New macOS malware targets Telegram, ‘crypto’ wallets: report

1 hour ago 1



Homepage > News > Business > New macOS malware targets Telegram, ‘crypto’ wallets: report Blockchain security firm SlowMist has uncovered a macOS information-stealing malware capable of hijacking Telegram sessions and targeting digital currency wallets, revealing an attack chain that could grant attackers unauthorized access to accounts and digital assets. The malware targets macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop local data, and the databases of over a dozen digital currency wallets, according to SlowMist. The firm explained that the malware collects passwords and authenticated sessions in Telegram and copies the users’ authenticated Telegram Desktop session data, wallet databases, and browser wallet extension data. After conducting an analysis in a controlled environment, SlowMist reported that the attackers would try to decrypt the stolen wallet databases offline. They may use information collected from the infected device or replace legitimate Ledger and Trezor applications with counterfeit versions. This could deceive victims into entering their recovery phrases. Source: SlowMist’s Medium Post SlowMist confirmed that Telegram’s two-step verifica...

Read Entire Article