Digmine Cryptocurrency Mining Malware Being Spread via Facebook Messenger: Trend Micro

Advertisement
By Indo-Asian News Service | Updated: 25 December 2017 16:35 IST
Highlights
  • Digmine malware said to only affect Messenger's desktop, Web versions
  • Digmine was first observed in South Korea
  • It has since spread to Vietnam, Thailand, and other countries

A new cryptocurrency-mining bot, named "Digmine", that was first observed in South Korea, is spreading fast through Facebook Messenger across the world, Tokyo-headquartered cyber-security major Trend Micro has warned.

After South Korea, it has since spread in Vietnam, Azerbaijan, Ukraine, the Philippines, Thailand, and Venezuela. It is likely to reach other countries soon, given the way it propagates.

Facebook Messenger works across different platforms but Digmine only affects the Messenger's desktop or Web browser (Chrome) version. If the file is opened on other platforms, the malware will not work as intended, Trend Micro said in a blog post.

Advertisement

Digmine is coded in AutoIt and sent to would-be victims posing as a video file but is actually an AutoIt executable script.

Advertisement

If the user's Facebook account is set to log in automatically, Digmine will manipulate Facebook Messenger in order to send a link to the file to the account's friends.

The abuse of Facebook is limited to propagation for now, but it wouldn't be implausible for attackers to hijack the Facebook account itself down the line. This functionality's code is pushed from the command-and-control (C&C) server, which means it can be updated.

Advertisement

A known modus operandi of cryptocurrency-mining botnets and particularly for Digmine (which mines Monero), is to stay in the victim's system for as long as possible. It also wants to infect as many machines as possible, as this translates to an increased hash rate and potentially more cybercriminal income, the blog post stated.

The malware will also perform other routines such as installing a registry autostart mechanism as well as system infection marker. It will search and launch Chrome, then load a malicious browser extension that it retrieves from the C&C server.

Advertisement

If Chrome is already running, the malware will terminate and relaunch Chrome to ensure the extension is loaded. While extensions can only be loaded and hosted from the Chrome Web Store, the attackers bypassed this by launching Chrome via command line.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's When Xiaomi Will Launch the Xiaomi 17 and Xiaomi 17 Ultra Globally
  2. Xiaomi Teases a New Computing Device, New Tablet Expected to Launch Soon
  3. OTT Releases of the Week (Feb 16 - Feb 22): Know What to Watch This Weekend
  4. Poco X8 Pro, X8 Pro Max Colour Options, Design Leaked Online
  5. Motorola Edge 70 Fusion India Launch Teased; Might Launch With This Chip
  6. Realme P4 Lite With 6,300mAh Battery Launched at This Price in India
  7. Vivo V70 Elite Review: Vivo's V-Series Goes 'Elite'
  8. Samsung's One UI 8.5 Update Will Bring These Useful Upgrades to Bixby
  9. Hello Bachhon Set for OTT Release on Netflix: See Details
  10. Redmi A7 Bags Thailand's NBTC Certification, Could Launch Soon
  1. Redmi A7 Could Launch Soon as Handset Bags Thailand’s NBTC Certification
  2. Poco X8 Pro, Poco X8 Pro Max Design and Colour Options Seen in Leaked Renders
  3. Hello Bachhon OTT Release Date: When and Where to Watch Vineet Kumar Singh Starrer Online?
  4. Xiaomi Teases India Launch of New Computing Device; New Tablet With Keyboard or Laptop Expected
  5. Realme C83 5G India Price, RAM and Storage Configurations Leaked Online
  6. Xiaomi 17 Series Global Launch Date Announced; Xiaomi 17, Xiaomi 17 Ultra Expected to Debut
  7. Google Blocked 266 Million Risky App Installs, Prevented 1.75 Million Policy-Violating Apps in 2025
  8. Motorola Edge 70 Fusion India Launch Teased on Flipkart; Leaked Marketing Image Hints at Snapdragon 7s Gen 4 SoC
  9. Google Releases Gemini 3.1 Pro With Ability to Execute Complex Tasks; Pomelli Gets New Photoshoot Feature
  10. Theatre: The Myth of Reality OTT Release: Where to Watch Kerala Film Critics Award-Winning Movie Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.