HomeinetDigmine Malware: Spreads via Facebook Messenger

Digmine Malware: Spreads via Facebook Messenger

A new variant of Digmine Malware has emerged and infects users via Google Chrome and Facebook Messenger.

 

Digmine

 

The victims usually receive a file named video_xxxx.zip (where xxxx is a four‑digit number). The file however hides another .EXE file that contains malicious software. Users typically run the executable file, resulting in infection.

The Digminer is written in the AutoIT language and uses C&C servers in order to communicate with infected computers. According to a South Korean security researcher, currently the servers are used only to deliver the Monaro miner and a Chrome extension. After these are installed, it then creates a registry entry in the system to start automatically each time the computer is turned on.

The role of the Google extension is to gain access to the user's profile on Facebook Messenger and to send automated messages to all of their contacts the infected file video_xxxx.zip. The good thing about the hypothesis is that this automated mechanism works only if users have their username and password saved in Google Chrome in order to log into Facebook automatically. In any other case, it appears that the propagation process stops. The countries it targets, for now, are South Korea, Vietnam, Azerbaijan, Thailand, Ukraine, Venezuela and the Philippines.

The Facebook security team announced that it succeeded and deleted all the links and files that contained video_xxxx.zip; however, it is certainly only a matter of time before the creators of Digmine simply create a different file name that will be infected, in order to continue its spread.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS