Block Chain Security slow fog disclosed that a malicious program against MacOS was targeting encrypted users. The program steals Telegram sessions, passwords kept by browsers, Apple Keychain data, memo contents and encrypted wallet databases, and further obtains user helper words by forging a hardware wallet interface.
To steal Telegram and wallet data
Slow mist claims that such malicious programs are installed to collect in-house sensitive information from the backstage and that users may not be able to detect it in a timely manner. The data that are targeted include Telegram login sessions, account numbers and passwords kept by browsers, Apple Keychain data, Mac memo content, and encrypted database files for encrypted wallets.
- Telegram Login Session
- Apple Keychain and Browser Support
- Encrypt Wallet Databases and Memorandums
This means that if a user keeps an account voucher, wallet file or other sensitive information on Mac, it can be targeted.
Fake Legger and Trezor windows
The slow fog indicates that the assailant will also eject a counterfeit Ledger or Trezor wallet window after having obtained relevant data from the device. These interfaces are similar to the original application and are intended to induce users to enter and restore the phrase.
Once the user inserts a reference in a false interface, the information is immediately sent to the attacker and the wallet control may be lost. This step directly increases the financial risk compared to simply stealing encrypted wallet documents.
Telegram session is more risky
The slow fog specifically mentioned that the theft of Telegram's conversation was a high-risk link in the attack. Since the attackers stole a log-in session instead of an account password, it may be possible to enter user chats and groups directly without a authentication code.
In the encrypted market, many transactions, off-site transactions and investment-group exchanges rely on Telegram, which makes the accounts more useful.
Slow fog gives precautionary advice.
The slow fog suggests that the MacOS user minimizes the installation of software of unknown origin and avoids entering assistive words in a window wallet interface.
- Download applications from trusted sources only
- Save as much as you can offline as possible
- Check unusual Telegram login sessions
Slow fog claims that even experienced encryption users may be successful by misbeliefing a wallet window or installing unknown programs.
