logo

Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft

ID: adc367a1-70d9-57b8-a391-05a084291e49

STIX ID: report--adc367a1-70d9-57b8-a391-05a084291e49

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Mayura Kathir

...
...

A macOS-targeting infostealer campaign collects encrypted wallet databases, Keychain entries, browser passwords, Apple Notes, and Telegram Desktop session files to enable offline cracking of cryptocurrency wallets and direct account takeover. Researchers demonstrated that stolen LevelDB wallet data combined with harvested passwords or Keychain secrets can decrypt wallets off-device; attackers also deploy fake Ledger/Trezor apps (WebView loaders) to phish recovery phrases. The report includes observed IOCs and reproduction steps showing active threat behavior and practical exploitation paths for crypto theft and session reuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.