A newly discovered macOS malware campaign is actively targeting cryptocurrency users through compromised wallets and Telegram account takeovers. The malicious software specifically focuses on popular wallet applications including Exodus, Electrum, Atomic, Wasabi, Monero, Ledger Live, and Trezor Suite, according to FinanceFeeds.
The malware's capabilities extend beyond standard wallet compromise. It actively harvests active Telegram Desktop sessions, allowing attackers to gain unauthorized account access while bypassing two-factor authentication and password protections entirely. This dual-vector attack approach significantly expands the threat surface for cryptocurrency holders who rely on messaging platforms for account recovery or transaction verification.
The malicious code additionally searches for wallet passwords, database files, seed phrase notes, and browser data across infected systems. Security experts recommend cryptocurrency users avoid consolidating all wallet infrastructure on a single device and consider deploying dedicated hardware or separate computers exclusively for wallet management to mitigate exposure to this emerging threat.