Malware Hijacks Facebook Business Accounts Via Phishing

Share post:

Vietnamese threat actors are using a malware called Ducktail to hijack high-profile Facebook Business and advertising platform accounts.

The campaign was uncovered by security researchers at WithSecure. The malware uses browser cookies from authenticated user sessions to take over accounts and steal data.

“The malware is designed to steal browser cookies and take advantage of authenticated Facebook sessions to steal information from the victim’s Facebook account and ultimately hijack any Facebook Business account that the victim has sufficient access to,” researchers wrote on a blog post.

To spread the malware, the financially driven threat actors target LinkedIn users through a phishing campaign. This entices victims with brand, product, and project-related keywords to download an archive file containing the executable malware.

According to researchers, Ducktail works with six key components when it infects a system. It performs Mutex creation and ensures that only one instance of the malware works simultaneously.

Ducktail has two components that are dedicated to stealing files. The first scans an infected machine for Google Chrome, Microsoft Edge, Brave Browser or Firefox. It extracts all cookies in each of the browsers found, including Facebook session cookies.

The second component of information theft is the extraction of data from Facebook Business/Ads accounts that interacts directly with various Facebook endpoints.

The sources for this piece include an article in ThreatPost.

Featured Tech Jobs

SUBSCRIBE NOW

Related articles

Controversial expansion of US surveillance powers nears Senate vote

The US Senate is poised to vote on a significant expansion of Section 702 of the Foreign Intelligence...

Russian-linked hackers target U.S. and European water systems

A Russian military-affiliated hacking group, Sandworm, is suspected of coordinating recent cyberattacks on water utilities in the U.S.,...

Cisco Duo’s Multifactor Authentication service compromised by social engineering attack

Cisco Duo, a prominent provider of multifactor authentication (MFA) services, has fallen victim to a cyberattack targeting one...

Cyber Security Today, April 17, 2024 – More suspicious attempts to take over open source projects, a data theft at a Cisco Duo partner,...

This episode reports on security updates from Delinea and PuTTY, and reports on bad bots and threat actors going after Zoo

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways