MacOS malware hijacks Telegram sessions, targets crypto

MacOS malware hijacks Telegram sessions, targets crypto helps explain what this update means for Telegram Mini Apps, users, and developers across the TON

MacOS malware hijacks Telegram sessions, targets crypto remains the main reference point for users and Telegram Mini App developers following this update.

A newly identified malware strain has been found targeting macOS users by stealing credentials and hijacking Telegram Desktop sessions to access cryptocurrency wallets. Security firm SlowMist reports this malware extracts sensitive data from a Mac device’s Keychain, Safari cookies, Apple Notes, Telegram session files, and databases tied to more than a dozen wallet applications. Attackers leverage this information to decrypt wallet databases and, in some cases, trick users into revealing their recovery phrases with convincing fake applications.

One of the most dangerous features is its ability to restore Telegram Desktop sessions on a different Mac without needing a phone number or additional verification. Two-step verification does not help in these cases, as the attack relies on copying existing authenticated session files rather than triggering a new login. Beyond Telegram, the malware searches for and duplicates wallet files from software wallets like Exodus and Electrum, hardware wallet apps including Ledger Live, and full-node clients such as Bitcoin Core and Litecoin Core.

How the macOS Malware Steals Telegram and Wallet Data

Analysis from SlowMist details the malware’s attack path: it first extracts macOS Keychain items, browser data, Apple Notes, and authenticated Telegram Desktop session files. This allows attackers to bypass standard authentication methods by restoring the session elsewhere for instant access.

The malware seeks out wallet databases and browser extension profiles from applications like Exodus, Atomic, Electrum, Wasabi, Monero, and extension-based wallets. It also scans for full node client data, such as Bitcoin Core and Dogecoin Core. Once collected, attackers attempt to unlock these wallets offline using passwords harvested from the Keychain and browser.

A further attack vector comes from fraudulent, lookalike versions of hardware wallet apps (e.g., Ledger Live, Trezor Suite) designed to trick victims into entering recovery phrases. With this information, attackers can drain wallets or transfer funds without any further user interaction.

Affected Wallets and Attack Methods

Software targets include Exodus, Atomic, Electrum, Wasabi, and Monero, along with data associated with hardware wallet management tools like Ledger Live and Trezor Suite. The malware also searches for full-node wallet databases (Bitcoin Core, Litecoin Core, Dash Core, Dogecoin Core). By collecting information from the macOS Keychain, browser cookies, notes, and other sources, the risk extends to anyone storing sensitive keys or passwords on a Mac.

Once a device is infected, the malware captures active Telegram sessions and passwords, enabling offline decryption of wallet databases or phishing attempts via fake wallet apps. Telegram’s two-step verification does not prevent this method, as attackers use session files, not login attempts. This means that an attacker can take over an authenticated Telegram Desktop session on a new device without any notification or prompt for additional credentials.

TON Drop Hub take: Users relying on Telegram sessions for any crypto authentication on macOS face increased risk. If you use any wallet app called out in the SlowMist report, review device security, terminate all active Telegram Desktop sessions, and reinstall wallets only from verified, official channels.

Security Steps for Infected Users

Because the malware can export session data and restore it on a different device, traditional security methods like SMS verification or two-step passwords offer no protection once a Mac is compromised. Attackers target over a dozen wallet platforms and can remain undetected by mimicking normal device fingerprints or clearing logs.

Signs of compromise include Telegram activity that does not match your own, new sessions in Telegram’s "Active Sessions" list, or unexpected prompts to enter wallet recovery phrases—especially in apps claiming to be hardware wallet managers. The full extent and distribution channel of this malware remain unclear, though lab tests confirm the attack’s core mechanisms.

To check for compromise, users should do the following:

  • Review Telegram’s "Active Sessions" for unknown devices.
  • Audit password vaults and Keychain for unfamiliar access.
  • Reinstall wallet and Telegram Desktop applications only from trusted, official sources.
  • Reset wallet recovery phrases and credentials if there are any signs of unauthorized access or suspicious behavior.

TON Drop Hub take: The unique ability of this malware to silently hijack authenticated Telegram Desktop sessions raises new risks. For users interacting with crypto wallets or browser extensions on macOS, standard recovery steps may not suffice. Resetting all session tokens and wallet credentials is necessary if compromise is suspected. Be wary of any prompts for recovery phrases, and only download wallet applications from official channels to avoid fakes that play a central role in these attacks.

For more updates, explore Latest TON news.

MacOS malware hijacks Telegram sessions, targets crypto remains the main reference point for users and Telegram Mini App developers following this update.

MacOS malware hijacks Telegram sessions, targets crypto remains the main reference point for users and Telegram Mini App developers following this update.

Source reference: original source.