Facebook, Chrome users, and cryptocurrency miners should be aware of a new malware called FacexWorm that infects victims with the aim of stealing passwords, cryptocurrencies, executing cryptomining scripts, and more.

This new variant was detected in late April by Trend Micro researchers and appears to be related to two other Facebook Messenger spam campaigns: one carried out last August and the other in December 2017, spreading the Digmine malware.
Users first receive an unsolicited link via Facebook Messenger. Clicking on the link takes them to a website that mimics YouTube, which attempts to trick the user into installing a YouTube-themed Chrome extension.
Trend Micro says it analyzed the extension and found several malicious functions. This one targets users who have access to Google, Coinhive, or MyMonero accounts. The credentials are then sent to FacexWorm's servers.
Additionally, the illegal extension automatically redirects users to a website prompting them to send a small amount of Ether cryptocurrency to verify their account. The extension includes a list of 52 websites in total.
Third, the extension inserts a cryptomining script, loading the Coinhive miner, which is used to mine Monero.
Last but not least, when users try to access specific websites, FacexWorm redirects them to other addresses (Binance, DigitalOcean, FreeBitco.in, FreeDoge.co.in, and HashFlare).
Trend Micro said it has already taken action by reporting the results of its investigation to both Google and Facebook. Chrome Web Store staff have intervened by removing the infected extensions, while Facebook has banned domains associated with spam messages distributed by FacexWorm.
