Eilmeldung
ESIncendio forestal en el Valle del Tiétar y Sierra Oeste de Madrid: Evacuaciones masivas y lucha contra el fuegoESTadej Pogacar pulveriza el récord del Alpe d'Huez en un Tour de Francia marcado por la multitudESIncendio en la Vall d'Uixó: más de 6.500 hectáreas quemadas y 16.000 desalojadosESAagesen pide precaución ante fuegos y la posible llegada de la cuarta ola de calor en EspañaESIncendios en Ávila, Madrid y Toledo: Evolución y datos clave según satélites de CopernicusESIncidio en Gironda: Más de 200.000 evacuados y 42.000 hectáreas calcinadasESIncendios en España: Solidaridad y Unidad ante la CatástrofeESIncendios en España: 39 carreteras secundarias cortadas e intransitablesESSánchez anuncia declaración de zonas gravemente afectadas por incendios tras superar las 150.000 hectáreas calcinadasESGiro inesperado en el caso Plus Ultra: dimisión de directivos y nuevas investigacionesESIncendio forestal en el Valle del Tiétar y Sierra Oeste de Madrid: Evacuaciones masivas y lucha contra el fuegoESTadej Pogacar pulveriza el récord del Alpe d'Huez en un Tour de Francia marcado por la multitudESIncendio en la Vall d'Uixó: más de 6.500 hectáreas quemadas y 16.000 desalojadosESAagesen pide precaución ante fuegos y la posible llegada de la cuarta ola de calor en EspañaESIncendios en Ávila, Madrid y Toledo: Evolución y datos clave según satélites de CopernicusESIncidio en Gironda: Más de 200.000 evacuados y 42.000 hectáreas calcinadasESIncendios en España: Solidaridad y Unidad ante la CatástrofeESIncendios en España: 39 carreteras secundarias cortadas e intransitablesESSánchez anuncia declaración de zonas gravemente afectadas por incendios tras superar las 150.000 hectáreas calcinadasESGiro inesperado en el caso Plus Ultra: dimisión de directivos y nuevas investigaciones
Newsgather
ZurückmacOS Malware Targets Crypto Wallets, Steals Telegram Sessions
macOS Malware Targets Crypto Wallets, Steals Telegram Sessions
Technik
Cointelegraph19.7.2026Technik2 Min. Lesezeit

macOS Malware Targets Crypto Wallets, Steals Telegram Sessions

Auf einen Blick

A macOS malware steals data from Keychain, Safari, Apple Notes, Telegram Desktop, and 13+ crypto wallets, compromising sessions and wallets even with 2FA, as discovered by SlowMist.

KI-generierte Zusammenfassung

Warum es wichtig ist

The malware attack leverages multiple vulnerabilities in macOS and crypto wallet security.

Schriftgröße

A macOS information-stealing malware can hijack Telegram Desktop sessions and compromise cryptocurrency wallets, according to blockchain security firm SlowMist. The malware harvests data from the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and databases associated with more than a dozen cryptocurrency wallets. After collecting passwords and authenticated sessions, the malware copies users’ authenticated Telegram Desktop session data, wallet databases and browser wallet extension data. SlowMist said attackers can then attempt to decrypt the stolen wallet databases offline using passwords harvested from the infected device or replace legitimate Ledger and Trezor applications with fake versions that trick users into entering their recovery phrases. The security firm reproduced the attack chain in an isolated environment. MacOS malware code used to steal keys and passwords. Source: SlowMist Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner says MacOS malware targets popular crypto wallets According to SlowMist, the malware combines multiple techniques into a coordinated attack chain, allowing attackers to pursue different methods of compromising cryptocurrency accounts and wallets. The malware targets software wallets including Exodus, Atomic, Electrum, Wasabi and Monero, as well as hardware wallet applications such as Ledger Live and Trezor Suite, according to SlowMist. It also searches for wallet data stored by full-node clients including Bitcoin Core, Litecoin Core, Dash Core and Dogecoin Core. Telegram two-step verification does not prevent the attack because the malware reuses an authenticated local session instead of creating a new login, according to SlowMist. In tests, researchers restored stolen Telegram Desktop session data on another Mac without entering a phone number, verification code or two-step verification password. SlowMist urged users who suspect their devices have been compromised to immediately terminate existing Telegram sessions, establish a new trusted login and change both their Telegram two-step verification password and Telegram Desktop Passcode. The company also recommended generating a new recovery phrase on a clean device and transferring all assets to new addresses.

Worauf zu achten ist

KI-Ausblick — Möglichkeiten, keine Fakten

  • Increased reports of similar malware targeting crypto wallets

    Wahrscheinlich · Innerhalb von Wochen

Offene Fragen

  • How widespread is the malware?
  • What is the origin of the malware?

Verwandte Themen

This article was originally published by Cointelegraph.

Ähnliche Meldungen

Mehr zu diesem ThemamacOS malware