: Does the Botanix failure prove that Bitcoiners don’t care about DeFi?

abcd
sadasda

Find us on

Latest articles

Related articles

See more articles

The President of Nigeria signs an executive order on...

Nigerian President Bola Ahmed Tinubu has addressed what his office called fragmented regulation of digital assets.Special Advisor...

The strategy raises $263.5 million through the sale of...

Strategy, the world's largest corporate holder of Bitcoin, is raising up-to-date capital by selling its Class A...

Crypto institutions move beyond audits as trust signals weaken:...

According to Hacken, institutional investors are moving beyond shrewd contract audits after conventional trust signals such as...

Will the US get CLARITY this week? Bitcoin’s fresh...

TRANSPARENCY is based on Trump's ethicsPolymarket suggests the CLARITY Act's chances of passing this year are just...

Allbridge Suspends Cross-Chain Bridge After $1.65M Exploit

Allbridge, the company behind the Allbridge Core cross-chain stablecoin bridge, said it had paused the protocol as...

South Korea investigated 40 cases of cryptocurrency manipulation in...

South Korea's financial authorities have investigated more than 40 cases of unfair trading, including market manipulation and...