This article has been created in order to help you to learn what is the FacexWorm remote access Trojan and how to remove this malware completely from your computer plus protect your PC against future infections as well.
The FacexWorm virus is a newly discovered computer threat that bears an advanced infection engine. It targets computer users using redirects and browser hijackers and has the potential to hijack their cryptocurrency assets and spy on them in real time. Read our complete analysis to find out more about it. Our in-depth removal instructions for FacexWorm virus can help victims get rid of the active infections.
|Type||Remote Access Trojan (RAT), Cryptocurrency miner, Trojan|
|Short Description||The FacexWorm virus is a dangerous worm that can hijack sensitive data, including cryptocurrency assets.|
|Symptoms||The users may notice that their browser settings are changed and that interaction with certain sites may lead to unexpected behavior.|
|Distribution Method||Mainly via browser redirects and social engineering scams.|
|Detection Tool|| See If Your System Has Been Affected by FacexWorm |
Malware Removal Tool
|User Experience||Join Our Forum to Discuss FacexWorm.|
FacexWorm – Distribution Methods
The FacexWorm virus is a dangerous worm that has recently been discovered by Trend Labs experts in a worldwide attack against computer users. Instead of the usual email delivery tactics it uses alternative methods that have a high infection ratio. The analysts have observed that the actual mechanism is a fairy complex one.
It involves the setup of fake profiles on Facebook. They are programmed via bots to send out links to the intended victims. The links lead to redirects that open a notification prompt asking the users to install a malware browser hijacker. Thеy represent dangerous browser plugins that have the ability to change the default settings to redirect the victims to a hacker-controlled page. Example system changes include the default home page, new tabs page and the search engine. The developers behind these malware extensions usually make it compatible with the most popular applications: Mozilla Firefox, Google Chrome, Opera, Microsoft Edge, Safari and Internet Explorer. As soon as the threat has been delivered to the target computers the built-in scripts will be initiated.
So far this has been the main method. We envision that the criminals will also set up alternative channels of distribution that can propagate the FacexWowrm virus. A related mechanism is the use of bundle software installers. The hacker operators behind the threat may embed the code into installers of popular applications. Examples include system utilities, computer games or creativity suites. In most cases the virus delivery can happen without the user noticing. Only in certain cases the victims may be presented with the option of disallowing the installation.
Another mechanism is its inclusion into web scripts that can also affect legitimate sites through affiliate and ad networks. Examples include all kinds of banners, pop-ups and redirects.
The hackers behind the FacexWorm virus have been found to operate a multitude of domains and C&C servers.
FacexWorm – Purpose and Activity
Once the FacexWorm virus has infiltrated the victim machine it will automatically start itself. In certain cases the threat can install itself as a persistent threat. This means that it will change various system settings in order to automatically start every time the computer is booted.
When the malware plugin is started it will start to spy on the users activity and particularly their web browser habits. As soon as Facebook or another social network is opened by the users a connection with hacker-controlled servers is started. The hackers can then automatically obtain the OAuth token and therefore gain access to their accounts.
One of the first actions is to harvest the affected victims friends list and use it to send fake YouTube videos to the contacts that are either online or idle. This is done to spread malware or advertisement to the users for scam purposes. The security analysts have detected that when the relevant links are opened in a web browser other than Google Chrome (its desktop variant), the link will be changed to lead to a random advertisement. This will generate income for the operators.
The standard behavior is to execute the code the delivered code. Some of the built-in functions of the captured samples include the following commands:
- Steal Account Credentials — When a compatible service’s login page is open a stealer function will be injected to the web browsers. It is inteded to steal the account credentials of the following sites: Google, MyMonero and Coinhive. It is expected that this list will grow further.
- Cryptocurrency Scams — When the FacexWorm virus detects that the users is accessing cryptocurrency trading platforms or exchanges it will automatically redirect them to a scam site. The currently captured strains have been found to feature a built-in list of 52 sites and a lot of keywords. The scams themselves coerce the victims into sending 0.5 to 10 ETH to the hacker’s wallet address for “verification purposes”.
- Transactions Hijack — Once a cryptocurrency transaction page is opened a on a cryptocurrency-relted site the virus will located the entered recipient address and replace it with the hacker’s own. At the moment the following platforms are implemented: HitBTC, Bitfinex, Ethfinex and Binance. A wallet application is targeted as well (Blockchain.info). The following digital assets are targeted at the moment: Bitcoin (BTC), Bitcoin Gold (BTG), Bitcoin Cash (BCH), Dash (DASH), ETH, Ethereum Classic (ETC), Ripple (XRP), Litecoin (LTC), Zcash (ZEC), and Monero (XMR).
- Referral Programs Infection — Certain web sites can lead to a specific referral link. This means that purchases or certain interactions can lead to direct income being generated for the hackers. At the moment the following sites are targeted: Binance, DigitalOcean, FreeBitco.in, FreeDoge.co.in, and HashFlare.
One of the integral features of the worm is the persistence protection component. It detects when the victims attempt to remove the malware extension by automatically closing the Chrome extensions management page.
Remove FacexWorm from Your Computer
In order to make sure that this nefarious software is completely gone from your computer, security researchers strongly advise following the manual or automatic removal instructions underneath. They are created in order to assist you based on how much experience you have in malware removal. If you lack such experience, be advised that security analysts strongly advise to download an advanced anti-malware software and remove FacexWorm automatically by scanning for all of it’s objects and changed settings and reverting them back to normal. Such tool has the capability to not only fully secure your PC after removing FacexWorm, but also make sure it’s operating system remains protected against future intrusions that might take place.