CryptocurrenciesNews

Digmine, the miner that expands on Facebook Messenger for computer

New script for mining cryptocurrencies, in this case it is a false video file that is expanded by Facebook Messenger for the computer and that receives the name, the miner, from Digmine.

The security firm Trend Micro, reports that a cryptocurrency mining bot has been found that is being distributed through Facebook Messenger, specifically in the Google Chrome browser for the desktop. This has been called Digmine and was first detected in South Korea and has since spread to Azerbaijan, the Philippines, Thailand, Ukraine, Venezuela and Vietnam. There is a high probability that this bot will appear shortly in Europe, as it is expanding at a great speed.

The report indicates that Digmine began to spread through Facebook Messenger, appearing in chat as an unincorporated video file. The recipient user, when he clicks on the file, the one named as video, is actually an executable script, which downloads components from a remote server that are installed in Chrome as an extension. The Extension keeps broadcasting the fake video as a decoy or logging into Facebook to spread malicious love among the social network contacts.

Extensions can normally only be installed on Chrome from the Chrome Web Store. Digmine configuration avoids this requirement by installing the Extension using the command prompt. During this installation process, the script will receive the configuration through a remote server and the upload instructions where the fake video is hosted, in which there are additional configurations, or by accessing Facebook if users have Chrome configured to automatically log in. in this social network.

“A known modus operandi of cryptocurrency mining botnets, and particularly for Digmine (which mines Monero), is to remain on the victim’s system for as long as possible,” Trend Micro explains. “It also wants to infect as many machines as possible, as this translates into an increase in hashrate and potentially more cybercriminal revenue.”

While it is running, it undermines the cryptocurrency in the background, while we continue browsing the net. The item for mining, a file named codec.exe for the PC, is a modified version of the Monero open source miner, which is named XMRig. This operates with a remote server, to obtain coins in secret. This one could also be used for many more things than mining Monero. Digmine could receive an update to hijack Facebook accounts, simply by having hackers remotely modify the code to take possession of the accounts. Facebook has been tipped off by Trend Micro and has blocked and removed the links to the fake videos.

To fix it, we just have to go to the Customize and control button in Chrome, and select More tools> Extensions in the drop-down menu. On the resulting page, remove all suspicious enabled extensions. Of course, the best way to avoid infections of any kind is not to click on the files and links sent through Facebook Messenger. But since friends you trust launch back and forth links every day, avoiding malware that way can be difficult.

Source: DT

Show more

Robert Sole

Director of Contents and Writing of this same website, technician in renewable energy generation systems and low voltage electrical technician. I work in front of a PC, in my free time I am in front of a PC and when I leave the house I am glued to the screen of my smartphone. Every morning when I wake up I walk across the Stargate to make some coffee and start watching YouTube videos. I once saw a dragon ... or was it a Dragonite?

Related publications

A comment

Leave your comment

Your email address will not be published. Required fields are marked with *

Button back to top
CLOSE

Ad blocker detected

This site is funded through the use of advertising. We always make sure that the advertising is not too intrusive for the reader and we prioritize the reader's experience on the website. However, if you block the ads, part of our funding will be reduced.