Son Dakika
ARما أهمية مضيق باب المندب بعد إعلان الحوثيين فرض "حصار بحري" على السعودية؟ARعطل يضرب "فيسبوك" يمنع الآلاف حول العالم من الوصول إلى حساباتهمARترامب يهدد بتدمير البنية التحتية الإيرانية في مضيق هرمزARميّار شريف تتأهل لدور الـ32 في بطولة التنسARموجة حر قياسية وانقطاعات كهرباء متواترة تثير غضباً في تونسARاحتجاجات في إيطاليا بعد وفاة شاب مغربي أثناء اعتقالهARتأثير الانتخابات الإسرائيلية على مصر والأردن والقضية الفلسطينيةARترامب وافق على اتفاق نووي تاريخي مع السعوديةARعائلة الملازم الأمريكي تايلر فيهان تتذكر حياته بعد مقتله في الأردنARارتفاع حصيلة قتلى الهجوم إلى 3 عسكريين أمريكيينARما أهمية مضيق باب المندب بعد إعلان الحوثيين فرض "حصار بحري" على السعودية؟ARعطل يضرب "فيسبوك" يمنع الآلاف حول العالم من الوصول إلى حساباتهمARترامب يهدد بتدمير البنية التحتية الإيرانية في مضيق هرمزARميّار شريف تتأهل لدور الـ32 في بطولة التنسARموجة حر قياسية وانقطاعات كهرباء متواترة تثير غضباً في تونسARاحتجاجات في إيطاليا بعد وفاة شاب مغربي أثناء اعتقالهARتأثير الانتخابات الإسرائيلية على مصر والأردن والقضية الفلسطينيةARترامب وافق على اتفاق نووي تاريخي مع السعوديةARعائلة الملازم الأمريكي تايلر فيهان تتذكر حياته بعد مقتله في الأردنARارتفاع حصيلة قتلى الهجوم إلى 3 عسكريين أمريكيين
Newsgather
GerimacOS Malware Targets Crypto Wallets, Steals Telegram Sessions
macOS Malware Targets Crypto Wallets, Steals Telegram Sessions
Teknoloji
Cointelegraph3 gün önceTeknoloji2 dk okuma

macOS Malware Targets Crypto Wallets, Steals Telegram Sessions

Hızlı Bakış

A macOS malware steals data from Keychain, Safari, Apple Notes, Telegram Desktop, and 13+ crypto wallets, compromising sessions and wallets even with 2FA, as discovered by SlowMist.

Yapay zekâ özeti

Neden Önemli?

The malware attack leverages multiple vulnerabilities in macOS and crypto wallet security.

Yazı boyutu

A macOS information-stealing malware can hijack Telegram Desktop sessions and compromise cryptocurrency wallets, according to blockchain security firm SlowMist. The malware harvests data from the macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and databases associated with more than a dozen cryptocurrency wallets. After collecting passwords and authenticated sessions, the malware copies users’ authenticated Telegram Desktop session data, wallet databases and browser wallet extension data. SlowMist said attackers can then attempt to decrypt the stolen wallet databases offline using passwords harvested from the infected device or replace legitimate Ledger and Trezor applications with fake versions that trick users into entering their recovery phrases. The security firm reproduced the attack chain in an isolated environment. MacOS malware code used to steal keys and passwords. Source: SlowMist Related: AI has not triggered DeFi ‘hackpocalypse,’ Dragonfly partner says MacOS malware targets popular crypto wallets According to SlowMist, the malware combines multiple techniques into a coordinated attack chain, allowing attackers to pursue different methods of compromising cryptocurrency accounts and wallets. The malware targets software wallets including Exodus, Atomic, Electrum, Wasabi and Monero, as well as hardware wallet applications such as Ledger Live and Trezor Suite, according to SlowMist. It also searches for wallet data stored by full-node clients including Bitcoin Core, Litecoin Core, Dash Core and Dogecoin Core. Telegram two-step verification does not prevent the attack because the malware reuses an authenticated local session instead of creating a new login, according to SlowMist. In tests, researchers restored stolen Telegram Desktop session data on another Mac without entering a phone number, verification code or two-step verification password. SlowMist urged users who suspect their devices have been compromised to immediately terminate existing Telegram sessions, establish a new trusted login and change both their Telegram two-step verification password and Telegram Desktop Passcode. The company also recommended generating a new recovery phrase on a clean device and transferring all assets to new addresses.

Bundan Sonra Ne Olabilir?

Yapay zekâ öngörüsü — kesinlik taşımaz

  • Increased reports of similar malware targeting crypto wallets

    Muhtemel · Haftalar içinde

Açık Sorular

  • How widespread is the malware?
  • What is the origin of the malware?

İlgili Konular

Bu haber ilk olarak şurada yayınlandı: Cointelegraph.

İlgili Haberler

Cardano-linked Midnight bridge exploit drains 515M NIGHT tokens, ADA defies sell-off
Gelişiyor·1 saat önce

Cardano-linked Midnight bridge exploit drains 515M NIGHT tokens, ADA defies sell-off

An exploit on a Wanchain-operated bridge connected to the Cardano ecosystem resulted in the theft of approximately 515 million NIGHT tokens, causing a 30% price drop for NIGHT. The Midnight Foundation confirmed its core protocol was unaffected, and major exchanges collaborated to freeze stolen assets. Cardano's ADA token, however, defied the sell-off, climbing nearly 8%.

CryptoSlate
6 dk okuma
Bu konuda daha fazlamacOS malware