A newly identified strain of macOS malware is targeting cryptocurrency users by hijacking Telegram sessions, decrypting digital wallets and tricking victims into surrendering their recovery phrases, according to blockchain security firm SlowMist.
How the Malware Works
The malicious software is designed to harvest credentials from infected Apple computers, giving attackers the ability to seize control of active Telegram sessions. Once inside, the malware can move to compromise cryptocurrency holdings by decrypting locally stored wallet data.
Beyond stealing session information, the malware employs social engineering tactics. Victims are lured into entering their wallet recovery phrases through counterfeit applications that mimic legitimate software, according to SlowMist's analysis.
Once a recovery phrase is exposed, an attacker gains full and irreversible control over a victim's cryptocurrency holdings.
The combination of session hijacking and phishing-style deception makes the threat especially dangerous, as it attacks multiple points of a user's security setup at once.
Why Crypto Users Are at Risk
Cryptocurrency holders remain prime targets for cybercriminals because transactions on blockchain networks are largely irreversible. Unlike traditional banking, there is often no way to claw back funds once they have been transferred out of a compromised wallet.
The reliance on recovery phrases — the master keys to self-custodied wallets — creates a single point of failure. If those phrases are captured, an attacker can drain an account regardless of other protections in place.
Security researchers have repeatedly warned that macOS, once considered relatively insulated from malware, is increasingly in the crosshairs as more high-value users adopt Apple devices for managing digital assets.
Protecting Against the Threat
To reduce exposure, security experts recommend users take several precautions:
- Never enter recovery phrases into any application or website
- Download software only from official, verified sources
- Be wary of unexpected prompts asking for wallet credentials
- Keep operating systems and security tools up to date
SlowMist's findings underscore the ongoing arms race between cybercriminals and the crypto community, where attackers continually adapt their methods to exploit both technical vulnerabilities and human error. Vigilance around unofficial downloads and credential requests remains one of the strongest defenses available to users.
