Is Your Telegram Account Really Secure? Hackers Are Hijacking Active Sessions to Compromise Even 2FA-Protected Accounts!
A newly discovered macOS information-stealing (infostealer) malware poses a serious security threat to Telegram Desktop users. According to security researchers, this malware steals Telegram Desktop’s local session files, allowing attackers to access a user’s account without requiring the password, SMS verification code, or Telegram’s Two-Step Verification (2FA) password.
Experts emphasize that this does not mean Telegram’s 2FA has been broken. Instead, the malware copies an already authenticated and active user session and transfers it to another device. As a result, Telegram recognizes the imported session as an already trusted session rather than a new login.
Telegram Desktop stores authentication data in a special tdata directory on the local system. This folder contains cryptographic keys and other data that validate an active user session.
The attacker then transfers these files to another compatible macOS device.
Experiments conducted by the SlowMist security laboratory demonstrated that the session could be successfully restored on macOS 12.7 running Telegram Desktop version 4.16.
Instead, the application immediately restored the existing session and synchronized all chats and messages.
Security experts stress that this is not a bypass of Telegram’s Two-Step Verification mechanism.
Telegram’s 2FA only protects the authentication process when signing in from a new device.
However, if an attacker obtains the files associated with an already authenticated session, Telegram treats it as a continuation of the existing trusted session rather than a new login.
Therefore, the user is not prompted again for:
This is an extract. The publication continues at the source.
Read the original at the source: https://uzcert.uz/en/is-your-telegram-account-really-secure-hackers-are-hijacking-active-sessions-to-compromise-even-2fa-protected-accounts/
Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- UZCERT — imported from official source
- Official source
- https://uzcert.uz/en/feed/ RSS
- Imported
- October 03, 2026 20:40
- Versions
- 1 recorded
- Identity
https://uzcert.uz/?p=39218