IOC Radar
TLP:WHITE7 IOCs

Telegram Account Compromised, Wallet Swapped: How Does macOS Malware Break Through Your Defenses?

SL
SlowMist
Published July 15, 2026Original Report

Threat Actors

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYSandwormINFRASTRUCTUREhttp://192.253.248.18…http://192.253.248.18…http://86.54.25.213/l…CAPABILITYunknownVICTIMunknown
Adversary(1)
Infrastructure(4)
Capability
Victim

Attack Flow8 steps · MITRE ATT&CK mapped

Credential AccessTA0006·T1056
1/8
Input Capture
ActionCapture user credentials via fake prompt
Malware displays a fake password prompt disguised as a Google API Connector update to capture user credentials.

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise7

TypeIndicatorConfidenceScoreFirst Seen
URLhttp://192.253.248.181/web/ledger.zip
intel-blognetworkurl
High
58
Jul 15, 26
SHA25636f4ae11560ed34f32c927468a09a5370a5fbdcae41660f6e8d9a49330c8d059
file-hashindicatorintel-blog
Medium
53
Jul 15, 26
URLhttp://192.253.248.181/web/trezor.zip
intel-blognetworkurl
High
58
Jul 15, 26
URLhttp://86.54.25.213/ledger?username=night</li><li>http://86.54.25.213/trezor?username=night</li><li>http://86.54.25.213/log</li></ul><h3>Malicious
intel-blognetworkurl
High
58
Jul 15, 26
URLhttp://192.253.248.181/web/ledgerwallet.zip
intel-blognetworkurl
High
58
Jul 15, 26
SHA25660f33e7b8c6b84839e28c710c8c5a99a718c0b88135653561be8d45f976b794f
file-hashintel-blogsupply-chain
Medium
53
Jul 15, 26
SHA25641d77fef030b8515efb068defed5e15c14fbebd16259253f1f79febd6e12ebcb
file-hashindicatorintel-blog
Medium
53
Jul 15, 26

IOC Relationship Graph

IOC Relationship Graph7 total IOCs
URLSHA256
URL4SHA2563Actors1REPORTTelegram Account CompromisSandworm
scroll to zoom · drag to pan · click IOC to open