Ducktail Infostealer Targets Facebook Business Accounts
ID: abacdf11-e268-5c7d-b2b0-6f1624254ff8
STIX ID: report--abacdf11-e268-5c7d-b2b0-6f1624254ff8
Feed Name: Zscaler Security Research Blog
This report describes an active Ducktail infostealer campaign where threat actors distribute a PHP-based stealer bundled as cracked or free installers (ZIPs) to harvest browser-stored credentials, Facebook Business/Ads account information, and wallet data; the campaign uses a multi-stage execution (PHP scripts, .NET job-scheduling binary, auxiliary executables) to achieve persistence and exfiltrates stolen data to JSON-hosted C2 endpoints. The document provides code-level analysis of the PHP stealer, network behavior, IOC hashes and filenames, and maps observed techniques to MITRE ATT&CK.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
