Crypto malware attacks compromise macOS users and steal cryptocurrency seed phrases
Cybersecurity firms have uncovered two active malware campaigns targeting cryptocurrency users. SlowMist reports a macOS information‑stealing malware that hijacks Telegram Desktop sessions, extracts data from the macOS Keychain, Safari cookies, Apple Notes and a range of crypto‑wallet databases. The malware can also present counterfeit Ledger Live or Trezor Suite windows to capture seed phrases, giving attackers full control of digital assets.
Kaspersky’s research describes the modular OkoBot framework, comprising more than 20 malicious components that infiltrate computers via social‑engineering tactics such as ClickFix prompts and fake GitHub repositories. OkoBot harvests wallet files, browser data, login credentials and, through its SeedHunter module, replaces legitimate hardware‑wallet recovery screens to steal seed phrases. The campaign has been detected in at least 25 countries, with the highest victim counts in Brazil, Vietnam, Canada, Mexico and Turkey. Both threats illustrate how crypto holders remain vulnerable to sophisticated malware that bypasses two‑step verification and exploits trusted software installations.