Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

MacOS malware hijacks Telegram sessions, targets crypto wallets

A newly identified macOS malware steals authenticated session files for Telegram Desktop, bypassing standard login credentials and two-factor authentication, and exfiltrates data from numerous cryptocurrency wallet applications. The attack vector involves users being socially engineered into pasting malicious commands into the Terminal. No patch is available; immediate remediation requires terminating all active Telegram sessions, changing associated passwords, and moving cryptocurrency funds to new wallets on uncompromised devices.
Read Full Article →

Malware MacOS malware hijacks Telegram sessions, targets crypto wallets July 17, 2026 Share By SC Staff MacOS users are facing a new security threat from malware capable of hijacking Telegram Desktop sessions and stealing cryptocurrency wallet data. The malware, discovered by SlowMist researchers, exploits authenticated session files, bypassing standard security measures, according to Coin Central. The macOS malware targets information stored locally on infected devices, including passwords, browser cookies, Apple Notes and Telegram Desktop session files. Instead of breaking login credentials, the malware copies existing authenticated session data. This allows attackers to restore access to a Telegram account on a different device without needing the user's phone number, verification codes, or even the two-step verification password, as the copied session bypasses these checks. The attack also targets popular cryptocurrency wallet applications such as Exodus, Atomic, Electrum, Wasabi, and Monero, as well as hardware wallet applications like Ledger Live and Trezor Suite. It also searches for full-node wallet databases for Bitcoin Core, Litecoin Core, Dash Core, and Dogecoin Core. SlowMist advises users to immediately terminate all active Telegram sessions, change their two-step verification password and Telegram Desktop passcode, and move any funds from potentially compromised wallets to new, clean wallets on uncompromised devices. Source: Coin Central SC Staff Related Malware New macOS stealer uses social engineering and coercion SC Staff July 17, 2026 The attack chain begins when a victim pastes a command into their Terminal, often lured by a ClickFix page. Malware Daxin malware resurfaces with new backdoor targeting Taiwan manufacturer SC Staff July 16, 2026 The kernel-mode rootkit, Daxin, first documented in March 2022, was found operating on a compromised host in Taiwan in 2026. Malware New TELEPUZ malware spreads via ClickFix lures SC Staff July 16, 2026 TELEPUZ is a lightweight and modular malware, likely developed by a small team and potentially offered as a malware-as-a-service. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article