macOS Infostealer Hijacks Telegram Desktop Sessions via tdata Theft to Bypass 2FA, Harvests Keychain, Browser Credentials, Apple Notes, and 16 Crypto Wallets
macOS Infostealer Hijacks Telegram Desktop Sessions via (TL-2026-1424), also tracked as Odyssey Stealer macOS Campaign, is a high-severity malware campaign, first published 2026-07-16. It has no confirmed attribution, affects Telegram Telegram Desktop, maps to 27 MITRE ATT&CK techniques (T1005, T1027, T1036.004), and is covered by 9 detection rules and 41 indicators of compromise.
Key facts for TL-2026-1424
- Threat ID
- TL-2026-1424
- Also known as
- Odyssey Stealer macOS Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-07-16
- Last reviewed
- 2026-07-16
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- cryptocurrency, finance, technology, individual-consumers
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 41
Malware and tooling in macOS Infostealer Hijacks Telegram Desktop Sessions via
Malware and tooling: Odyssey Stealer, Telethon, opentele
SlowMist reproduced a macOS infostealer technique that copies Telegram Desktop's local 'tdata' directory (key_datas, maps, and session state files) from an infected Mac and restores it on an attacker-controlled machine, resuming an authenticated Telegram session without triggering a login prompt, SMS code, or Two-Step Verification password when the victim has not set a separate Telegram Desktop passcode. The same malware family harvests macOS Keychain data, Safari/Chromium browser credentials, Apple Notes content, and 16+ cryptocurrency wallet databases, and replaces legitimate Ledger Live/Trezor Suite apps with trojanized WKWebView phishing clones.
How macOS Infostealer Hijacks Telegram Desktop Sessions via works
In July 2026, SlowMist's MistEye monitoring platform detected a macOS information-stealing malware campaign and published two related technical analyses: an initial report on a Google Sites community-application phishing campaign delivering the stealer, and a follow-up specifically detailing Telegram Desktop session (tdata) compromise and cryptocurrency wallet swapping. The malware does not exploit a code vulnerability or crack Telegram's cryptography; instead it abuses the portability of Telegram Desktop's local session state. Telegram Desktop stores an AES key in a file named key_datas inside ~/Library/Application Support/Telegram Desktop/tdata/, alongside session-mapping files (maps) and per-account state files matching an <name>s naming pattern. An attacker who exfiltrates this directory can restore it on a compatible machine and inherit the victim's live, already-authorized session — the client does not request a phone number, SMS code, or Telegram Two-Step Verification password on restoration, because from Telegram's server-side perspective this is simply the same authorized session continuing to poll. SlowMist confirmed this on macOS 12.7 with Telegram Desktop 4.16, and noted both the Qt-based Telegram Desktop client and the native Swift-based Telegram for macOS client are susceptible; the native client additionally persists cached conversation data locally even after server-side session termination. Once obtained, tdata can be converted into a fully programmatic Telegram API session using open-source tooling (opentele, Telethon) combined with the already-authorized AuthKey and official client API parameters, letting an attacker read message history, exfiltrate media, and interact with contacts entirely outside the Telegram Desktop UI. The broader malware is consistent in tooling, infrastructure pattern, and behavior with the 'Odyssey Stealer' macOS malware-as-a-service operation reported independently by Censys, GBHackers, and Cyberpress in the same period: a fake 'GAPI_Update' administrator-password prompt that validates the entered credential via `dscl . authonly` and then uses it to unlock the Keychain (`security find-generic-password -ga \"Chrome\"` to obtain the Chrome Safe Storage key), systematic harvesting of Chrome/Brave/Edge/Vivaldi/Opera Login Data, Cookies, Web Data and Firefox logins.json/key4.db, Apple Notes database extraction, LevelDB wallet-store copying with offline AES-256-CBC decryption attempts using harvested passwords as candidates, and termination/replacement of legitimate Ledger Live and Trezor Suite applications (via pkill, sudo rm -rf, and ditto extraction) with trojanized WKWebView/SwiftUI clones that phish for hardware-wallet recovery phrases through fake recovery-workflow pages. Stolen data is zip-compressed and POSTed to a C2 /log endpoint identical in structure to IOCs published in the Telegram-specific SlowMist report. The wider Odyssey Stealer operation runs a MaaS affiliate model: delivery via obfuscated AppleScript wrapped in shell scripts distributed through phishing/malvertising with per-affiliate download paths (/d/{affiliate}{campaign_id}), boot persistence via a randomly-labeled LaunchDaemon (com.{random_5-digit}) that polls a disk-stored C2 URL (/.chost) every 60 seconds via osascript, and supports remote commands for reinfection (repeat), arbitrary shell execution (doshell), SOCKS5 proxy tunneling (enablesocks5), and self-removal (uninstall). No CVE applies: this is an abuse of session-file portability and social-engineering/credential-harvesting technique rather than a software vulnerability.
MITRE ATT&CK techniques used in TL-2026-1424
Collection
T1005 Data from Local System; T1074.001 Local Data Staging; T1560 Archive Collected Data
Defense Evasion
T1027 Obfuscated Files or Information; T1036.004 Masquerade Task or Service; T1070 Indicator Removal
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059.002 AppleScript; T1059.004 Unix Shell
Command and Control
T1071.001 Web Protocols; T1090.001 Internal Proxy; T1105 Ingress Tool Transfer
Discovery
T1083 File and Directory Discovery; T1518 Software Discovery
Credential Access
T1187 Forced Authentication; T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1555.001 Keychain; T1555.003 Credentials from Web Browsers
Impact
T1531 Account Access Removal; T1657 Financial Theft
Persistence
T1543.004 Launch Daemon; T1547.013 XDG Autostart Entries
Privilege Escalation
T1548 Abuse Elevation Control Mechanism
Initial Access
T1566 Phishing; T1566.002 Spearphishing Link
Lateral Movement
Affected products and versions in macOS Infostealer Hijacks Telegram Desktop Sessions via
- Telegram — Telegram Desktop
Vulnerable versions: 4.16 and prior configurations without a Desktop Passcode
Fixed in: N/A - mitigated by enabling Telegram Desktop Passcode - Telegram — Telegram for macOS (native Swift client)
Vulnerable versions: all versions without Desktop Passcode enabled
Fixed in: N/A - mitigated by enabling Telegram Desktop Passcode - Apple — macOS
Vulnerable versions: 12.7 (tested); broader macOS versions implied compatible - Ledger — Ledger Live (trojanized replacement)
Vulnerable versions: any version replaced by malicious downloader - Trezor — Trezor Suite (trojanized replacement)
Vulnerable versions: any version replaced by malicious downloader
Remediation for macOS Infostealer Hijacks Telegram Desktop Sessions via
Immediate actions
- Terminate all active Telegram sessions from a trusted device and reset Two-Step Verification password
- Set a dedicated Telegram Desktop passcode distinct from any other reused password
- For any Mac suspected infected, wipe/reimage rather than attempting in-place cleanup given SOCKS5/reinfection persistence
- Rotate all Keychain-stored, browser-stored, and Apple Notes-stored credentials, prioritizing email, exchange, cloud storage, and password-manager accounts
- Move any cryptocurrency exposed to the infected machine to a newly generated wallet/seed on a clean device; treat any recovery phrase entered into a Ledger Live/Trezor Suite app as compromised
Workarounds
- Enable a strong, unique Telegram Desktop local passcode to prevent the tdata directory alone from yielding a usable session even if exfiltrated
- Avoid storing the Telegram Desktop passcode or macOS admin password in browsers, Keychain items with generic names, or Apple Notes
Longer-term hardening
- Deploy EDR/behavioral monitoring on macOS fleets capable of detecting LaunchDaemon creation, dscl authonly invocation, and security find-generic-password calls by unsigned/unexpected processes
- Enforce application allowlisting / notarization verification for wallet software (Ledger Live, Trezor Suite) to detect trojanized replacements
- Monitor egress to C2 /log and /d/ URL patterns and block known malicious IP ranges
- Educate users against installing software or approving install prompts sourced from Google Sites-hosted community pages or unsolicited update prompts
Weaknesses (CWE) in macOS Infostealer Hijacks Telegram Desktop Sessions via
CWE-522, CWE-311, CWE-434, CWE-494
Timeline of macOS Infostealer Hijacks Telegram Desktop Sessions via
- Developer 'Rodrigo4' (prior contributor to Atomic macOS Stealer/AMOS) advertises a new macOS stealer platform on underground forums at $3,000/month, capped at 15 affiliates — the lineage that later becomes Poseidon/Odyssey Stealer (Censys research).
- Public feud erupts on the XSS underground forum between Rodrigo4 and the AMOS lead developer, accelerating Rodrigo4's pivot to a competing platform (Censys research).
- Rodrigo4 sells the Poseidon Stealer platform; the identity of the buying/current operators remains unconfirmed (Censys research).
- First confirmed Poseidon/Odyssey-lineage C2 server (88.214.50.3) is identified in the wild by independent researcher @g0njxa (Censys research).
- Secondary C2 infrastructure (5.199.166.102, later reused by Odyssey Stealer) is discovered, beginning a pattern of migration across European hosting providers (Censys research).
- New operators rebrand the Poseidon Stealer codebase as 'Odyssey Stealer', continuing the macOS-focused malware-as-a-service affiliate model (Censys research).
- Latest observed Odyssey Stealer C2 infrastructure (213.209.159.175) identified, following multiple mid-2025 through late-2025 infrastructure migrations across ~10 physical hosts in the Netherlands, Russia, Lithuania, and Singapore (Censys research).
- Censys ARC publishes the first detailed Odyssey Stealer operational analysis, documenting affiliate build IDs, developer history, and C2 infrastructure clustering.
- SlowMist MistEye platform begins detecting the macOS information-stealing campaign in the wild, later documented in two separate SlowMist Medium reports.
- SlowMist publishes analysis of the Google Sites community-application phishing campaign used to deliver the macOS information-stealing malware.
- SlowMist independently reproduces the Telegram Desktop session-hijack technique on macOS 12.7 with Telegram Desktop 4.16, confirming full authenticated access is restored without 2FA.
- SlowMist publishes the follow-up report 'Telegram Account Compromised, Wallet Swapped', detailing tdata theft, Keychain/Notes/browser harvesting, and Ledger Live/Trezor Suite app replacement.
- Threat ingested into TL-Intel-Harness backlog and promoted to RESEARCH phase as TL-2026-1424 based on confirmed PoC and published IOCs.
- Censys, GBHackers, Cyberpress, SOC Prime, and Cryptonews independently publish technical breakdowns of the related 'Odyssey Stealer' macOS malware-as-a-service operation, sharing near-identical TTPs (16-18 targeted desktop wallets, Ledger/Trezor app replacement, /log C2 exfiltration endpoint, LaunchDaemon persistence).
- Cyber Security News publishes coverage of the SlowMist findings ('Hackers Crack Telegram 2FA'), making the technique and published IOCs (2 IPs, 3 hashes) broadly public.
Sources cited for macOS Infostealer Hijacks Telegram Desktop Sessions via
- Hackers 'Crack' Telegram 2FA
- Telegram Account Compromised, Wallet Swapped: How Does macOS Malware Break Through Your Defenses?
- Analysis of a Google Sites Community Application Phishing Campaign and macOS Information-Stealing Malware
- Odyssey Stealer: Inside a macOS Crypto-Stealing Operation
- Odyssey Stealer Hits macOS Users in 100+ Countries, Targets 300 Crypto Wallet Extensions
- Odyssey Stealer Hits 100+ Countries, Targets 16+ Crypto Wallet Apps on macOS
- Odyssey Trojan Targets macOS, Steals Crypto Wallets
- Odyssey Stealer: macOS Crypto Wallet Theft via MaaS
- Odyssey Infostealer Targets macOS Keychain and Cryptocurrency Wallets in Global Attacks
- Odyssey Stealer Attacks Macs Worldwide and Replaces Crypto Wallet Apps With Drainers
- Security researchers warn against Odyssey Infostealer targeting macOS users for crypto theft
- Odyssey Stealer (Mac) - Removal steps, and macOS cleanup
Threats related to macOS Infostealer Hijacks Telegram Desktop Sessions via
- macOS Info-Stealer Chains Fake Password Prompt, Telegram Session Theft, and Crypto Wallet App Replacement
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and MacSync Campaign
- Threat Actors Abuse Trusted AI Platforms (Claude, ChatGPT, Grok) to Distribute Malware
- Google Sites Phishing Campaign Delivers AMOS-Variant macOS Stealer (unix32385485) to Web3 Users
- Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser Fingerprinting Evasion Gate
- ClickFix macOS Trio: Loader/Script/Helper Campaigns Deliver SHub Stealer, AMOS, and Macsync Stealer with Trojanized Ledger/Trezor/Exodus Wallets and GoogleUpdate-Masqueraded Persistence
Detection coverage for TL-2026-1424
As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1424 across Splunk SPL, Microsoft KQL and Sigma, covering 41 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1424
12 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.