macOS Malware Targets Telegram Sessions and Crypto Wallets, Raising Security Concerns
macOS has long been viewed as a tougher target than Windows, yet the crypto community’s heavy reliance on personal computers for trading, DeFi, and Web3 activities has made it an increasingly attractive hunting ground. SlowMist’s analysis shows attackers are moving beyond conventional phishing emails and social‑engineering tricks. Instead, they deploy specialized malware that quietly harvests sensitive information without triggering obvious alerts.
The most alarming feature of the strain is its ability to capture Telegram session tokens. Telegram stores a session token that keeps users logged in across devices; once copied, the malware can log into the user’s account without a password or one‑time code. This grants attackers immediate access to private chats, group channels, and the power to impersonate project administrators or launch phishing campaigns against large communities.
Beyond session hijacking, the malware scans for cryptocurrency wallet data on the compromised Mac. It targets wallet configuration files, private‑key material, browser‑stored credentials, exchange login details, and other authentication data. Because blockchain transactions are irreversible, the loss of private keys or seed phrases can lead to permanent loss of funds. SlowMist highlighted that the malware’s focus on wallet‑related information makes it especially dangerous for users who keep substantial balances on internet‑connected devices.
Attackers spread the malware through a mix of social‑engineering tactics. SlowMist identified several methods, including fake cryptocurrency applications that appear legitimate but install the stealer, malicious links shared via messaging platforms such as Telegram, and counterfeit Web3 services that prompt users to download software or enter sensitive information. Similar infostealers—CrashStealer, discovered by Jamf Threat Labs, and Odyssey Infostealer, reported by CyberPress—have also been observed targeting macOS users during the same timeframe.
Security experts urge crypto users to adopt stricter security practices. Recommendations include installing software only from trusted sources, enabling multi‑factor authentication on all crypto accounts, avoiding unknown files or links in Telegram, keeping macOS and security software up to date, and storing long‑term holdings on hardware wallets. Users should also review wallet transactions regularly for suspicious activity and never share seed phrases or private keys, as legitimate services will never request them.
The emergence of this macOS malware campaign underscores that even operating systems with strong built‑in protections can be compromised when users are targeted through social engineering. While Apple’s security framework remains robust, the crypto sector’s continued growth and the high value of digital assets mean that attackers will likely refine their tactics. The industry must stay vigilant, and users should remain informed about new threats and best‑practice defenses.