FacexWorm, a malware that has spread through the Facebook messenger, has impacted cryptocurrency trading platforms and web-wallets. The malware appears in messenger and starts by displaying a fake error message that directs users to a fake YouTube page. It then tricks them into installing some Google Chrome extension. Malware would then send links to those in the friends list to retrieve data for any credentials when these people visit different websites; they are also redirected to cryptocurrency scams. The malware would hijack transactions by replacing a recipient address with the attackers address in every web-wallet, cold wallet or active trading platform.”]
Source: https://hackercombat.com/cryptocurrency-mining-malware-spreads-through-fb-messenger/