MacOS malware hijacks Telegram sessions and attacks cryptocurrency wallets: SlowMist

Featured in:
abcd

Information-stealing malware on macOS can hijack Telegram Desktop sessions and compromise cryptocurrency wallets, according to blockchain security firm SlowMist.

The malware collects data from macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and databases associated with over a dozen cryptocurrency wallets.

sadasda

After collecting passwords and authenticated sessions, the malware copies authenticated Telegram Desktop users’ session data, wallet databases, and browser wallet extension data.

Slow Fog he said attackers can then attempt to decrypt stolen wallet databases offline using passwords harvested from the infected device, or replace legitimate Ledger and Trezor apps with phony versions that trick users into entering recovery phrases. The security company recreated the attack chain in an isolated environment.

MacOS malware code used to steal keys and passwords. Source: SlowMist

Related: Artificial Intelligence Didn’t Cause DeFi’s ‘Hackpocalypse’, Says Dragonfly Partner

MacOS malware attacks popular cryptocurrency wallets

According to SlowMist, the malware combines multiple techniques into a coordinated attack chain, allowing attackers to apply different methods to compromise cryptocurrency accounts and wallets.

According to SlowMist, the malware targets software wallets including Exodus, Atomic, Electrum, Wasabi and Monero, as well as hardware wallet applications such as Ledger Live and Trezor Suite. It also searches for wallet data held by full node clients, including Bitcoin Core, Litecoin Core, Dash Core, and Dogecoin Core.

According to SlowMist, Telegram’s two-step verification does not prevent the attack because the malware reuses the authenticated local session instead of creating a novel login. In the tests, researchers restored stolen Telegram Desktop session data on another Mac without entering a phone number, verification code, or two-step verification password.

SlowMist urged users who suspect their devices have been compromised to immediately end their existing Telegram sessions, establish a novel trusted login, and change both their Telegram two-step verification password and their Telegram Desktop password. The company also recommended generating a novel recovery phrase on a neat device and moving all resources to novel addresses.

Warehouse: Does the Botanix failure prove that Bitcoiners don’t care about DeFi?

abcd
sadasda

Find us on

Latest articles

Related articles

See more articles

Tesla’s earnings put the spotlight back on the 11,509...

Reference: AND Tesla's earnings put the spotlight back on the 11,509 BTC treasure Tesla's upcoming second-quarter earnings report brings...

Aave Selects Chainlink CCIP as Default Standard for Cross-Chain...

Reference: Aave management Aave Selects Chainlink CCIP as Default Standard for Cross-Chain sGHO Aave governance has changed such that...

The President of Nigeria signs an executive order on...

Nigerian President Bola Ahmed Tinubu has addressed what his office called fragmented regulation of digital assets.Special Advisor...

The strategy raises $263.5 million through the sale of...

Strategy, the world's largest corporate holder of Bitcoin, is raising up-to-date capital by selling its Class A...

Crypto institutions move beyond audits as trust signals weaken:...

According to Hacken, institutional investors are moving beyond shrewd contract audits after conventional trust signals such as...

Will the US get CLARITY this week? Bitcoin’s fresh...

TRANSPARENCY is based on Trump's ethicsPolymarket suggests the CLARITY Act's chances of passing this year are just...