macOS Infostealer Steals Telegram Sessions and Replaces Ledger and Trezor Wallet Apps
ID: 81b3beb5-64db-564f-ac8f-0468da1c105f
STIX ID: report--81b3beb5-64db-564f-ac8f-0468da1c105f
Feed Name: Cyber Press
Threat Score
SlowMist discovered a macOS information-stealing malware that collects Keychain items, browser credentials/cookies, Apple Notes, Telegram Desktop session files, and data from many cryptocurrency wallet apps; it uses a fake macOS admin prompt and local-session restoration to hijack Telegram accounts and deploy phishing-capable wallet replacements, with hosted payloads and logging endpoints observed (defanged IPs provided).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
