Introducing MERENA+ — our premium tier with your personalized safety dashboard, risk score, and all security tools. Sign up and cancel risk free in the first 14 days.Learn More
MERENA
Advisory Alert

Hackers Don’t Crack Telegram 2FA—They Copy Your Already Logged-In Session

A new threat targeting Mac computers can steal the saved login data from the Telegram desktop app and use it to open someone’s account on another device. This means criminals may be able to read messages and sync chats without needing the password or extra sign-in code.


Who is at risk

Mac users who use the Telegram desktop app, especially those who may have downloaded unsafe files or apps, are most at risk.

What to watch for

Watch for Telegram acting strangely, unexpected new device activity, missing privacy settings, or signs your Mac has unknown apps, pop-ups, or other unusual behavior.

What to do

Immediately review Telegram’s active devices, sign out of any you do not recognize, update your Mac and apps, remove suspicious software, and avoid opening untrusted downloads.