macOS Malware Hijacks Telegram Sessions, Targets Crypto Wallets
As the crypto community increasingly relies on Telegram to manage assets, securing the messaging platform has become critical. macOS, once considered relatively secure, is now facing targeted malware attacks. Such attacks can directly steal locally authenticated session data and browser wallet extensions, bypassing two-factor authentication (2FA) and posing a serious threat to digital-asset holders worldwide.
Blockchain security company SlowMist warned on July 15, 2026, that malware targeting macOS was seeking to hijack Telegram desktop sessions. The malware targets more than a dozen major cryptocurrency wallets and copies data from their browser extensions. It also uses fake hardware-wallet applications purporting to be from Ledger and Trezor to trick users into disclosing seed phrases and steal their assets.
All Coverage
1 original reportsThe Backstory
The history behind this eventMacSync Targets macOS Crypto Wallets and Cloud Credentials
MacSync is an information stealer targeting macOS users through terminal-based social engineering, prompting victims to run malicious commands themselves. Microsoft’s disclosure highlights the growing value of data stored on Macs, including cryptocurrency wallets, system keychains and cloud-service credentials. Such information can be monetized directly or used to gain deeper access to personal accounts and corporate infrastructure.
Microsoft’s latest analysis found that MacSync searches infected systems for crypto wallet data, macOS Keychain records and cloud credentials before exfiltrating the material in separate chunks. The malware also rotates its command-and-control, or C2, domains, making domain-based blocking and tracking more difficult. Chunked uploads can further reduce the chance that unusually large outbound transfers trigger conventional security monitoring.
macOS Stealer Reaper Impersonates Tech Giants and Targets Crypto Wallets
macOS users are increasingly being targeted by information-stealing malware, with attackers often posing as Apple, Microsoft or Google update alerts to lower their guard. Reaper is particularly significant because it both creates a system backdoor and targets cryptocurrency wallets such as MetaMask and Phantom, potentially gaining access to credentials, private keys and control of assets.
A cybersecurity company recently disclosed that Reaper uses a mix of fake Apple, Microsoft and Google software updates to trick macOS users into installing it, after which it collects wallet data and steals assets. Existing reports have not disclosed the organization that discovered it, the exact disclosure date, the number of victims or the value of losses. Users should update software only through official channels.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →