Fintech

New macOS Malware Steals Telegram Credentials and Targets Crypto Wallets

Blockchain security firm SlowMist has identified new macOS malware that steals Telegram credentials and crypto wallet data.

By Tim Editorial

New macOS Malware Steals Telegram Credentials and Targets Crypto Wallets
s3-images.ctmedia.io

Blockchain security firm SlowMist has identified a new malware strain targeting Apple's macOS operating system. The malware is designed to steal login credentials in order to hijack users' Telegram sessions, and can also decrypt cryptocurrency wallets or trick victims into entering their wallet recovery phrases through fake applications. This method allows attackers to directly access victims' crypto assets. SlowMist's report did not specify which cryptocurrency wallet variants are targeted, but phishing through fake applications is a common attack vector in the digital asset ecosystem. The attack highlights security vulnerabilities on macOS, a platform long considered more secure than other operating systems. Telegram users who also store or manage crypto assets are primary targets.

No reports have yet emerged regarding the number of victims or the value of losses incurred. SlowMist recommends that users remain vigilant against suspicious applications and avoid entering wallet recovery phrases on untrusted devices. This development adds to the growing list of cyber threats targeting the crypto industry, where phishing and malware remain the primary methods for stealing digital assets. The malware operates by first compromising the user's macOS system, often through social engineering or by masquerading as a legitimate application. Once installed, it can extract Telegram session tokens stored locally, allowing the attacker to take over the user's account without needing a password or two factor authentication code. This technique, known as session hijacking, is particularly dangerous because it bypasses standard security measures.

In addition to Telegram hijacking, the malware targets cryptocurrency wallets. It can either decrypt wallet files stored on the device or display fake wallet interfaces that prompt the user to enter their recovery phrase. A recovery phrase, also known as a seed phrase, is a set of words that can restore full access to a cryptocurrency wallet. By capturing this phrase, the attacker can import the victim's wallet onto their own device and drain all funds. SlowMist's analysis indicates that the malware is sophisticated and likely the work of an organized cybercriminal group. The firm has not disclosed the exact distribution method, but it may involve malicious advertisements, compromised software downloads, or phishing emails.

Users are advised to download software only from official sources and to verify the authenticity of any application before installation. The emergence of this malware underscores a broader trend of increasing cyberattacks on macOS. While historically less targeted than Windows, macOS has seen a rise in malware as Apple's market share grows and as more high value users, including cryptocurrency investors, adopt the platform. Security experts warn that macOS users should not assume they are immune to such threats. For Telegram users, the risk is particularly acute because the platform is widely used in the cryptocurrency community for trading signals, project announcements, and peer to peer transactions. A hijacked Telegram account can be used to spread phishing links, solicit funds from contacts, or impersonate trusted individuals.

SlowMist has not yet released specific indicators of compromise or detection tools, but it is working with other security firms to track the malware's spread. The company urges users to enable two factor authentication on Telegram and to use hardware wallets for storing significant amounts of cryptocurrency. Hardware wallets store private keys offline, making them immune to malware that targets software wallets. This incident follows a series of high profile crypto thefts in 2023 and 2024, including the Lazarus Group's attacks on cross chain bridges and phishing campaigns targeting NFT holders. The total value lost to crypto related cybercrime in 2023 exceeded style="background-color: #ffffff;".7 billion, according to Chainalysis. Phishing and malware accounted for a significant portion of these losses. As the crypto industry matures, attackers are continuously refining their methods.

The SlowMist report serves as a reminder that security is a shared responsibility between platforms, developers, and users. While macOS and Telegram have robust security features, they are not foolproof against determined attackers. In response to the report, Telegram has not yet issued a public statement. However, the company has previously advised users to enable two factor authentication and to log out of active sessions on untrusted devices. Apple has also not commented, but the company regularly updates macOS with security patches. Users who suspect they may be infected should run a full system scan with reputable antivirus software, change their Telegram password immediately, and revoke all active sessions from the Telegram settings.

For cryptocurrency wallets, transferring funds to a new wallet with a fresh recovery phrase is recommended. The SlowMist report is a critical contribution to the cybersecurity community's understanding of evolving threats. It provides detailed technical analysis that can help other security researchers develop defenses. The firm has a track record of identifying major security flaws in blockchain projects, including the 2023 attack on the Multichain bridge. As the investigation continues, SlowMist will likely release more information about the malware's command and control infrastructure and potential links to known threat actors. In the meantime, the best defense is vigilance and adherence to security best practices.

Sources and references