MacOS malware hijacks Telegram sessions, targets crypto wallets: SlowMist

Published on July 19, 2026 • Expert Analysis
MacOS malware hijacks Telegram sessions, targets crypto wallets: SlowMist

The security landscape for Apple users has taken a concerning turn as a sophisticated new strain of macOS malware has emerged, specifically engineered to drain cryptocurrency wallets and compromise secure communications. According to a detailed report by the blockchain security firm SlowMist, this malware does not merely steal passwords; it orchestrates a multi-pronged attack that includes session hijacking, credential harvesting, and the deployment of deceptive "fake" wallet applications.

As the adoption of macOS for developers and crypto traders continues to grow, threat actors are pivoting their focus away from Windows and toward the Apple ecosystem. This latest threat highlights a critical vulnerability in how users manage their digital assets and their trust in third-party software installations.

The Anatomy of the Attack: How the Malware Operates

The malware typically finds its way onto a victim's machine through social engineering tactics, such as "cracked" software, fraudulent updates, or phishing emails masquerading as legitimate business communications. Once executed, the malware initializes a silent surveillance operation designed to exfiltrate sensitive data without alerting the user.

The primary objective of this malware is the acquisition of private keys and seed phrases. However, it employs several different methodologies to achieve this goal, depending on the victim's setup:

1. Telegram Session Hijacking: One of the most alarming features discovered by SlowMist is the ability to hijack Telegram sessions. By stealing the session files (the tdata folder or equivalent macOS application data), the attackers can bypass Two-Factor Authentication (2FA) and gain full access to the victim's Telegram account. This allows hackers to impersonate the user, send phishing links to their contacts, or access private keys stored within "Saved Messages."

2. Local Wallet Decryption: The malware scans the file system for known cryptocurrency wallet directories. If it finds encrypted wallet files, it attempts to harvest credentials from the system's keychain or monitors keystrokes (keylogging) to capture the password used to unlock the wallet.

3. Deceptive "Fake" Applications: In a more direct approach, the malware may trigger the installation of a fraudulent wallet application. These clones look identical to popular wallets like MetaMask or Trust Wallet. When the user attempts to "restore" their wallet, the application prompts them to enter their 12-to-24 word recovery phrase. Once entered, the seed phrase is transmitted directly to the attacker's Command and Control (C2) server, granting them total control over the funds.

Why Target Telegram? The Crypto-Social Connection

The focus on Telegram is not accidental. Telegram has become the primary hub for the cryptocurrency community, serving as the main communication channel for project developers, alpha groups, and trading bots. By compromising a Telegram account, attackers gain an entry point into the victim's professional and financial network.

Once a session is hijacked, the attacker can conduct "social engineering 2.0." Instead of a random bot sending a link, the victim's own trusted friend or colleague appears to be sending a request for help or a "hot tip" on a new token, making the subsequent phishing attempt far more successful.

The Broader Impact on macOS Security

For years, Mac users operated under the misconception that macOS was inherently "immune" to viruses. While Apple's Gatekeeper and XProtect provide robust layers of defense, the rise of targeted malware proves that no operating system is impenetrable. The SlowMist report underscores that modern malware is moving toward infostealers—software designed not to break the system, but to quietly steal the "keys to the kingdom."

This trend is particularly dangerous for "whales" (high-net-worth crypto holders) and developers who hold administrative privileges on their machines, as a single breach can lead to the loss of millions of dollars in assets across multiple chains.

How to Protect Your Assets and Your Mac

In light of the SlowMist findings, cryptocurrency users on macOS should implement the following security protocols to mitigate the risk of session hijacking and wallet theft:

Disable Telegram Auto-Login and Review Sessions: Periodically check your "Active Sessions" in Telegram settings. If you see a device or location you don't recognize, terminate the session immediately. Additionally, enable a Two-Step Verification password (separate from the SMS code) to add an extra layer of security.

Use Hardware Wallets: The only foolproof way to protect against seed-phrase-stealing malware is to move assets off "hot" software wallets and into "cold" hardware wallets (like Ledger or Trezor). Since the private keys never leave the hardware device, malware on the Mac cannot steal them.

Avoid "Cracked" Software: Many macOS malware strains are bundled with pirated software or "K'ed" apps. Avoid downloading software from unofficial sources or using third-party installers that request the disabling of System Integrity Protection (SIP).

Audit App Permissions: Be wary of any application that asks for excessive permissions, especially those that request access to the Accessibility or Full Disk Access settings without a clear, legitimate reason.

Conclusion

The discovery by SlowMist serves as a stark reminder that the intersection of decentralized finance and traditional computing is a high-risk zone. As malware becomes more specialized in targeting the tools used by the crypto community—such as Telegram and software wallets—users must shift from a mindset of "passive security" to "active defense." In the world of crypto, your security is your only guarantee; once a seed phrase or session is compromised, the assets are gone forever.

Read Also: