Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft
ID: adc367a1-70d9-57b8-a391-05a084291e49
STIX ID: report--adc367a1-70d9-57b8-a391-05a084291e49
Feed Name: GBHackers
A macOS-targeting infostealer campaign collects encrypted wallet databases, Keychain entries, browser passwords, Apple Notes, and Telegram Desktop session files to enable offline cracking of cryptocurrency wallets and direct account takeover. Researchers demonstrated that stolen LevelDB wallet data combined with harvested passwords or Keychain secrets can decrypt wallets off-device; attackers also deploy fake Ledger/Trezor apps (WebView loaders) to phish recovery phrases. The report includes observed IOCs and reproduction steps showing active threat behavior and practical exploitation paths for crypto theft and session reuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
