Tue, 21 Jul
34°C

New Delhi

Partly Cloudy
Feels Like
38°C
Humidity
62%
Wind Speed
14 km/h
Visibility
8 km
UV Index
8 (Moderate)
Pressure
1008 hPa
Hourly Forecast
21:00
34°C
20%
22:00
34°C
25%
23:00
33°C
30%
0:00
33°C
35%
1:00
32°C
40%
2:00
32°C
45%
7-Day Forecast
Today
Partly Cloudy
26°C
35°C
Tue
Partly Cloudy
26°C
35°C
Wed
Partly Cloudy
26°C
35°C
Thu
Partly Cloudy
26°C
34°C
Fri
Partly Cloudy
27°C
34°C
Sat
Partly Cloudy
27°C
34°C
Sun
Partly Cloudy
27°C
33°C
Daily News Insights LogoDaily News Insights Logo
BREAKING
Daily News Insights: AI-Powered News Platform — Updated On DemandBreaking coverage from India and the world, synthesized by Gemini 1.5 FlashLive pipeline: Firecrawl extraction • Supabase storage • Upstash caching
Home/Tech

New macOS Malware Hijacks Telegram Sessions to Drain Cryptocurrency Wallets

DNI
Daily News Insights Editorial Desk
MONDAY, 20 JULY 2026 AT 02:31 PM·4 MIN READ
New macOS Malware Hijacks Telegram Sessions to Drain Cryptocurrency Wallets
Wikimedia
IMAGE: DAILY NEWS INSIGHTS / NEWS DATA LABS

DNI SUMMARY — KEY POINTS

  • Security researchers at SlowMist have identified a sophisticated macOS malware campaign that bypasses standard authentication by hijacking active Telegram Desktop session files directly from infected systems.
  • The malicious software extracts sensitive data including browser credentials, system Keychain entries, and Apple Notes, which attackers then use to decrypt local cryptocurrency wallet databases offline.
  • Beyond simple credential theft, the malware actively replaces legitimate hardware wallet applications with malicious clones that masquerade as official software to facilitate further financial exploitation.
  • The attack method is particularly dangerous because it avoids traditional login triggers like two-step verification, effectively allowing hackers to impersonate users without needing secondary authentication codes.
  • Victims are being urged by industry experts to immediately terminate all active Telegram sessions and move their digital assets to entirely new wallets on uncompromised hardware.
IN-DEPTH ANALYSIS
TechFinanceScience

A dangerous new campaign targeting macOS users has emerged, combining Telegram session hijacking with advanced cryptocurrency theft tactics. Security firm SlowMist revealed that the malware does not rely on traditional brute-force tactics but instead copies authenticated session files directly from the local file system. This allows threat actors to replicate a victim’s environment on a secondary device, granting them immediate access to private chats and trading data without needing a password or SMS code. The operation represents a significant escalation in how cybercriminals leverage messaging apps to compromise financial accounts.

Exploiting Authenticated Messaging Sessions

The malware acts as a comprehensive information stealer that probes deep into the operating system for high-value data. It harvests Keychain credentials, browser cookies, and even sensitive text stored within Apple Notes. By aggregating these disparate data points, the attackers can build a profile of the user that includes not only communication history but also the necessary keys to unlock protected files. Once the researchers analyzed the execution flow, they discovered that the software is specifically designed to perform these tasks silently in the background, minimizing the chances of discovery by the victim.

The primary mechanism for financial theft involves the decryption of local cryptocurrency wallet databases. Rather than attempting to break encryption in real time on the victim’s machine, the malware extracts encrypted files and sends them to a remote server. The attackers then use passwords collected from the macOS environment to decrypt these databases offline. This multi-stage approach ensures that even well-protected software wallets, including Exodus and Atomic, are vulnerable to total compromise if the host machine has been infected by this specialized script.

The malware extracts authenticated Telegram session files to bypass security measures without requiring verification codes or secondary passwords.

Targeting Local Wallet Databases

Sophistication levels rise significantly when the malware shifts from data exfiltration to active social engineering through application replacement. The attackers have engineered a system to remove legitimate software such as Ledger Live or Trezor Suite from the applications folder. In their place, they install lightweight clones that use WKWebView to mimic the appearance of a real wallet. These fake applications are essentially hollow shells designed to capture user input or serve as a deceptive interface to lure victims into revealing recovery phrases.

The delivery method often involves deceptive tactics, such as hosting fake community applications on sites like Google Sites to trick users into downloading malicious scripts. Victims are prompted to execute commands in the Terminal under the guise of security verification or update processes. These prompts mimic official administrative requests, which can fool even experienced users into granting the necessary permissions. Once those permissions are granted, the malware achieves full system visibility, allowing it to bypass native protections that would otherwise prevent unauthorized access to sensitive local storage.

Replacing Official Wallet Software

This attack vector highlights the growing necessity for heightened security vigilance among those who manage digital assets on desktop computers. Because the malware exploits an already authenticated session, it effectively renders the platform's native two-factor authentication features useless. Users who believe their accounts are secure because they have enabled secondary checks are often the most surprised when their assets disappear. The ability of the malware to hide its presence from the active-session list makes it even more difficult for individuals to realize they have been compromised until the damage is already done.

Researchers identified that the campaign targets at least 16 different desktop cryptocurrency wallets and numerous browser-based wallet extensions.

Industry analysts emphasize that changing a wallet password is insufficient once a recovery phrase or private key has been exposed. The SlowMist report explicitly warns that affected users must generate new recovery phrases on clean devices to restore security to their holdings. This process is time-consuming and cumbersome, but it remains the only viable path to mitigating the risk of future theft. The nature of these attacks underscores the critical flaw in storing high-value digital assets on devices that are frequently exposed to third-party software and internet traffic.

Defending Against Desktop Malware

Moving forward, the cybersecurity community expects to see similar patterns adopted by other criminal syndicates as they refine their methods for targeting desktop environments. The reliance on AppleScript and legitimate-looking installers makes detection difficult for standard antivirus software that relies on signature-based scanning. As the threat landscape evolves, users are encouraged to strictly limit the installation of software from unverified sources and to treat any unsolicited update requests, especially those related to cryptocurrency wallets, with extreme skepticism to prevent unauthorized data loss.

KEY TAKEAWAYS

Attackers successfully use passwords harvested from the macOS Keychain and Apple Notes to decrypt stolen wallet databases offline.

The malware replaces legitimate hardware wallet software with deceptive clones built on the WKWebView framework to facilitate phishing attacks.

How do you feel about this story?

Share This Story

Choose a platform to share this article