DUCKTAIL is an information-stealing malware operation focused on hijacking Facebook Business/Ads accounts. Reporting attributes the activity with high confidence to a financially motivated Vietnam-based threat actor, with malware development and distribution observed since at least the second half of 2021 and possible earlier cybercriminal activity dating to 2018. The malware targets individuals and organizations that use Facebook Business/Ads, especially employees in managerial, digital marketing, digital media, and HR roles.
Observed delivery relies on social engineering, including spearphishing via LinkedIn, with lures sent to marketing and HR professionals. Payloads have been hosted on cloud/file-sharing services including Dropbox, iCloud, and MediaFire, and are often packaged in archives containing decoy documents, images, or videos. Filenames have used brand, product, and project-planning themes such as "products.pdf.exe" and "new project l'oréal budget business plan.exe," sometimes localized with country names. DUCKTAIL has also been observed in malicious LNK campaigns; one documented variant used caret (^) obfuscation in shortcut commands, and the decoded command downloaded an additional file from C2.
Functionally, DUCKTAIL scans for installed browsers including Google Chrome, Microsoft Edge, Brave, and Firefox, and steals stored browser cookies, especially Facebook session cookies. It also collects browser and system metadata, including browser details from HKLM\SOFTWARE[WOW6432Node]Clients\StartMenuInternet, and if Edge or Chrome is present it launches the browser headlessly with --dump-dom against whatismybrowser[.]com and api[.]myip[.]com to obtain user-agent, IP address, and country information. Stolen data is stored in %TEMP% text files such as temp_update_data.txt and temp_update_data_9.txt. The malware uses mutexes including "data" and "version_2" to enforce single-instance execution.
A core DUCKTAIL capability is abuse of already authenticated Facebook sessions from the victim machine to appear benign and evade Meta security controls. Using stolen session cookies and derived credentials, it interacts with Facebook pages and APIs, including the Graph API, to enumerate account information and business assets. Reported data theft includes personal Facebook account details such as name, email, birthday, and user ID from the c_user cookie. The malware also checks whether Facebook 2FA is enabled and attempts to fetch recovery codes; unused code reportedly suggests an attempt to generate a new login approval code.
The primary monetization behavior is Facebook Business takeover. DUCKTAIL attempts to add attacker-controlled email addresses to victim Facebook Business accounts with high-privilege roles, specifically Admin and Finance Editor, enabling persistent control and abuse of ad spend for malvertising and related fraud. WithSecure reported a newer mechanism allowing the operator to send a list of email addresses via the malware’s command channel to hijack a specific business.
Implementation details in reporting state that since late 2021 DUCKTAIL samples have been written in .NET Core and compiled as single-file executables to embed dependencies such as Telegram.Bot and reduce detection. Separate analysis also documented DuckTail-related samples using .NET ahead-of-time (AOT) compilation, producing native PE binaries with traits such as a single export named DotNetRuntimeDebugHeader and a .managed section. In one detonated sample, the malware created a new local account and was followed by an operator RDP session during which additional tools were downloaded and cookies were stolen.
Exfiltration has been reported via Telegram bot channels. Some samples were signed with valid Sectigo-issued certificates, and reporting states all known samples signed with the cited certificates were malicious. High-confidence infrastructure and artifacts mentioned in the content include whatismybrowser[.]com, api[.]myip[.]com, mutexes "data" and "version_2," temporary files temp_update_data.txt and temp_update_data_9.txt, and valid-signing certificate SHA1 fingerprints 92a7ac122ab87ccfd19224b2be89fd7bbee6d0b1 and c8d5b988464e7e49b932a01d3b75e192fc7a0026.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
“...directly target individuals within the company/business that might have high-level access... observed individuals with managerial, digital marketing, digital media, and human resources roles...”
“...targets individuals and organizations that operate on Facebook’s Business/Ads platform... performs information stealing as well as Facebook Business hijacking.”
Command and Scripting Interpreter (T1059.001) ... clicking the deceptive LNK file ... initiates a chain of events. Upon execution, the LNK file triggers a command that copies a malicious file.bat from a remote domain to the %USERPROFILE%\Music\file.bat directory on the targeted host.
Obfuscated Files or Information (T1027) Another technique we saw commonly used in phishing .LNK campaigns is the obfuscation of scripts it tries to execute, such as PowerShell or batch script. Figure 04 shows a ducktail LNK campaign that uses a caret “^” symbol as an obfuscation technique to break up commands or expressions to hinder readability and evade detection by security tools.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related Posts: Beware of LinkedIn: Ducktail Malware’s Sneaky ZIP Attack Revealed
"Ducktail & Quasar RAT: Vietnamese Threat Actors Target Meta Ads Professionals"
Credential/cookie-stealing malware associated with hands-on-keyboard follow-on activity (e.g., creating a local account, RDP access, downloading additional tooling) and observed here using .NET Ahead-Of-Time (AOT) compilation to hinder reverse engineering.
An infostealer designed primarily to steal browser data.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.