logo

Hackers Don’t Crack Telegram 2FA—They Copy Your Already Logged-In Session

ID: cd940f7b-05d2-58e8-876e-df2fbef2855e

STIX ID: report--cd940f7b-05d2-58e8-876e-df2fbef2855e

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-17

Author: Tushar Subhra Dutta

...
...

A macOS information-stealing malware campaign exfiltrates Telegram Desktop session files and other sensitive data (Keychain, browser credentials, notes, and cryptocurrency wallet databases). By copying and restoring Telegram's local tdata files to another Mac, attackers can resume authenticated sessions and bypass Telegram two-step verification; additionally, attackers deploy fake wallet applications and prompts to harvest recovery phrases and passwords. SlowMist reproduced the attack and provided IoCs (IP addresses, URLs, and SHA-256 hashes) for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.