VietCredCare and DuckTail Infostealers
by Boat - Sunday November 24, 2024 at 05:41 AM
#1
1. VietCredCare Infostealer
Focus: Domestic Facebook Account Theft (Vietnam)

Key Features:

Specifically targets Vietnamese Facebook users.
Steals Facebook credentials and sensitive session data.
The stolen accounts are resold to domestic cybercriminal networks, fueling further fraud and identity theft.
Example:

A small business owner in Vietnam uses Facebook for customer engagement.
After clicking on a malicious ad, the owner unknowingly downloads VietCredCare.
The malware extracts credentials and session cookies from their browser.
The compromised account is then sold on underground forums to scammers who use it for phishing campaigns or fraudulent e-commerce ads targeting other users in Vietnam.

2. DuckTail Infostealer
Focus: International Facebook Business Accounts

Key Features:

Targets high-value Facebook Business accounts worldwide.
Specializes in extracting session cookies to bypass multi-factor authentication (MFA).
The malware is distributed via spear-phishing campaigns and malicious links.
Once access is obtained, attackers use the accounts to run unauthorized advertising campaigns, often promoting scams.
Example:

A digital marketer in the U.S. receives a LinkedIn message with a proposal from a potential client.
The message contains a link to a shared Google Drive folder, which downloads the DuckTail malware.
DuckTail steals the session data and takes control of the marketer's Facebook Business account.
The attackers use the account to run fraudulent ads, depleting the marketer's ad budget and damaging their reputation.

How They Operate
Distribution Channels:

VietCredCare is spread via malicious links on local forums, pirated software, and phishing emails targeting Vietnamese users.
DuckTail uses LinkedIn spear-phishing campaigns and malicious documents to target business professionals.
Data Exfiltration:

Both malware variants focus on stealing browser-stored cookies, credentials, and session tokens, bypassing MFA.
Stolen data is either resold or used directly by the attackers for fraud.
Reply
#2
i can not down lad it

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Contact Administration.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  AI-Powered Vulnerability Scanners: Acunetix & Nessus op404 57 3,579 Apr 29, 2026, 09:19 AM
Last Post: Usercomplex
  Malware Development - Part 4 op404 19 1,469 Apr 21, 2026, 11:30 PM
Last Post: Bugatti
  Bluesnarfing op404 10 949 Feb 10, 2026, 08:06 AM
Last Post: windandweather
  Google Recovery Email/Phone bypass 085 114 13,640 Feb 08, 2026, 03:48 AM
Last Post: poneyyintheonion1
  ? Mantis: AI-Powered Exploit Development & Automation op404 19 1,520 Feb 07, 2026, 12:03 AM
Last Post: cryptokni8

Forum Jump:


 Users browsing this forum: 1 Guest(s)