Digmine Cryptocurrency Mining Malware Being Spread via Facebook Messenger: Trend Micro

Advertisement
By Indo-Asian News Service | Updated: 25 December 2017 16:35 IST
Highlights
  • Digmine malware said to only affect Messenger's desktop, Web versions
  • Digmine was first observed in South Korea
  • It has since spread to Vietnam, Thailand, and other countries

A new cryptocurrency-mining bot, named "Digmine", that was first observed in South Korea, is spreading fast through Facebook Messenger across the world, Tokyo-headquartered cyber-security major Trend Micro has warned.

After South Korea, it has since spread in Vietnam, Azerbaijan, Ukraine, the Philippines, Thailand, and Venezuela. It is likely to reach other countries soon, given the way it propagates.

Facebook Messenger works across different platforms but Digmine only affects the Messenger's desktop or Web browser (Chrome) version. If the file is opened on other platforms, the malware will not work as intended, Trend Micro said in a blog post.

Advertisement

Digmine is coded in AutoIt and sent to would-be victims posing as a video file but is actually an AutoIt executable script.

Advertisement

If the user's Facebook account is set to log in automatically, Digmine will manipulate Facebook Messenger in order to send a link to the file to the account's friends.

The abuse of Facebook is limited to propagation for now, but it wouldn't be implausible for attackers to hijack the Facebook account itself down the line. This functionality's code is pushed from the command-and-control (C&C) server, which means it can be updated.

Advertisement

A known modus operandi of cryptocurrency-mining botnets and particularly for Digmine (which mines Monero), is to stay in the victim's system for as long as possible. It also wants to infect as many machines as possible, as this translates to an increased hash rate and potentially more cybercriminal income, the blog post stated.

The malware will also perform other routines such as installing a registry autostart mechanism as well as system infection marker. It will search and launch Chrome, then load a malicious browser extension that it retrieves from the C&C server.

Advertisement

If Chrome is already running, the malware will terminate and relaunch Chrome to ensure the extension is loaded. While extensions can only be loaded and hosted from the Chrome Web Store, the attackers bypassed this by launching Chrome via command line.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. [Exclusive] Noise to Launch Flagship Master Series Over-Ear Headphones Soon
  2. Nothing Announces Offers on Phones, Wearables During Flipkart Sale
  3. Vivo Y31 Series With 6,500mAh Battery Launched in India: See Price
  4. Samsung Begins Rolling Out One UI 8 Update to the Galaxy S25 Series
  5. Flipkart Big Billion Days Sale: Discounts on Motorola Phones Announced
  6. Xiaomi 17 Pro Max Tipped to Come With a Secondary Display
  7. Oppo Find X9 Launch Timeline Revealed: See Find X9 Pro Camera Samples
  8. iQOO 15 Live Image Leaked; Company Reveals Display Details
  9. Apple AirPods 4 at Rs 9,999, Other Top Deals in Zepto's Fastest Sale Ever
  10. Qualcomm's Snapdragon 8 Elite Gen 5 Will Succeed Its Snapdragon 8 Elite SoC
  1. iOS 26 Update Released Alongside iPadOS 26 and macOS Tahoe: Check Eligible Models, How to Download
  2. Scientists Propose Space Missions to Chase Down Interstellar Comets
  3. Iceland Plume Discovery Reveals Ancient Volcanic Funnels Across North Atlantic
  4. Huawei Watch Ultimate 2 Design Renders Leaked, Could Launch Soon
  5. Marvel's Wolverine Will Reportedly Launch in 2026; Insomniac's Venom Game in 'Active Development'
  6. US President Donald Trump Challenges Block on Removing US Fed’s Lisa Cook
  7. iPhone 17 Series Outpaces iPhone 16 in Demand While iPhone 17 Pro Max Tops Pre-Orders, Analyst Says
  8. iPhone 16 Remained Top Selling Smartphone For Second Consecutive Quarter Globally: Report
  9. Samsung Galaxy S25 FE Launched in India With 6.7-Inch AMOLED Screen, 50-Megapixel Camera: Price, Features
  10. iPhone 18 Series Tipped to Feature Smaller Dynamic Island, Might Launch Without Under-Display Face ID
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.