Vietnamese threat groups targeting Meta Business accounts

Authors

Mohammad Kazem Hassan Nejad

Senior Threat Intelligence Researcher, WithSecure

Download report/s

Social media presents the biggest amalgamation of people and businesses in today’s connected world, with an estimated 4.9 billion people using these services. Social media also provides organizations with a platform to engage the world around them – capabilities the majority of businesses take advantage of in one way or another.

While the incentives are high for businesses to leverage social media for their own benefit, these platforms provide adversaries, with different intent and capabilities, with other opportunities. The adversarial challenges presented by these platforms are extensive, dynamic, complex, and most importantly, harmful.

In this report we share an overview of current and emerging threats surrounding Meta’s ad ecosystem that are pre-dominantly originating out of Vietnam. Additionally, we will share an update on the infamous DUCKTAIL operation exposed in our previous reports DUCKTAIL: An infostealer malware targeting Facebook Business accounts and DUCKTAIL returns: Underneath the ruffled feathers. Lastly, we will introduce an emerging threat dubbed “DUCKPORT” which has striking similarities to DUCKTAIL, but with important and distinct functionalities, TTPs, and history.

 

If you believe your business has been targeted or fallen victim to the same or similar attack and require assistance, you can reach out to our 24/7 incident hotline Emergency Cyber Security Incident Response | WithSecure™. If you like to collaborate on future research with WithSecure Intelligence, you may reach out at wit-data-driven-threat-insights@withsecure.com .

Download report/s

What next?

Discover WithSecure™ Elements Exposure Management.
– No credit card required. No obligations.No complexity.

Related Labs content

Find related content relating to this topic.

W/Labs

Attack Detection Software Protection Threat intelligence

DarkGate Rises: New version of DarkGate malware hunts like a Duck but bites like a RAT

On 4th August 2023, WithSecure Detection and Response Team (DRT) received an alert regarding spoofed process injection with abnormal memory characteristics on a host belonging to a WithSecure Countercept MDR customer.

W/Labs

Attack Detection Software Protection Threat intelligence

Reverse engineering a Lumma infection

Lumma is an information stealer that the WithSecure Detection and Response Team (DRT) have encountered several times. It has seen wider use over the past couple of years, and makes for an interesting threat to monitor.

W/Labs

AI security Attack Detection Software Protection

Machine learning-driven malware analysis

With the rapid emergence of new malware variants, accurately classifying and attributing malware samples has become more challenging than ever