註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

SlowMist
@SlowMist_Team
SlowMist is a Blockchain security firm established in 2018, providing services such as security audits, security consultants, red teaming, and more.
加入 April 2018
408 正在關注    88.8K 粉絲
✍️ Technical Analysis Published: Telegram Account Compromised, Wallet Swapped: How Does macOS Malware Break Through Your Defenses? Our latest investigation reconstructs how a single malware sample chains together Telegram session theft, wallet database exfiltration, offline decryption and fake wallet applications into a complete account takeover workflow. Our analysis shows: 1️⃣Stolen Telegram Desktop and Telegram for macOS session files can be restored on another Mac without re-entering a phone number, verification code or 2FA password 2️⃣For Telegram for macOS, even after server-side security mechanisms respond, cached chat history may remain accessible instead of being cleared by a forced logout 3️⃣Wallet databases can be paired with passwords collected from Keychain, browsers and Apple Notes for offline decryption, without interacting with the victim's device 4️⃣Fake Ledger and Trezor desktop apps are actually WKWebView-based loaders that replace trusted wallet interfaces with attacker-controlled phishing pages The malware doesn't rely on a single technique—it combines authenticated sessions, encrypted wallet data and credential material into one attack chain. 💡 Defense tip: Protect your local Telegram session by enabling a Telegram Passcode and using a strong, unique password. Full analysis and practical mitigation guidance👇
顯示更多
0
1
34
12
轉發到社區