HomeCoinsLitecoinMacOS Malware Uses Telegram Session Hijacking to Target Crypto Wallets

MacOS Malware Uses Telegram Session Hijacking to Target Crypto Wallets

A macOS information-stealing malware can hijack Telegram Desktop sessions and compromise cryptocurrency wallets, according to blockchain security firm SlowMist.

The malware harvests data from the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and databases associated with more than a dozen cryptocurrency wallets.

After collecting passwords and authenticated sessions, the malware copies users’ authenticated Telegram Desktop session data, wallet databases and browser wallet extension data.

SlowMist said attackers can then attempt to decrypt the stolen wallet databases offline using passwords harvested from the infected device or replace legitimate Ledger and Trezor applications with fake versions that trick users into entering their recovery phrases. The security firm reproduced the attack chain in an isolated environment.

Read More:  Binance Futures Volume Jumps 80% in June

MacOS malware code used to steal keys and passwords. Source: SlowMist

Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner says

MacOS malware targets popular crypto wallets

According to SlowMist, the malware combines multiple techniques into a coordinated attack chain, allowing attackers to pursue different methods of compromising cryptocurrency accounts and wallets.

Read More:  Upbit Says It Isn’t Participating in Open USD Issuance

The malware targets software wallets including Exodus, Atomic, Electrum, Wasabi and Monero, as well as hardware wallet applications such as Ledger Live and Trezor Suite, according to SlowMist. It also searches for wallet data stored by full-node clients including Bitcoin Core, Litecoin Core, Dash Core and Dogecoin Core.

Telegram two-step verification does not prevent the attack because the malware reuses an authenticated local session instead of creating a new login, according to SlowMist. In tests, researchers restored stolen Telegram Desktop session data on another Mac without entering a phone number, verification code or two-step verification password.

Read More:  Bitmine Generated $46M from Ethereum Staking Last Quarter

SlowMist urged users who suspect their devices have been compromised to immediately terminate existing Telegram sessions, establish a new trusted login and change both their Telegram two-step verification password and Telegram Desktop Passcode. The company also recommended generating a new recovery phrase on a clean device and transferring all assets to new addresses.

Magazine: Does Botanix’s failure prove Bitcoiners don’t care about DeFi?

Facebook Comments Box

LATEST POSTS

AAA Launches Web3 Panel for Crypto Disputes

The American Arbitration Association (AAA), one of the world’s largest providers of private dispute-resolution services, has launched a specialist panel for blockchain and digital-asset cases,...

Hyperscale Data sits on $71 million in Bitcoin with a $56 million market cap

The market values Hyperscale Data’s common equity below its disclosed Bitcoin holdings. Whether that gap belongs to common shareholders is a much harder question.The company...

Most Popular