A new macOS malware strain has been discovered stealing credentials to hijack Telegram sessions and decrypt cryptocurrency wallets, according to blockchain security firm SlowMist. The malware tricks users into entering their wallet recovery phrases through fake applications while also stealing Telegram Desktop session files for persistent access.
The malware targets information stored locally on infected Macs, including passwords, browser cookies, and Apple Notes. Its Telegram hijacking capability is particularly concerning, as it allows attackers to maintain persistent access to victims accounts and monitor for crypto-related conversations.
Separately, a similar macOS infostealer called ClickLock has been documented by Group-IB. It terminates all visible processes every 210 milliseconds to force users into entering their system login password, then captures the credential for exfiltration. The malware affects users across 33 countries.
These threats highlight the growing sophistication of macOS-targeted malware as Apple’s market share grows. While macOS has historically been less targeted than Windows, the increasing value of cryptocurrency assets stored on Mac systems has attracted developer attention from cybercriminal groups. As reported by Cointelegraph and Bleeping Computer, users should avoid running untrusted terminal commands and only download wallet software from official sources.
