Is Your Telegram Account Really Secure? Hackers Are Hijacking Active Sessions to Compromise Even 2FA-Protected Accounts!

Imported from official source

Announcement

A newly discovered macOS information-stealing (infostealer) malware poses a serious security threat to Telegram Desktop users. According to security researchers, this malware steals Telegram Desktop’s local session files, allowing attackers to access a user’s account without requiring the password, SMS verification code, or Telegram’s Two-Step Verification (2FA) password.

Experts emphasize that this does not mean Telegram’s 2FA has been broken. Instead, the malware copies an already authenticated and active user session and transfers it to another device. As a result, Telegram recognizes the imported session as an already trusted session rather than a new login.

Telegram Desktop stores authentication data in a special tdata directory on the local system. This folder contains cryptographic keys and other data that validate an active user session.

  • Locates the Telegram Desktop tdata folder.
  • Copies key_datas, maps, and other session-related files.
  • Uploads the archive, along with other stolen data, to an attacker-controlled server.
  • The attacker then transfers these files to another compatible macOS device.

    Experiments conducted by the SlowMist security laboratory demonstrated that the session could be successfully restored on macOS 12.7 running Telegram Desktop version 4.16.

  • Did not request the user’s phone number.
  • Did not require an SMS verification code.
  • Did not ask for the Telegram Two-Step Verification password.
  • Instead, the application immediately restored the existing session and synchronized all chats and messages.

    Security experts stress that this is not a bypass of Telegram’s Two-Step Verification mechanism.

    Telegram’s 2FA only protects the authentication process when signing in from a new device.

    However, if an attacker obtains the files associated with an already authenticated session, Telegram treats it as a continuation of the existing trusted session rather than a new login.

    Therefore, the user is not prompted again for:

    This is an extract. The publication continues at the source.

    Read the original at the source: https://uzcert.uz/en/is-your-telegram-account-really-secure-hackers-are-hijacking-active-sessions-to-compromise-even-2fa-protected-accounts/

    Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    UZCERT — imported from official source
    Official source
    https://uzcert.uz/en/feed/ RSS
    Imported
    October 03, 2026 20:40
    Versions
    1 recorded
    Identity
    https://uzcert.uz/?p=39218

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.