Facebook Messenger Users Targeted by Cryptocurrency Viral Miner

Facebook Messenger Users Targeted by Cryptocurrency Viral Miner

Experts from the Trend Micro Company recorded a new activity during which malicious actors have been distributing the Monero cryptocurrency miner called Digmine. They have been spreading it virally through the instant messaging application Facebook Messenger. The campaign is directed against users from such countries as Ukraine, Azerbaijan, Vietnam, South Korea, the Philippines, Thailand, and Venezuela.

“We found a new cryptocurrency-mining bot spreading through Facebook Messenger, which we first observed in South Korea. We named this Digmine based on the moniker it was referred to in a report of recent related incidents in South Korea,” Trend Micro informs.

Our top trading bots

Vicious bot

The malware is disguised as a video file named “video_xxxx.zip”, where xxxx is an arbitrary set of digits. Last week, lots of users were attracted to the fact that such files came to them in personal messages. Inside the archive, there was a malicious Digmine.

According to experts, Digmine only affects the desktop version of Facebook Messenger for the Chrome browser. If the file is opened in the mobile version of the messenger, the virus does not function.

“A known modus operandi of cryptocurrency-mining botnets, and particularly for Digmine (which mines Monero), is to stay in the victim’s system for as long as possible. It also wants to infect as many machines as possible, as this translates to an increased hashrate and potentially more cybercriminal income,” stated the company.

Infection Circuit

Getting on the computer, Digmine reaches out to the server from which it loads and installs the cryptocurrency miner and extension for Chrome. Then it activates the autorun. While the miner is engaged in the production of cryptocurrency, the extension sends messages on behalf of the victim with the virus.

The method works only if the browser retains credentials for authorization in the Facebook account. Otherwise, the extension will not be able to access the messenger interface and send out spam.

“If the user has their Facebook account automatically logged in by default, the browser extension can interact with their account. It does so by downloading additional code from the C&C server. Digmine’s interaction with Facebook could get more functions in the future since it’s possible to add more code,” explained the company, which conducted a bot-related investigation.

Extensions for Chrome can only be downloaded from the official Chrome Web Store directory, but the attackers bypassed this condition. To install a malicious extension, they use a command-line download.

By now, the campaign has affected only users of Windows. Trend Micro informed Facebook about the problem, and the company has already deleted the malicious links in the messages, but experts say this has not solved the problem completely: attackers can change the method of spreading the malware and launch a new campaign.

How to Prevent it?

Cryptocurrency mining is growing in popularity; hence attackers are getting more attracted by the mining botnet business. The more victims are attacked, the bigger the profits – this is a traditional dogma of all the cybercriminal blueprints. It is also not unexpected that they are using popular social media platforms for distributing their malware.

If you want to prevent this type of cyber threats, merely follow golden practices on protecting social media accounts. First of all, you should think twice before you share anything that might seem suspicious. You should also be cautious when downloading any files even if you have received them from your friends. Secondly, be aware of unreclaimed messages. And thirdly, activate your account’s privacy settings.

In its official statement, Facebook claimed that “we maintain a number of automated systems to help stop harmful links and files from appearing on Facebook and in Messenger. If we suspect your computer is infected with malware, we will provide you with a free anti-virus scan from our trusted partners. We share tips on how to stay secure and links to these scanners on facebook.com/help.”

Images Source: blog.trendmicro.com

Examining the crypto market’s reaction to the Russia–Ukraine crisis
February saw a noticeable shift between inflation and U.S. Federal Reserve news, followed by news of a conflict in Eastern Europe that completely overshadowed...
Law Decoded: Tangible wins, new menaces and the global crypto taxation drive, Feb. 1–7
Every global event or major political crisis these days can trigger a digital asset-related conversation. As China welcomes the world’s top athletes to...
Solana-based DeFi protocol Hubble raises $10M, prepares for mainnet launch
The Solana (SOL) network is ready to see the mainnet launch for another decentralized finance (DeFi) protocol, aimed at Web3 development and backed by bigshots...
Analyst says Bitcoin is 'on sale' after BTC price dips below $54,000
Bitcoin's (BTC) downtrend extended a few rungs lower on Dec. 3 after the price dropped under $54,000 and traders will note that the BTC/USD daily chart...
Star Trek creator’s signature goes where no NFT has gone before: DNA
The signature of Star Trek producer Gene Roddenberry has gone boldly where no NFT has gone before — into the code for life itself.Back in 1965, Roddenberry...
Law Decoded: Best regulation is self-regulation, Oct. 11–18
Between fever-pitch anticipation over the impending approval of a Bitcoin exchange-traded fund, the Commodity Futures Trading Commission’s $42-million-plus settlement...
SEC approves Volt Equity ETF providing exposure to Bitcoin-centric companies
The United States Securities and Exchange Commission, or SEC, has approved the Volt Crypto Industry Revolution and Tech ETF, providing investors with easy...
BlockFi board of directors replaces 'Crypto Dad' after four months
Former Commodity Futures Trading Commission chair Christopher Giancarlo, also known as “Crypto Dad,” will be leaving crypto lending firm BlockFi’s board...
3 key areas traders are watching as Bitcoin’s monthly close occurs
Bitcoin's (BTC) whipsaw volatility has been on full display throughout June, leaving traders confused and in search of the latest technical indicator or...
Altcoins bag double-digit gains as Bitcoin price approaches $37,000
Cryptocurrency prices surged on June 29 as Bitcoin (BTC) price pushed through the $35,000 resistance level and lifted the total market cap by $93 billion,...
Thai crypto adoption is booming, with volume up 588% since November
Crypto adoption appears to be booming in Thailand, with the local Securities and Exchange Commission, or SEC, estimating domestic crypto volumes have increased...
Ohio Will Start Accepting Bitcoin For Tax Payments, BTC Plunges Below $3,600
The American state of Ohio appears to be the first one where people can pay taxes in bitcoin. A recent Wall Street Journal report specifies, however, that...
Bulgaria Launches One of the First Blockchain Master’s in Europe
As the hype over blockchain does not abate, more industries embrace this tech trend (or plan to do so). The adoption of DLT is sprawling to such spheres...
Tom Lee Stands By His $25,000 Bitcoin Prediction
Bitcoin’s price has been fluctuating throughout this summer, getting fixed at around $6,700-$7,000 at the end of August. The coin might be showing some...
Bitcoin Transaction Fees Plunge Breaking 2018 Record, Same For Mempool Queue
Long waiting transaction time and high fees have been a bottleneck in bitcoin network for quite a long time. Critics have been using these arguments as...