Última hora
DEKrieg in Nahost: Irans Nachbarn suchen Alternativrouten zur Straße von HormusUSSupreme Court to Review Alaska Pilot's Claim Over Plane Seizure for BeerFRL'UE propose de suspendre les amendes sur les émissions de méthane pour les importateurs d'hydrocarburesUSAmerican Oystercatcher Population Recovers, Faces New Threats from Climate Change and ESA ChangesFRAndy Burnham nommé Premier ministre du Royaume-Uni par Charles IIICN中聯油脂七批原油苯並芘超標 食藥署將修法加強食安管理UKOfcom Launches Investigation into Married at First Sight UK Following Rape AllegationsRUДональд Трамп пригрозил Ирану жестким ответом за убийство американских солдатARالولايات المتحدة تعتزم إرسال طائرات مقاتلة إضافية إلى الشرق الأوسطINBangladesh Army Chief Visits Turkiye for Military Training and Hardware PartnershipsDEKrieg in Nahost: Irans Nachbarn suchen Alternativrouten zur Straße von HormusUSSupreme Court to Review Alaska Pilot's Claim Over Plane Seizure for BeerFRL'UE propose de suspendre les amendes sur les émissions de méthane pour les importateurs d'hydrocarburesUSAmerican Oystercatcher Population Recovers, Faces New Threats from Climate Change and ESA ChangesFRAndy Burnham nommé Premier ministre du Royaume-Uni par Charles IIICN中聯油脂七批原油苯並芘超標 食藥署將修法加強食安管理UKOfcom Launches Investigation into Married at First Sight UK Following Rape AllegationsRUДональд Трамп пригрозил Ирану жестким ответом за убийство американских солдатARالولايات المتحدة تعتزم إرسال طائرات مقاتلة إضافية إلى الشرق الأوسطINBangladesh Army Chief Visits Turkiye for Military Training and Hardware Partnerships
Newsgather
AtrásmacOS Malware Targets Crypto Wallets, Steals Telegram Sessions
macOS Malware Targets Crypto Wallets, Steals Telegram Sessions
Tecnología
CointelegraphayerTecnología2 min de lectura

macOS Malware Targets Crypto Wallets, Steals Telegram Sessions

En resumen

A macOS malware steals data from Keychain, Safari, Apple Notes, Telegram Desktop, and 13+ crypto wallets, compromising sessions and wallets even with 2FA, as discovered by SlowMist.

Resumen generado por IA

Por qué importa

The malware attack leverages multiple vulnerabilities in macOS and crypto wallet security.

Tamaño de fuente

A macOS information-stealing malware can hijack Telegram Desktop sessions and compromise cryptocurrency wallets, according to blockchain security firm SlowMist. The malware harvests data from the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and databases associated with more than a dozen cryptocurrency wallets. After collecting passwords and authenticated sessions, the malware copies users’ authenticated Telegram Desktop session data, wallet databases and browser wallet extension data. SlowMist said attackers can then attempt to decrypt the stolen wallet databases offline using passwords harvested from the infected device or replace legitimate Ledger and Trezor applications with fake versions that trick users into entering their recovery phrases. The security firm reproduced the attack chain in an isolated environment. MacOS malware code used to steal keys and passwords. Source: SlowMist Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner says MacOS malware targets popular crypto wallets According to SlowMist, the malware combines multiple techniques into a coordinated attack chain, allowing attackers to pursue different methods of compromising cryptocurrency accounts and wallets. The malware targets software wallets including Exodus, Atomic, Electrum, Wasabi and Monero, as well as hardware wallet applications such as Ledger Live and Trezor Suite, according to SlowMist. It also searches for wallet data stored by full-node clients including Bitcoin Core, Litecoin Core, Dash Core and Dogecoin Core. Telegram two-step verification does not prevent the attack because the malware reuses an authenticated local session instead of creating a new login, according to SlowMist. In tests, researchers restored stolen Telegram Desktop session data on another Mac without entering a phone number, verification code or two-step verification password. SlowMist urged users who suspect their devices have been compromised to immediately terminate existing Telegram sessions, establish a new trusted login and change both their Telegram two-step verification password and Telegram Desktop Passcode. The company also recommended generating a new recovery phrase on a clean device and transferring all assets to new addresses.

Qué observar

Perspectiva de IA — posibilidades, no hechos

  • Increased reports of similar malware targeting crypto wallets

    Probable · En semanas

Preguntas abiertas

  • How widespread is the malware?
  • What is the origin of the malware?

Temas relacionados

This article was originally published by Cointelegraph.

Noticias relacionadas

Contractor linked to North Korea worked on MetaMask code
Tecnología·hace 20 horas

Contractor linked to North Korea worked on MetaMask code

A contractor, later linked to North Korea, worked on MetaMask code for Consensys from March to April before access was terminated. Consensys's investigation found no asset or data misappropriation, malicious code, or impact on user safety. The incident highlights the need for rigorous third-party contractor security, including identity verification, least-privilege access, and continuous monitoring.

CryptoSlate
2 min de lectura
Más sobre este temamacOS malware