Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsDucktail is an information-stealing malware family that targets Facebook accounts, including valuable Facebook Business access. It can steal browser cookies and credentials, letting attackers reuse a logged-in session; later variants were distributed in ZIP files or installers disguised as free or cracked software and other downloads. A password change alone may not end access if a device is infected or a stolen session remains active.
What Ducktail malware does
Ducktail is a financially motivated infostealer associated in public reporting with Vietnamese threat actors. The earlier operation described by WithSecure focused on people in digital marketing and advertising who were likely to have privileged Facebook Business access. Attackers used stolen browser cookies to reuse authenticated Facebook sessions, gather account information, and take over Business accounts the victim could access.
The objective was not limited to stealing a password. A browser session cookie can act as proof that a user has already signed in. If malware captures a usable session token, an attacker may be able to make requests as that user without entering the password again. Meta has described this broader tactic as malware “capturing session tokens in an attempt to circumvent two factor authentication requirements.” That does not mean every Ducktail infection defeats every MFA setup; it means MFA may not protect an already-stolen authenticated session.
How the campaign changed
Reporting on the early operation and Zscaler’s later PHP variant describes a shift in delivery and audience, while retaining the goal of finding valuable Facebook Business access and payment data.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Dimension | Earlier DUCKTAIL operation | Later PHP campaign |
|---|---|---|
| Victim selection | Focused on selected marketing or HR personnel likely to have privileged Business access. | Broadened lures to ordinary users as well as people with business access. |
| Delivery lure | Digital-marketing and advertising targets were the focus of the reporting; a specific lure format is not stated in the cited summary. | Malicious ZIP files and installers posed as free or cracked applications, games, Office software, subtitle files, and other downloads. |
| Data collection | Browser cookies and authenticated Facebook sessions were central to account takeover. | Sought saved browser credentials, Facebook account information, cryptocurrency-wallet data, and detailed business-account information. |
| Facebook Business activity | Used session access to obtain account information and hijack Business accounts for which the victim had sufficient access. | Identified business accounts and collected associated payment, billing, ownership, verification, page, and PayPal details. |
| Monetization | Account access could be used to run advertisements for financial gain. | Preserved the objective of exploiting business advertising access or payment capacity. |
What Ducktail tried to steal
The PHP variant sought saved browser credentials, Facebook account information, and cryptocurrency-wallet information. When it found a business account, Zscaler reported collection of payment methods, billing cycles and amounts, owner details, verification status, owned pages, and PayPal addresses. That information can help attackers identify which accounts are worth abusing and how the business is configured.
Facebook Business access is attractive because it may provide control over pages, advertising accounts, or payment arrangements. The documented monetization path is unauthorized advertising or other use of the account’s payment capacity. Public reporting cited here does not establish a dependable campaign-wide loss total.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How to tell whether your Facebook Business account may be affected
There is no single public indicator that proves Ducktail was responsible. Treat unexpected account activity as a reason to investigate, especially if you recently ran a suspicious archive or installer on a Windows computer used to access Facebook.
- Look for unfamiliar users, partners, page roles, or other access in the business account.
- Review advertising accounts and campaigns for activity you or your team did not authorize.
- Check payment methods, billing details, and charges for changes or transactions you cannot explain.
- Investigate unexpected changes to owned pages or account ownership and verification details.
- Consider browser credentials and cryptocurrency wallets on the affected device potentially exposed if the malware ran successfully.
These checks can reveal unauthorized access or spending, but a clean-looking account does not prove that a device or browser session is safe.
Rank #3
- FIDO2/Passkey Authentication – Secure, passwordless login with supported platforms. Check if your intended service supports hardware keys before purchase. Works with Gmail, Facebook, GitHub, Dropbox, and more.
- Enhanced Multi-Factor Authentication (MFA): Strengthen account security using either FIDO2.0 authentication or TOTP/HOTP codes, providing flexible options for added protection.
- Universal Connectivity: Features USB-A and NFC compatibility, making it easy to use across various devices including PCs, Macs, iPhones, and Android phones for seamless integration.
- Durable & Portable Design: Built with a 360° rotating metal cover for extra durability. Compact and lightweight, it easily attaches to a keychain for on-the-go convenience. No batteries or network required, ensuring dependable use anywhere.
- FIDO Certified & Business-Ready: Certified for FIDO standards and supported by a range of management software suites, ideal for both individual users and enterprise deployment.
What to do after running a suspicious download
- Isolate the Windows device. Disconnect it from networks and stop using it to sign in to Facebook or other sensitive accounts. If it is a work device, contact your security or IT staff promptly.
- Preserve evidence for investigation. Keep the suspicious file and note when it was downloaded and run, but do not open it again. Follow your organization’s incident-response process rather than attempting cleanup that could destroy useful evidence.
- Scan and remove malware. Use trusted endpoint security or have security staff examine and remediate the device. Do not treat a scan result alone as proof that all stolen data or sessions have been dealt with.
- Revoke Facebook sessions and review business access. From a device you trust, sign out other active sessions where the account controls allow it. Review users, partners, page roles, ad accounts, campaigns, and payment methods; remove access or activity you cannot verify, and escalate suspicious billing promptly.
- Then secure credentials and authentication. Change the Facebook password and any reused passwords from a clean device, and enable strong multi-factor authentication. A hardware security key can help prevent future account access, but it does not clean an infected computer or invalidate cookies already stolen.
Why session theft makes detection difficult
Meta’s analysis of platform-targeting malware explains that a tailored infostealer can capture session tokens and make requests through the victim’s own IP address and browser context, while inspecting the victim’s relationships to business accounts. That can make malicious activity resemble a legitimate user session and complicate detection. It is one reason incident response needs to address the endpoint and active sessions as well as the password.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How many people were affected?
The cited public reporting does not provide a reliable Ducktail victim count or total loss figure. WithSecure told TechCrunch it was unable to determine the operation’s success or how many users had been affected. Group-IB reported that Vietnamese authorities announced arrests of more than 20 people in 2024 in a broader investigation of Facebook infostealer campaigns; that is an enforcement figure, not a count of Ducktail victims.
Quick Recap
Rank #4
- Passwordless World - A revolutionary new way to protect your account info. By being FIDO2 certified by the world’s largest ecosystem for standard-based, interoperable authentication, FIDO2 makes everyday log-in experience effortless and passwordless yet more secure than generic password style security. **Note: FIDO2 does NOT support Mac log-in.
- Online Account Protection - FIDO2 key is backward compatible with U2F protocol and works with the newest Chrome browser with operating systems such as: Windows, macOS, or Linux. U2F can be supported and protected on all websites that follow U2F protocols.
- Multi-factored Authentication - Built-in, advanced HOTP (One Time Password) technology that completes the unique multi-factored authentication process. Eliminate worry and help prevent losing your account info to theft, phishing, hacking, or other online scams. Note: Only Enterprise Users using Azure Active Directory can access Windows Hello log-in via Thetis FIDO2 Security Key.
- Compact And Durable - 360° design with rotating aluminum alloy cover that shields the USB connector when not in use. Tough and durable alloy protects FIDO2 key from daily wear-and-tear, accidental drops, and scratches.
- Portable Design - ultra-portable design allows you to take your FIDO key anywhere you need it.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

