DuckTail is a financially motivated malware operation linked to Vietnamese threat actors that targets people with access to Facebook Business and advertising accounts, especially marketing and advertising professionals. Researchers said the group commonly uses fake LinkedIn job offers, recruiter impersonation, spear-phishing emails, and bogus marketing or AI-themed websites to deliver malicious archives, often hosted on public cloud services, Trello, or shortened-link infrastructure. Victims are persuaded to open Windows archive files and manually launch malware disguised as documents or job materials, sometimes with decoy files or even instructional videos to improve infection success.
Once executed, DuckTail steals browser cookies and abuses already authenticated Facebook sessions to take over accounts and add attacker-controlled access to business assets. Multiple variants have been observed, including large .NET executables, LNK files that trigger obfuscated PowerShell, Delphi-based loaders, malicious browser extensions, and deployments of commodity stealers such as Doenerium and Vidar. The malware has used Telegram for exfiltration and command-and-control, fake or Vietnamese-linked code-signing certificates, and infrastructure tied to Vietnam; one campaign also used Facebook API requests and the 2fa[.]live service to help bypass two-factor authentication, with detections spanning India, Europe, Asia, the Middle East, and the Americas.

Pull IOCs and campaign context straight into your stack.
11 events from the most recent confirmed update back to the earliest known activity.
ThreatLabz published research focused on how DuckTail is distributed, describing fake LinkedIn recruiter personas, job-offer lures targeting marketing professionals, malicious archives hosted on cloud services or Trello, and attribution clues pointing to Vietnamese operators.
Deep Instinct published analysis of DUCKTAIL's re-emergence, detailing its LNK- and PowerShell-based infection chains, use of public hosting services, and occasional substitution of commodity stealers such as Doenerium and Vidar.
By mid-February 2023, DUCKTAIL resumed attacks using both the older executable-based chain and the newer LNK/PowerShell chain. The wave delivered a 64-bit .NET Core 5 DUCKTAIL payload signed with a new valid certificate and incorporated techniques tested in late 2022.
Deep Instinct observed the operation becoming active again at the beginning of February 2023 after earlier quiet periods that followed public reporting.
Unit 42 reported a previously unreported phishing campaign that began around December 2022 and used two Python-based NodeStealer variants to steal Facebook business account data, browser credentials, and MetaMask wallets. One variant also attempted full Facebook account takeover by purchasing mailbox accounts from Vietnamese services and changing victims' Facebook email addresses.
From November to December 2022, Deep Instinct observed DUCKTAIL relying mainly on archives containing malicious LNK files that launched PowerShell to fetch later stages, while the actor continued experimenting with obfuscation and hosting changes.
In October 2022, Deep Instinct observed DUCKTAIL delivering its custom .NET malware through its established archive-and-executable infection chain, including decoy images and videos.
WithSecure published research on DUCKTAIL as an infostealer targeting people with access to Facebook Business accounts, assessing the actor as Vietnamese and financially motivated. Before release, WithSecure shared its research with Meta, which said it was aware of the scammers and regularly enforced against them.
Securelist described Ducktail as a malware family active since the second half of 2021, aimed at stealing Facebook business accounts.
Securelist said the analyzed 2023 Ducktail campaign persisted from March through early October 2023, with telemetry showing India as the most affected country and additional detections across Europe, Asia, the Middle East, North America, and South America.
Securelist reported a Ducktail campaign running between March and early October 2023 that targeted marketing professionals with fake clothing-company job materials. This campaign used Delphi instead of the earlier .NET-based approach and deployed a malicious browser extension to steal Facebook-related sessions and account data.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 50 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
6 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourceunit42.paloaltonetworks.com
Open sourcedeepinstinct.com
Open sourceforensicitguy.github.io
Open sourcesecurelist.com
Open sourcelabs.withsecure.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.