logo

Ducktail Infostealer Targets Facebook Business Accounts

ID: abacdf11-e268-5c7d-b2b0-6f1624254ff8

STIX ID: report--abacdf11-e268-5c7d-b2b0-6f1624254ff8

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes an active Ducktail infostealer campaign where threat actors distribute a PHP-based stealer bundled as cracked or free installers (ZIPs) to harvest browser-stored credentials, Facebook Business/Ads account information, and wallet data; the campaign uses a multi-stage execution (PHP scripts, .NET job-scheduling binary, auxiliary executables) to achieve persistence and exfiltrates stolen data to JSON-hosted C2 endpoints. The document provides code-level analysis of the PHP stealer, network behavior, IOC hashes and filenames, and maps observed techniques to MITRE ATT&CK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.