Digmine, the miner that expands on Facebook Messenger for computer
New script for mining cryptocurrencies, in this case it is a false video file that is expanded by Facebook Messenger for the computer and that receives the name, the miner, from Digmine.
The security firm Trend Micro, reports that a cryptocurrency mining bot has been found that is being distributed through Facebook Messenger, specifically in the Google Chrome browser for the desktop. This has been called Digmine and was first detected in South Korea and has since spread to Azerbaijan, the Philippines, Thailand, Ukraine, Venezuela and Vietnam. There is a high probability that this bot will appear shortly in Europe, as it is expanding at a great speed.
The report indicates that Digmine began to spread through Facebook Messenger, appearing in chat as an unincorporated video file. The recipient user, when he clicks on the file, the one named as video, is actually an executable script, which downloads components from a remote server that are installed in Chrome as an extension. The Extension keeps broadcasting the fake video as a decoy or logging into Facebook to spread malicious love among the social network contacts.
Extensions can normally only be installed on Chrome from the Chrome Web Store. Digmine configuration avoids this requirement by installing the Extension using the command prompt. During this installation process, the script will receive the configuration through a remote server and the upload instructions where the fake video is hosted, in which there are additional configurations, or by accessing Facebook if users have Chrome configured to automatically log in. in this social network.
“A known modus operandi of cryptocurrency mining botnets, and particularly for Digmine (which mines Monero), is to remain on the victim’s system for as long as possible,” Trend Micro explains. “It also wants to infect as many machines as possible, as this translates into an increase in hashrate and potentially more cybercriminal revenue.”
While it is running, it undermines the cryptocurrency in the background, while we continue browsing the net. The item for mining, a file named codec.exe for the PC, is a modified version of the Monero open source miner, which is named XMRig. This operates with a remote server, to obtain coins in secret. This one could also be used for many more things than mining Monero. Digmine could receive an update to hijack Facebook accounts, simply by having hackers remotely modify the code to take possession of the accounts. Facebook has been tipped off by Trend Micro and has blocked and removed the links to the fake videos.
To fix it, we just have to go to the Customize and control button in Chrome, and select More tools> Extensions in the drop-down menu. On the resulting page, remove all suspicious enabled extensions. Of course, the best way to avoid infections of any kind is not to click on the files and links sent through Facebook Messenger. But since friends you trust launch back and forth links every day, avoiding malware that way can be difficult.
Source: DT
Ufff good data, thanks for sharing