Jump to content

A cryptocurrency mining malware is spreading through Facebook Messenger


Kargai

Featured Comment

Posted

 The company (from Tokyo) Trend Micro discovered a cryptocurrency mining bot in Facebook Messenger.

Called "Digmine" the origin seem to take place in South Korea and started to spread in other countries like Vietnam, Thaïland, Philippines and others.

If a Facebook Messenger user has their account set to automatically log in, Digmine will immediately send a disguised video link, typically titled “video_xxxx.zip,” to all of their friends via direct message. If that file is opened, it will execute the malware. Once the bot is planted, an auto-start mechanism will launch Chrome and run a malicious browser extension. 

digmine-cryptocurrency-mining-malware-vi

source : https://www.dailydot.com/debug/cryptocurrency-facebook-messenger/

The bot is only working with the desktop (Chrome) version of Messenger. If the video file is opened on other platforms, like the mobile webpage or app, it will not work as intended. 

So just take care of the links you open, even if it come from a trusted person. And especially if you are from the Philippines (we have lots of PH players here) and other mentionned countries.

Stay safe peeps ;) 

 

Posted

Holy crap. Those people keeps finding a new way to get more money....

Thank you for sharing this, stay safe guys! 

 

*PS:  As it's only works with chrome, the easiest way to not infected by those malwares is to use another browser!  xD

Posted
Just now, wilberthh said:

Holy crap. Those people keeps finding a new way to get more money....

Thank you for sharing this, stay safe guys! 

 

*PS:  As it's only works with chrome, the easiest way to not infected by those malwares is to use another browser!  xD

Or do a daily/weekly anti virus scan. never hurts to scan ur pc :P

Posted
25 minutes ago, Kargai said:

 The company (from Tokyo) Trend Micro discovered a cryptocurrency mining bot in Facebook Messenger.

Called "Digmine" the origin seem to take place in South Korea and started to spread in other countries like Vietnam, Thaïland, Philippines and others.

If a Facebook Messenger user has their account set to automatically log in, Digmine will immediately send a disguised video link, typically titled “video_xxxx.zip,” to all of their friends via direct message. If that file is opened, it will execute the malware. Once the bot is planted, an auto-start mechanism will launch Chrome and run a malicious browser extension. 

digmine-cryptocurrency-mining-malware-vi

source : https://www.dailydot.com/debug/cryptocurrency-facebook-messenger/

The bot is only working with the desktop (Chrome) version of Messenger. If the video file is opened on other platforms, like the mobile webpage or app, it will not work as intended. 

So just take care of the links you open, even if it come from a trusted person. And especially if you are from the Philippines (we have lots of PH players here) and other mentionned countries.

Stay safe peeps ;) 

 

Damn this new type of hacker nowadays, making new techniques in capturing their prey in social medias,

Well a lot people especially in asia and most specifically filipinos are really very lazy logging out their fb accounts even I just used this auto-log in feature always. 

Thanks for this great and helpful info kargai. Ill start warning my friends now on fb 

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...

Important Information

Privacy Policy Terms of Use