Ducktail Malware Operation Evolves with New Malicious Capabilities

Share:

The operators of the Ducktail information stealer have demonstrated a “relentless willingness to persist” and continued to update their malware as part of an ongoing financially driven campaign.

“The malware is designed to steal browser cookies and take advantage of authenticated Facebook sessions to steal information from the victim’s Facebook account,” WithSecure researcher Mohammad Kazem Hassan Nejad said in a new analysis.

“The operation ultimately hijacks Facebook Business accounts to which the victim has sufficient access. The threat actor uses their gained access to run ads for monetary gain.”

Attributed to a Vietnamese threat actor, the Ducktail campaign is designed to target businesses in the digital marketing and advertising sectors which are active on the Facebook Ads and Business platform.

Also targeted are individuals within prospective companies that are likely to have high-level access to Facebook Business accounts. This includes marketing, media, and human resources personnel.

The malicious activity was first documented by the Finnish cybersecurity company in July 2022. The operation is believed to be underway since the second half of 2021, although evidence points to the threat actor being active as far back as late 2018.

Bild7 1

A subsequent analysis by Zscaler ThreatLabz last month uncovered a PHP version of the malware distributed as installers for cracked software. WithSecure, however, said the activity has no connection whatsoever to the campaign it tracks under the Ducktail moniker.

The latest iteration of the malware, which resurfaced on September 6, 2022, after the threat actor was forced to halt its operations on August 12 in response to public disclosure, comes with a host of improvements incorporated to circumvent detection.

Infection chains now commence with the delivery of archive files containing spreadsheet documents hosted on Apple iCloud and Discord through platforms like LinkedIn and WhatsApp, indicating diversification of the threat actor’s spear-phishing tactics.

The Facebook Business account information collected by the malware, which is signed using digital certificates obtained under the guise of seven different non-existent businesses, is exfiltrated using Telegram.

“An interesting shift that was observed with the latest campaign is that [the Telegram command-and-control] channels now include multiple administrator accounts, indicating that the adversary may be running an affiliate program,” Nejad explained.

https://thehackernews.com/2022/11/ducktail-malware-operation-evolves-with.html?

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:22 am, Jul 12, 2025
weather icon 20°C
L: 18° | H: 21°
clear sky
Humidity: 73 %
Pressure: 1018 mb
Wind: 5 mph ENE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 0%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:57 am
Sunset: 9:14 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
18° | 21°°C 0 mm 0% 10 mph 70 % 1018 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
17° | 28°°C 0.51 mm 51% 6 mph 66 % 1014 mb 0 mm/h
Mon Jul 14 10:00 pm
weather icon
19° | 26°°C 0.3 mm 30% 15 mph 60 % 1015 mb 0 mm/h
Tue Jul 15 10:00 pm
weather icon
15° | 21°°C 0 mm 0% 12 mph 68 % 1018 mb 0 mm/h
Wed Jul 16 10:00 pm
weather icon
17° | 20°°C 1 mm 100% 13 mph 93 % 1017 mb 0 mm/h
Today 4:00 am
weather icon
17° | 19°°C 0 mm 0% 3 mph 70 % 1018 mb 0 mm/h
Today 7:00 am
weather icon
19° | 19°°C 0 mm 0% 4 mph 69 % 1018 mb 0 mm/h
Today 10:00 am
weather icon
26° | 26°°C 0 mm 0% 5 mph 46 % 1017 mb 0 mm/h
Today 1:00 pm
weather icon
29° | 29°°C 0 mm 0% 7 mph 32 % 1015 mb 0 mm/h
Today 4:00 pm
weather icon
30° | 30°°C 0 mm 0% 10 mph 29 % 1014 mb 0 mm/h
Today 7:00 pm
weather icon
25° | 25°°C 0 mm 0% 10 mph 37 % 1014 mb 0 mm/h
Today 10:00 pm
weather icon
21° | 21°°C 0 mm 0% 6 mph 46 % 1015 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 4 mph 57 % 1014 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,615.36
1.74%
Ethereum(ETH)
€2,532.66
0.69%
XRP(XRP)
€2.34
8.23%
Tether(USDT)
€0.86
0.02%
Solana(SOL)
€139.73
-0.08%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.172305
4.24%
Shiba Inu(SHIB)
€0.000011
0.20%
Pepe(PEPE)
€0.000010
0.12%
Peanut the Squirrel(PNUT)
€0.246209
7.19%
Scroll to Top