Is Your Telegram Account Really Secure? Hackers Are Hijacking Active Sessions to Compromise Even 2FA-Protected Accounts!
Imported from official source
A newly discovered macOS information-stealing (infostealer) malware poses a serious security threat to Telegram Desktop users. According to security researchers, this malware steals Telegram Desktop’s local session files, allowing attackers to access a user’s account without requiring the password, SMS verification code, or Telegram’s Two-Step Verification (2FA) password. Experts emphasize that this does not mean Telegram’s 2FA has been broken. Instead, the malware copies an already authenticated and active user session and transfers it to another device. As a result, Telegram recognizes the imported session as an already trusted session rather than a new login. How Does the Attack Work? Telegram Desktop stores authentication data in a special tdata directory on the local system. This folder contains cryptographic keys and other data that validate an active user session. Researchers found that the malware: The attacker then transfers these files to another compatible macOS device. Experiments conducted by the SlowMist security laboratory demonstrated that the session could be successfully restored on macOS 12.7 running Telegram Desktop version 4.16. As a result, Telegram: Instea...
This version
- Version
- 1 of 1
- Recorded
- October 03, 2026 20:40
- Change
- Initial
- Content hash
036f2fb0e8e1dcdf2541fe920d42d0a0- All versions
- Revision history