DuckTail
Ducktail is a Windows-based information-stealing malware family and associated financially motivated operation focused on hijacking Facebook Business and advertising accounts.
DuckTail
Family profile
Ducktail is a Windows-based information-stealing malware family and associated financially motivated operation focused on hijacking Facebook Business and advertising accounts. Active since at least the second half of 2021 and widely linked to Vietnam-based operators, it targets individuals and organizations likely to manage Meta advertising assets, especially marketing, digital media, managerial, and HR personnel.
Ducktail is best known for stealing browser cookies and abusing already authenticated Facebook sessions rather than relying solely on credential theft. It enumerates installed browsers, extracts browser data and Facebook session material, and uses the victim’s own machine and session context to interact with Facebook services and APIs in a way intended to appear legitimate. When it identifies access to a Facebook Business account, it attempts account takeover actions such as adding attacker-controlled email addresses with high-privilege business roles, enabling persistent control over advertising assets and abuse of ad spend.
Observed Ducktail variants have been implemented in multiple forms, including .NET Core single-file executables, Delphi-based samples, malicious browser-extension workflows, and LNK-triggered PowerShell chains. The malware commonly includes anti-analysis checks, browser and system reconnaissance, and exfiltration through Telegram. Some campaigns also used decoy documents or media to mask execution and improve social-engineering success.
Delivery has centered on highly targeted social engineering. Operators have used fake LinkedIn recruiter personas, job-offer lures, direct messages, and follow-on archive downloads aimed at professionals likely to hold advertising privileges. Additional distribution has used phishing emails, fake websites impersonating marketing or AI-related tools, cloud-hosted archives, and LNK-based lure packages. Campaigns have also used spoofed branding, fake document icons, and decoy files to increase credibility.
The operation’s objective is primarily monetization through takeover and abuse of Facebook Business and Ads accounts, including malvertising and related advertising fraud. Ducktail is frequently discussed alongside other Vietnam-linked ad-account theft malware families, but it remains distinct for its focused abuse of Facebook business sessions and role-management workflows.
Capabilities
- Defense Evasion
- Exfiltration
- Reconnaissance
- Session Hijacking
- Spoofing
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
MITRE ATT&CK