A New Facebook Messenger Malware Is Targeting Crypto Users

FacexWorm, a malicious Chrome extension, has been recast to target cryptocurrency exchanges.

AccessTimeIconMay 2, 2018 at 7:00 p.m. UTC
Updated Sep 13, 2021 at 7:54 a.m. UTC

A malicious Google Chrome extension known for its effectiveness has been revamped to target cryptocurrency exchanges, cybersecurity company Trend Micro reported this week.

Dubbed FacexWorm, Trend Micro said in a blog post that the malicious extension's capabilities "were made over" to steal user credentials for Google, MyMonero, and Coinhive; in sum, it promotes a scam that dupes users into sending ether to the attacker's wallet and drains a computer's processing power to power clandestine cryptocurrency mining.

The extension also has the ability to hijack cryptocurrency transactions on a variety of major exchanges including Poloniex, HitBTC, Bitfinex, Ethfinex, Binance in addition to Blockchain's (previously Blockchain.info) crypto wallet, according to Trend Micro.

First exposed in August 2017, the malware initially used Facebook Messenger to send malicious links that, when clicked on, provided the attacker with access to users' Facebook accounts while also infecting their operating systems. FacexWorm resurfaced in early April of this year.

Trend Micro said it had discovered one affected bitcoin transaction, but it has not identified the value of the plunder garnered from the crypto mining.

The company reported that Chrome removed many of the FacexWorm extensions prior to Trend Micro's discovery and that Facebook Messenger is also capable of detecting and blocking the insidious links the malware uses.

Chrome banned cryptocurrency mining extensions from its Web Store in early April.

Trend Micro advised users to "think before sharing, be more prudent against unsolicited or suspicious messages and enable tighter privacy settings for your social media accounts."

Minature SWAT team on computer image via Shutterstock

DISCLOSURE

Please note that our privacy policy, terms of use, cookies, and do not sell my personal information has been updated.

The leader in news and information on cryptocurrency, digital assets and the future of money, CoinDesk is a media outlet that strives for the highest journalistic standards and abides by a strict set of editorial policies. CoinDesk is an independent operating subsidiary of Digital Currency Group, which invests in cryptocurrencies and blockchain startups. As part of their compensation, certain CoinDesk employees, including editorial employees, may receive exposure to DCG equity in the form of stock appreciation rights, which vest over a multi-year period. CoinDesk journalists are not allowed to purchase stock outright in DCG.


Learn more about Consensus 2024, CoinDesk’s longest-running and most influential event that brings together all sides of crypto, blockchain and Web3. Head to consensus.coindesk.com to register and buy your pass now.