macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain, Browser Credentials, Apple Notes, and 16 Crypto Wallets

macOS Infostealer Hijacks Telegram Desktop Sessions via (TL-2026-1424), also tracked as Odyssey Stealer macOS Campaign, is a high-severity malware campaign, first published 2026-07-16. It has no confirmed attribution, affects Telegram Telegram Desktop, maps to 27 MITRE ATT&CK techniques (T1005, T1027, T1036.004), and is covered by 9 detection rules and 41 indicators of compromise.

Key facts for TL-2026-1424

Threat ID
TL-2026-1424
Also known as
Odyssey Stealer macOS Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-16
Last reviewed
2026-07-16
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
cryptocurrency, finance, technology, individual-consumers
Target regions
Global
Detection rules
9
Indicators of compromise
41

Malware and tooling in macOS Infostealer Hijacks Telegram Desktop Sessions via

Malware and tooling: Odyssey Stealer, Telethon, opentele

SlowMist reproduced a macOS infostealer technique that copies Telegram Desktop's local 'tdata' directory (key_datas, maps, and session state files) from an infected Mac and restores it on an attacker-controlled machine, resuming an authenticated Telegram session without triggering a login prompt, SMS code, or Two-Step Verification password when the victim has not set a separate Telegram Desktop passcode. The same malware family harvests macOS Keychain data, Safari/Chromium browser credentials, Apple Notes content, and 16+ cryptocurrency wallet databases, and replaces legitimate Ledger Live/Trezor Suite apps with trojanized WKWebView phishing clones.

How macOS Infostealer Hijacks Telegram Desktop Sessions via works

In July 2026, SlowMist's MistEye monitoring platform detected a macOS information-stealing malware campaign and published two related technical analyses: an initial report on a Google Sites community-application phishing campaign delivering the stealer, and a follow-up specifically detailing Telegram Desktop session (tdata) compromise and cryptocurrency wallet swapping. The malware does not exploit a code vulnerability or crack Telegram's cryptography; instead it abuses the portability of Telegram Desktop's local session state. Telegram Desktop stores an AES key in a file named key_datas inside ~/Library/Application Support/Telegram Desktop/tdata/, alongside session-mapping files (maps) and per-account state files matching an <name>s naming pattern. An attacker who exfiltrates this directory can restore it on a compatible machine and inherit the victim's live, already-authorized session — the client does not request a phone number, SMS code, or Telegram Two-Step Verification password on restoration, because from Telegram's server-side perspective this is simply the same authorized session continuing to poll. SlowMist confirmed this on macOS 12.7 with Telegram Desktop 4.16, and noted both the Qt-based Telegram Desktop client and the native Swift-based Telegram for macOS client are susceptible; the native client additionally persists cached conversation data locally even after server-side session termination. Once obtained, tdata can be converted into a fully programmatic Telegram API session using open-source tooling (opentele, Telethon) combined with the already-authorized AuthKey and official client API parameters, letting an attacker read message history, exfiltrate media, and interact with contacts entirely outside the Telegram Desktop UI. The broader malware is consistent in tooling, infrastructure pattern, and behavior with the 'Odyssey Stealer' macOS malware-as-a-service operation reported independently by Censys, GBHackers, and Cyberpress in the same period: a fake 'GAPI_Update' administrator-password prompt that validates the entered credential via `dscl . authonly` and then uses it to unlock the Keychain (`security find-generic-password -ga \"Chrome\"` to obtain the Chrome Safe Storage key), systematic harvesting of Chrome/Brave/Edge/Vivaldi/Opera Login Data, Cookies, Web Data and Firefox logins.json/key4.db, Apple Notes database extraction, LevelDB wallet-store copying with offline AES-256-CBC decryption attempts using harvested passwords as candidates, and termination/replacement of legitimate Ledger Live and Trezor Suite applications (via pkill, sudo rm -rf, and ditto extraction) with trojanized WKWebView/SwiftUI clones that phish for hardware-wallet recovery phrases through fake recovery-workflow pages. Stolen data is zip-compressed and POSTed to a C2 /log endpoint identical in structure to IOCs published in the Telegram-specific SlowMist report. The wider Odyssey Stealer operation runs a MaaS affiliate model: delivery via obfuscated AppleScript wrapped in shell scripts distributed through phishing/malvertising with per-affiliate download paths (/d/{affiliate}{campaign_id}), boot persistence via a randomly-labeled LaunchDaemon (com.{random_5-digit}) that polls a disk-stored C2 URL (/.chost) every 60 seconds via osascript, and supports remote commands for reinfection (repeat), arbitrary shell execution (doshell), SOCKS5 proxy tunneling (enablesocks5), and self-removal (uninstall). No CVE applies: this is an abuse of session-file portability and social-engineering/credential-harvesting technique rather than a software vulnerability.

MITRE ATT&CK techniques used in TL-2026-1424

Collection

T1005 Data from Local System; T1074.001 Local Data Staging; T1560 Archive Collected Data

Defense Evasion

T1027 Obfuscated Files or Information; T1036.004 Masquerade Task or Service; T1070 Indicator Removal

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059.002 AppleScript; T1059.004 Unix Shell

Command and Control

T1071.001 Web Protocols; T1090.001 Internal Proxy; T1105 Ingress Tool Transfer

Discovery

T1083 File and Directory Discovery; T1518 Software Discovery

Credential Access

T1187 Forced Authentication; T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1555.001 Keychain; T1555.003 Credentials from Web Browsers

Impact

T1531 Account Access Removal; T1657 Financial Theft

Persistence

T1543.004 Launch Daemon; T1547.013 XDG Autostart Entries

Privilege Escalation

T1548 Abuse Elevation Control Mechanism

Initial Access

T1566 Phishing; T1566.002 Spearphishing Link

Lateral Movement

T1570 Lateral Tool Transfer

Affected products and versions in macOS Infostealer Hijacks Telegram Desktop Sessions via

  • Telegram — Telegram Desktop
    Vulnerable versions: 4.16 and prior configurations without a Desktop Passcode
    Fixed in: N/A - mitigated by enabling Telegram Desktop Passcode
  • Telegram — Telegram for macOS (native Swift client)
    Vulnerable versions: all versions without Desktop Passcode enabled
    Fixed in: N/A - mitigated by enabling Telegram Desktop Passcode
  • Apple — macOS
    Vulnerable versions: 12.7 (tested); broader macOS versions implied compatible
  • Ledger — Ledger Live (trojanized replacement)
    Vulnerable versions: any version replaced by malicious downloader
  • Trezor — Trezor Suite (trojanized replacement)
    Vulnerable versions: any version replaced by malicious downloader

Remediation for macOS Infostealer Hijacks Telegram Desktop Sessions via

Immediate actions

  • Terminate all active Telegram sessions from a trusted device and reset Two-Step Verification password
  • Set a dedicated Telegram Desktop passcode distinct from any other reused password
  • For any Mac suspected infected, wipe/reimage rather than attempting in-place cleanup given SOCKS5/reinfection persistence
  • Rotate all Keychain-stored, browser-stored, and Apple Notes-stored credentials, prioritizing email, exchange, cloud storage, and password-manager accounts
  • Move any cryptocurrency exposed to the infected machine to a newly generated wallet/seed on a clean device; treat any recovery phrase entered into a Ledger Live/Trezor Suite app as compromised

Workarounds

  • Enable a strong, unique Telegram Desktop local passcode to prevent the tdata directory alone from yielding a usable session even if exfiltrated
  • Avoid storing the Telegram Desktop passcode or macOS admin password in browsers, Keychain items with generic names, or Apple Notes

Longer-term hardening

  • Deploy EDR/behavioral monitoring on macOS fleets capable of detecting LaunchDaemon creation, dscl authonly invocation, and security find-generic-password calls by unsigned/unexpected processes
  • Enforce application allowlisting / notarization verification for wallet software (Ledger Live, Trezor Suite) to detect trojanized replacements
  • Monitor egress to C2 /log and /d/ URL patterns and block known malicious IP ranges
  • Educate users against installing software or approving install prompts sourced from Google Sites-hosted community pages or unsolicited update prompts

Weaknesses (CWE) in macOS Infostealer Hijacks Telegram Desktop Sessions via

CWE-522, CWE-311, CWE-434, CWE-494

Timeline of macOS Infostealer Hijacks Telegram Desktop Sessions via

  • Developer 'Rodrigo4' (prior contributor to Atomic macOS Stealer/AMOS) advertises a new macOS stealer platform on underground forums at $3,000/month, capped at 15 affiliates — the lineage that later becomes Poseidon/Odyssey Stealer (Censys research).
  • Public feud erupts on the XSS underground forum between Rodrigo4 and the AMOS lead developer, accelerating Rodrigo4's pivot to a competing platform (Censys research).
  • Rodrigo4 sells the Poseidon Stealer platform; the identity of the buying/current operators remains unconfirmed (Censys research).
  • First confirmed Poseidon/Odyssey-lineage C2 server (88.214.50.3) is identified in the wild by independent researcher @g0njxa (Censys research).
  • Secondary C2 infrastructure (5.199.166.102, later reused by Odyssey Stealer) is discovered, beginning a pattern of migration across European hosting providers (Censys research).
  • New operators rebrand the Poseidon Stealer codebase as 'Odyssey Stealer', continuing the macOS-focused malware-as-a-service affiliate model (Censys research).
  • Latest observed Odyssey Stealer C2 infrastructure (213.209.159.175) identified, following multiple mid-2025 through late-2025 infrastructure migrations across ~10 physical hosts in the Netherlands, Russia, Lithuania, and Singapore (Censys research).
  • Censys ARC publishes the first detailed Odyssey Stealer operational analysis, documenting affiliate build IDs, developer history, and C2 infrastructure clustering.
  • SlowMist MistEye platform begins detecting the macOS information-stealing campaign in the wild, later documented in two separate SlowMist Medium reports.
  • SlowMist publishes analysis of the Google Sites community-application phishing campaign used to deliver the macOS information-stealing malware.
  • SlowMist independently reproduces the Telegram Desktop session-hijack technique on macOS 12.7 with Telegram Desktop 4.16, confirming full authenticated access is restored without 2FA.
  • SlowMist publishes the follow-up report 'Telegram Account Compromised, Wallet Swapped', detailing tdata theft, Keychain/Notes/browser harvesting, and Ledger Live/Trezor Suite app replacement.
  • Threat ingested into TL-Intel-Harness backlog and promoted to RESEARCH phase as TL-2026-1424 based on confirmed PoC and published IOCs.
  • Censys, GBHackers, Cyberpress, SOC Prime, and Cryptonews independently publish technical breakdowns of the related 'Odyssey Stealer' macOS malware-as-a-service operation, sharing near-identical TTPs (16-18 targeted desktop wallets, Ledger/Trezor app replacement, /log C2 exfiltration endpoint, LaunchDaemon persistence).
  • Cyber Security News publishes coverage of the SlowMist findings ('Hackers Crack Telegram 2FA'), making the technique and published IOCs (2 IPs, 3 hashes) broadly public.

Sources cited for macOS Infostealer Hijacks Telegram Desktop Sessions via

Threats related to macOS Infostealer Hijacks Telegram Desktop Sessions via

Detection coverage for TL-2026-1424

As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1424 across Splunk SPL, Microsoft KQL and Sigma, covering 41 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Community OSINT corroboration for TL-2026-1424

12 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats