MacOS Malware Hijacks Telegram Sessions and Targets Cryptocurrency Wallets

A new macOS malware strain is actively stealing credentials to hijack Telegram sessions and decrypt cryptocurrency wallets, according to a report from blockchain security firm SlowMist. The malware spreads through fake applications that trick users into entering their wallet recovery phrases.

The malware, which targets macOS users specifically, operates by capturing session tokens from the Telegram messaging app. Once an attacker gains access to a victim’s Telegram session, they can read messages, access groups, and potentially impersonate the user to spread the malware further.

Beyond Telegram hijacking, the malware also targets cryptocurrency wallets stored on the infected device. It can decrypt certain wallet files and exfiltrate private keys or seed phrases entered into fake application interfaces. SlowMist identified multiple fake apps that appear legitimate but are designed specifically to harvest crypto credentials.

The security firm noted that macOS has historically been perceived as more secure than Windows against malware, but the growing value of cryptocurrency assets has made Mac users increasingly attractive targets. Attackers have developed increasingly sophisticated methods to bypass Apple’s built-in security protections, including Gatekeeper and notarization requirements.

Users are advised to download applications only from official sources, avoid clicking on unsolicited links, and use hardware wallets for cryptocurrency storage. Enabling two-factor authentication on Telegram and other messaging platforms can also help prevent session hijacking attacks.

This article was adapted from Cointelegraph. Read the original here.