A phishing campaign is spreading brand new malware targeting Facebook users

Representational image of a cybercriminal
Image Credit: Pixabay (Image credit: Pixabay)

Ducktail, a known phishing campaign that hijacks Facebook accounts running advertising campaigns for businesses, is now distributing a brand new infostealer malware.

According to researchers at according to Zscaler, Ducktail previously used LinkedIn to distribute a piece of malware written in .NET Core that would steal Facebook Business account data stored in a web browser and exfiltrate it into a private Telegram channel which acted as the malware’s command & control server (C2), communicating with target systems to coordinate cyberattacks.

Now, however, Ducktail has been spotted distributing a new malware variant that can not only steal Facebook-adjacent data, but also other sensitive data stored in browsers, such as data related to cryptocurrency wallets, account information, and basic system data. 

Stealing browser data

The C2 has also been changed - the data no longer goes to a Telegram channel, but rather to a JSON website that also stores account tokens and other data needed for on-device fraud.

Zscaler also claimed that the malware is being shared as an archive file uploaded to a legitimate file hosting service. The attackers, they say, made sure that the malware doesn’t get flagged by antivirus software by only loading in memory.

Users can mitigate the damage caused by Ducktail and other malware by switching to an anonymous browser, or simply making sure not to save sensitive information in their browser of choice.

This is especially important because, if malware compromises an endpoint with a Facebook Business account, they may search for additional sensitive financial details such as PayPal data. This includes amounts spent on certain purchases, verification statuses, and more.

In most cases, attackers using malware try to trick people into downloading it by presenting it as movie subtitle files, adult content, or cracks for illegitimate software.

While it’s true that Ducktail’s new infostealer could be evading antivirus software, software that comes with in-built web protection could still be of help against it by blocking access to suspicious sites that may be carrying it.

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
These fake macOS updates are actually just looking to spread malware
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Mac users targeted with new malware, so be on your guard
Hands typing on a keyboard surrounded by security icons
Infostealers on the rise: the latest concern for organizational defenses
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
Hook on Keyboard
Fake DocuSign and HubSpot phishing emails target 20,000 Microsoft Azure accounts
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off