macOS Malware Hijacks Telegram Sessions and Crypto Wallets, SlowMist Warns

A newly identified macOS malware is capable of stealing authenticated Telegram sessions, draining cryptocurrency wallets, and deceiving users into surrendering their wallet recovery phrases — all through a coordinated, multi-stage attack chain, blockchain security firm SlowMist has disclosed.

The threat is notable for its breadth. Rather than relying on a single exploit, the malware pulls data from multiple sensitive sources on an infected Mac, combining them to give attackers several paths toward financial theft.

How the Attack Works

Once installed on a macOS device, the malware begins harvesting credentials from the macOS Keychain, Safari cookies, Apple Notes, and Telegram Desktop session files. It also targets databases linked to more than a dozen cryptocurrency wallets.

MacOS malware code used to steal keys and passwords. Source: SlowMist

With that data in hand, attackers have options. They can attempt to decrypt stolen wallet databases offline using passwords lifted directly from the victim's machine. Alternatively, they can swap out legitimate Ledger and Trezor desktop applications with convincing fakes designed to capture users' recovery phrases. SlowMist confirmed it reproduced the full attack sequence in an isolated test environment.

Wallets and Apps in the Crosshairs

The malware casts a wide net across the crypto software ecosystem. Software wallets targeted include Exodus, Atomic, Electrum, Wasabi, and Monero. Hardware wallet companion apps — specifically Ledger Live and Trezor Suite — are also in scope.

Beyond hot wallets, the malware scans for data stored by full-node clients: Bitcoin Core, Litecoin Core, Dash Core, and Dogecoin Core are all affected. That range suggests the threat actor behind the campaign is casting a deliberate, wide net across both casual and technical crypto users.

Telegram's Two-Step Verification Offers No Protection

One of the more alarming findings from SlowMist's research is that Telegram's two-step verification does nothing to block this particular attack. The malware doesn't attempt a fresh login — it simply copies and reuses an already-authenticated local session from the compromised machine.

In controlled tests, SlowMist researchers transferred stolen Telegram Desktop session data to a separate Mac and regained full account access without entering a phone number, a verification code, or a two-step password. The existing session was accepted as legitimate.

Why It Matters

This malware illustrates how attackers are moving beyond single-vector exploits toward layered campaigns that hedge their bets. If one avenue — say, decrypting a wallet database — fails, they pivot to another, such as swapping in a fake hardware wallet app. macOS users, who have historically enjoyed a relatively lower threat profile than Windows users, face a growing number of sophisticated, crypto-focused threats.

The financial stakes are high. A successful attack could hand an adversary complete control over both a victim's Telegram identity and their digital assets simultaneously.

What Affected Users Should Do

SlowMist urged anyone who suspects their Mac has been compromised to act quickly on several fronts. First, terminate all active Telegram sessions immediately and establish a fresh, trusted login. Both the Telegram two-step verification password and the Telegram Desktop Passcode should be changed without delay.

On the crypto side, the firm recommended generating a entirely new recovery phrase on a clean, uncompromised device and transferring all holdings to freshly created wallet addresses. Continuing to use existing addresses or seed phrases after a suspected breach carries significant risk.