Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

4/30/2018
08:15 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Old Worm, New Tricks: FacexWorm Targets Crypto Platforms

Malicious Chrome extension FacexWorm has reappeared with new capabilities, targeting cryptocurrency platforms and lifting user data.

FacexWorm, a malicious Chrome extension, has been rediscovered targeting cryptocurrency trading platforms and spreading via Facebook Messenger. The Cyber Safety Solutions team at Trend Micro reports it's packing a few new capabilities, including the ability to steal user data.

The extension was first detected in August 2017 and returned the following April amid reports of increased appearances in Germany, Tunisia, Japan, Taiwan, South Korea, and Spain. Like the original, it sends socially-engineered links to friends of affected Facebook account holders.

Unlike the original, it steals accounts and credentials related to FacexWorm's targeted sites. The attack takes potential victims to websites where it injects malicious cryptomining code and redirects to the attacker's referral link for crypto-related referral programs. It hijacks transactions in trading platforms by replacing the recipient address with the attacker's.

The attacker gets a referral incentive every time a victim registers an account, researchers report. Targeted websites include Binance, DigitalOcean, FreeBitco.in, FreeDoge.co.in, and HashFlare.

FacexWorm arrives on victims' machines via socially-engineered Facebook links. Those who click are redirected to a fake YouTube page where they are prompted to install a codec extension (FacexWorm) to play a video. The extension requests privilege to access and edit data on the site.

If permission is granted, FacexWorm downloads malicious codes from its command-and-control server, opens Facebook's website, and checks to see if the propagation function is turned on. If it is, the extension requests an OAuth token from Facebook and begins obtaining the target account's friend list. Contacts who are online or idle are sent fake YouTube links.

"FacexWorm is a clone of a normal Chrome extension but injected with short code containing its main routine," explains Trend Micro fraud researcher Joseph Chen in a blog post on the finding. The threat downloads more code from the C&C server when the browser is opened.

"Every time a victim opens a new webpage, FacexWorm will query its C&C server to find and retrieve another JavaScript code (hosted on a Github repository) and execute its behaviors on that webpage." This JavaScript code, or miner, is an obfuscated Coinhive script connected to a Coinhive pool, configured to use 20% of the target system's CPU power for each threat.

FacexWorm exhibits other malicious behaviors like stealing account credentials for Google, MyMonero, and Coinhive. This threat targets a total of 52 cryptocurrency platforms. When it detects anyone accessing any of them or using keywords like "blockchain" or "ethereum" in the URL, it redirects the user to a fraudulent webpage.

This threat only works in Chrome. If the malicious link is accessed through any browser other than the Chrome desktop version, it redirects to a random advertisement. Trend Micro has only spotted one Bitcoin transaction compromised by FacexWorm based on monitoring the attacker's wallet. Researchers haven't determined how much money the threat has generated.

Related Content:

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/30/2018 | 11:09:11 PM
Performance Impact
I would be surpirsed if this gained legs. If a user takes a 20% cpu hit they are most likely going to report a performance impact.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
4/30/2018 | 11:07:03 PM
Facebook
Talk about kicking facebook while their down. Using Facebook messenger as the medium seems apropos. 
GitHub Named in Capital One Breach Lawsuit
Dark Reading Staff 8/14/2019
The Mainframe Is Seeing a Resurgence. Is Security Keeping Pace?
Ray Overby, Co-Founder & President at Key Resources, Inc.,  8/15/2019
The Flaw in Vulnerability Management: It's Time to Get Real
Jim Souders, Chief Executive Officer at Adaptiva,  8/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5034
PUBLISHED: 2019-08-20
An exploitable information disclosure vulnerability exists in the Weave Legacy Pairing functionality of Nest Cam IQ Indoor version 4620002. A set of specially crafted weave packets can cause an out of bounds read, resulting in information disclosure. An attacker can send packets to trigger this vuln...
CVE-2019-5035
PUBLISHED: 2019-08-20
An exploitable information disclosure vulnerability exists in the Weave PASE pairing functionality of the Nest Cam IQ Indoor, version 4620002. A set of specially crafted weave packets can brute force a pairing code, resulting in greater Weave access and potentially full device control. An attacker c...
CVE-2019-5036
PUBLISHED: 2019-08-20
An exploitable denial-of-service vulnerability exists in the Weave error reporting functionality of the Nest Cam IQ Indoor, version 4620002. A specially crafted weave packets can cause an arbitrary Weave Exchange Session to close, resulting in a denial of service. An attacker can send a specially cr...
CVE-2019-8103
PUBLISHED: 2019-08-20
Adobe Acrobat and Reader versions, 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation ...
CVE-2019-8104
PUBLISHED: 2019-08-20
Adobe Acrobat and Reader versions, 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2017.011.30142 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have an out-of-bounds read vulnerability. Successful exploitation ...