DUCKTAIL Malware Targets High-Profile Facebook Accounts

267 million Facebook Account Sold on the Dark Web

DUCKTAIL is the name of a highly specialized piece of malware that targets Facebook Business accounts for the purpose of exploitation.

DUCKTAIL is believed to be linked with a criminal outfit operating out of Vietnam. All campaigns observed using the malware since 2021 have been very specific and highly targeted.

The purpose of DUCKTAIL is to compromise the account of a person who has a high level of control and privileged access to a Facebook Business account. This usually includes the finance editor of the account or its admin.

The malware can scrape information about Facebook sessions stored in cookies and use this to compromise the account. DUCKTAIL has a module that can check if the account in question has multi-factor authentication enabled and if it is on, the malware attempts to grab the recovery codes for it.

Once the account is cracked open, the malware operators can change the account email with one they control and essentially take over the whole account.

This sort of privacy leak can lead to massive damages for bigger entities, the sort that the malware is usually targeting.

July 29, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.