SlowMist Reveals MacOS Malware Campaign Compromising Telegram and Cryptocurrency Wallets
Cybersecurity researchers have discovered sophisticated macOS malware that compromises Telegram sessions and steals cryptocurrency by harvesting credentials, decrypting wallet files, and deploying fraudulent applications to capture recovery phrases.

Blockchain security company SlowMist has identified a sophisticated information-stealing malware targeting macOS that is capable of compromising Telegram Desktop sessions and infiltrating cryptocurrency wallets.
The malicious software extracts sensitive information from multiple sources on macOS systems, including the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop, and database files linked to over a dozen different cryptocurrency wallet applications.
Once the malware successfully gathers passwords and active authenticated sessions, it proceeds to duplicate authenticated Telegram Desktop session information, cryptocurrency wallet database files, and data from browser-based wallet extensions.
According to SlowMist, threat actors can subsequently work to decrypt the exfiltrated wallet database files offline by utilizing passwords extracted from the compromised machine, or they can substitute authentic Ledger and Trezor wallet applications with counterfeit versions designed to deceive users into providing their recovery phrases. The security research team successfully replicated the entire attack sequence within a controlled environment.
MacOS malware targets popular crypto wallets
SlowMist's analysis reveals that the malware integrates several distinct techniques into a unified attack sequence, providing threat actors with multiple pathways to successfully compromise cryptocurrency accounts and digital wallets.
The malicious program specifically targets software-based wallets such as Exodus, Atomic, Electrum, Wasabi and Monero, in addition to hardware wallet management applications like Ledger Live and Trezor Suite, SlowMist reported. The malware also conducts searches for wallet information maintained by full-node client software including Bitcoin Core, Litecoin Core, Dash Core and Dogecoin Core.
The two-step verification feature in Telegram fails to provide protection against this attack vector since the malware leverages an already authenticated local session rather than initiating a fresh login attempt, SlowMist explained. During their testing procedures, the research team successfully restored hijacked Telegram Desktop session information on a separate Mac computer without requiring a phone number entry, verification code, or two-step verification password.
SlowMist has advised users who believe their systems may have been infected to take immediate action by terminating all active Telegram sessions, creating a new trusted login session, and updating both their Telegram two-step verification password and Telegram Desktop Passcode. The security firm has additionally recommended that affected users generate a completely new recovery phrase on an uncompromised device and migrate all digital assets to freshly created addresses.