Ducktail is a Windows-based information-stealing malware family and associated financially motivated operation focused on hijacking Facebook Business and advertising accounts. Active since at least the second half of 2021 and widely linked to Vietnam-based operators, it targets individuals and organizations likely to manage Meta advertising assets, especially marketing, digital media, managerial, and HR personnel.
Ducktail is best known for stealing browser cookies and abusing already authenticated Facebook sessions rather than relying solely on credential theft. It enumerates installed browsers, extracts browser data and Facebook session material, and uses the victim’s own machine and session context to interact with Facebook services and APIs in a way intended to appear legitimate. When it identifies access to a Facebook Business account, it attempts account takeover actions such as adding attacker-controlled email addresses with high-privilege business roles, enabling persistent control over advertising assets and abuse of ad spend.
Observed Ducktail variants have been implemented in multiple forms, including .NET Core single-file executables, Delphi-based samples, malicious browser-extension workflows, and LNK-triggered PowerShell chains. The malware commonly includes anti-analysis checks, browser and system reconnaissance, and exfiltration through Telegram. Some campaigns also used decoy documents or media to mask execution and improve social-engineering success.
Delivery has centered on highly targeted social engineering. Operators have used fake LinkedIn recruiter personas, job-offer lures, direct messages, and follow-on archive downloads aimed at professionals likely to hold advertising privileges. Additional distribution has used phishing emails, fake websites impersonating marketing or AI-related tools, cloud-hosted archives, and LNK-based lure packages. Campaigns have also used spoofed branding, fake document icons, and decoy files to increase credibility.
The operation’s objective is primarily monetization through takeover and abuse of Facebook Business and Ads accounts, including malvertising and related advertising fraud. Ducktail is frequently discussed alongside other Vietnam-linked ad-account theft malware families, but it remains distinct for its focused abuse of Facebook business sessions and role-management workflows.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
35 distinct techniques documented for this family, organized by ATT&CK tactic.
threat actors also registered many custom domains through Rebrandly, spreading shortened links with their own fake company name domains
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
Our team also observed cases where threat actors sent infected archive links through email, after making initial contact on LinkedIn. The image below shows a spear phishing email example.
The campaign saw the bad actor send out an archive containing images of new products by bona fide companies along with a malicious executable disguised with a PDF icon.
Type 2 Archive - .lnk files with PowerShell payloads, plus .scr executables, both obscured by double extensions (.pdf.lnk, .docx.scr)
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
The PowerShell command inside the LNK is lightly obfuscated using simple tricks like adding quotes, concatenation, and string replace which are used to bypass static detections.
Double-clicking the executable (camouflaged as another type of file) inside it... Includes a fake Office or PDF document icon... .lnk files with PowerShell payloads, plus .scr executables, both obscured by double extensions (.pdf.lnk, .docx.scr)
Finally, the 2nd-stage PowerShell deletes the initial LNK file to cover its tracks
Ad account theft, the systematic hijacking of Meta Business Manager and Google Ads accounts, has grown into a commodity-driven cybercrime economy... Legitimate ad spend history raises account trust scores, meaning aged, active accounts can serve ads that pass platform safety checks that would reject a new attacker-created account.
.NET core “single file” apps are multiple binaries appended to one another... the first binary in the append chain has the responsibility of being a “.NET loader” that loads subsequent .NET resources (appended after the loader) into memory at runtime. Once the resources get loaded, the actual .NET app gets run.
Malware tries to ping IP address in HEX format to check internet connectivity.
T1057 Process Discovery If there are less than 150 running processes the malware won’t execute.
It constantly sends the details of all open browser tabs to the command-and-control (C&C) server, and if detecting Facebook-related URLs, checks for ads and business accounts to try and steal them.
47 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
19 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Vietnam-linked malware family associated with theft of Meta Business Manager and Google Ads accounts.
Related Posts: Beware of LinkedIn: Ducktail Malware’s Sneaky ZIP Attack Revealed
"Ducktail & Quasar RAT: Vietnamese Threat Actors Target Meta Ads Professionals"
Credential and session theft malware focused on hijacking Facebook/advertising-related accounts. It is distributed via fake LinkedIn job offers, spear phishing, and spoofed marketing/AI tool websites; payloads are commonly .NET executables, sometimes Excel add-ins or browser extensions, and may use Telegram for C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.