DuckTail

 

DUCKTAIL, a financially motivated malware variant, is crafted by Threat Actors (TAs) based in Vietnam and strategically targets individuals and businesses utilizing Social Media Business/Ads platforms. Since the latter part of 2021, these threat actors have been actively engaged in developing and disseminating malware associated with the DUCKTAIL operation.

This malicious software is intricately designed to extract browser cookies, exploiting active social media sessions to pilfer sensitive information from the victim's social media account. The ultimate objective of the malware operation is to seize control of Social Media Business accounts endowed with substantial access privileges. The threat actors leverage this acquired access to orchestrate advertisements, aiming for financial gains.

Target OS 

  • Windows 7 to Windows 11, both 32-64 bit, including Server editions.

Infection Vector

In this campaign, a new tactic emerges as the threat actor employs LNK (shortcut) files within distributed archives. These seemingly innocuous shortcuts act as a gateway to activate the concealed malware upon interaction. The use of LNK files adds a layer of subtlety to the attack, making it imperative for users to stay vigilant against evolving cyber threats. Comprehensive cybersecurity measures are crucial to thwart such dynamic strategies employed by malicious actors in the ever-changing landscape of online threats.

 Identification

  • C2 Communication
    •  jivesmedia[.]agency
  • Behavior
    •  "C:\ProgramData\Microsoft\Windows\Start Menu\Programs"
    • "\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned"
  • Strings
    •  "powershell.exe powershell.exe -WindowStyle hidden -NoLogo -NoProfile -ExecutionPolicy bypass -EncodedCommand"

MITRE ATT&CK

  •  T1566.001 - Phishing: Spearphishing Attachment
  • T1059.001 - Command and Scripting Interpreter: PowerShell
  • T1539 -  Steal Web Session Cookie
  • T1027 - Obfuscated Files or Information
  • T1589 - Gather Victim Identity Information

Evasion techniques

  •  Obfuscated Files or Information - Ducktail employs base64 encoding techniques to obscure data, encompassing Registry entries and file paths. 

IOC's

for more IOC's 
      

Comments