Malware

Ducktail operation targets Facebook’s Business and Ad Accounts

0

Security researchers have discovered an ongoing campaign dubbed Ducktail that targets individuals and organizations that operate on Facebook’s Business and Ads platform.

According to Finnish cybersecurity company WithSecure (formerly F-Secure Business), the threat actor targets individuals and employees that may have access to a Facebook Business account with an information-stealer malware that is designed to steal browser cookies and take advantage of authenticated Facebook sessions to steal information from the victim’s Facebook account and ultimately hijack any Facebook Business account that the victim has sufficient access to.

The attacks have been attributed to a Vietnamese threat actor and has started in the second half of 2021, with primary targets being individuals with managerial, digital marketing, digital media, and human resources roles in companies.

The threat actors target employees with high-level access to Facebook Business accounts associated with their organizations, tricking them into downloading supposed Facebook advertising information hosted on Dropbox, Apple iCloud, and MediaFire.

In some cases, the archive file containing the malicious payload is also delivered to victims through LinkedIn, ultimately allowing the attacker to take over any Facebook Business account.

An information-stealing malware written in .NET Core, which is engineered to use Telegram for command-and-control and data exfiltration. The researchers have identified eight Telegram channels that were used for this purpose.

It first scans for installed browsers such as Google Chrome, Microsoft Edge, Brave Browser, and Mozilla Firefox to extract all the stored cookies and access tokens, alongside stealing information from the victim’s personal Facebook account such as name, email address, date of birth, and user ID.

The data from businesses and ad accounts connected to the victim’s personal account are also stolen, allowing the threat actor to hijack the accounts by adding an actor-controlled email address retrieved from the Telegram channel and grant themselves Admin and Finance editor access.

The users with Admin roles have full control over the Facebook Business account, while the users with Finance editor permissions can edit business credit card information and financial details like transactions, invoices, account spend, and payment methods.

The global targeting pattern has spanned a number of countries, including the Philippines, India, Saudi Arabia, Italy, Germany, Sweden, and Finland. However, it cannot be estimated as how many users have been affected by the spear-phishing operation.

Facebook Business administrators are advised to review their access permissions and remove any unknown users to secure the accounts.

Image Credits : Madgicx

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Spanish police arrested two accused of hacking radioactivity alert network

Previous article

Australian hacker arrested for distributing spyware to cyber criminals

Next article

You may also like

More in Malware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *