Back to news

New threat: hackers steal crypto wallet data via Telegram, bypassing 2FA

SlowMist specialists discovered macOS malware that intercepts Telegram Desktop sessions and bypasses two-factor authentication.

SlowMist security specialists have discovered malware for macOS that intercepts Telegram Desktop sessions, bypassing two-factor authentication.

Attackers collect Safari cookies, Apple notes, and browser extension data, then use stolen passwords to access crypto wallets and steal seed phrases.

The malware goes beyond simple password theft: it gathers all possible data to take over accounts and access crypto assets.

By copying active Telegram session data, hackers restore a session on another device without entering a phone number, confirmation code, or 2FA password.

2FA becomes useless because attackers use an already trusted local session.

Once they gain access to a Telegram account, hackers can read correspondence, impersonate the victim, and spread malicious links.

The malware targets Exodus, Atomic, Electrum, Wasabi, and Monero wallets, as well as Ledger Live and Trezor Suite applications.

It also searches for wallet data in full-node clients: Bitcoin Core, Litecoin Core, Dash Core, and Dogecoin Core.

The infected software can replace Ledger and Trezor apps with fake versions where users enter their seed phrases.

Expert recommendations

  1. End active Telegram sessions and set up a new login.
  2. Change your two-factor authentication password.
  3. Generate a new seed phrase only on a clean device.
  4. Move assets to new addresses not created on the compromised device.
  5. Do not store passwords and personal correspondence on the same device.

Previously, Kaspersky specialists reported on the OkoBot malware that steals credentials and seed phrases via Trezor Suite and Ledger.

WARNINGTronUSDTTX7f…3kP9BLOCKEDEthereumUSDC0xA1B2…9F00UNBLOCKEDTronUSDTTA4m…8rQ2BURNEDEthereumUSDC0x7C8D…21E4