Full Report
Following the arrest in May 2024 of more than 20 individuals behind Facebook infostealers campaigns in Vietnam, we have compared the tactics of operators behind VietCredCare and DuckTail stealers. These 2 malware families have been active before the arrest in Vietnam and are believed to be controlled by Vietnamese threat actors. Based on the research, we decided that the groups operate in a different way and the arrest probably affected the VietCredCare operators.
Analysis Summary
# Threat Actor: VietCredCare & DuckTail Operators
## Attribution & Identity
* **Actor Identification:** Vietnamese threat actors.
* **Aliases/Associated Groups:** Specifically associated with the **VietCredCare** and **DuckTail** stealer families.
* **Known Associations:** In May 2024, more than 20 individuals were arrested in Vietnam in connection with Facebook infostealer campaigns. While both groups are Vietnamese, they are believed to operate as distinct entities with different operational models.
## Activity Summary
* **Recent Campaigns:** Systematic harvesting of Facebook credentials (specifically targeting business and ad accounts) throughout 2023 and into mid-2024.
* **Impact of Law Enforcement:** Research indicates that the May 2024 arrests likely impacted the **VietCredCare** operators more significantly than the DuckTail operators, due to differences in their organizational structure.
## Tactics, Techniques & Procedures
* **Social Engineering:** Use of lures disguised as legitimate software, cracked applications, or business-related documents to trick users into executing malware.
* **Credential Harvesting:** Specific focus on extracting cookies and login credentials from web browsers to bypass authentication.
* **Session Hijacking:** Utilizing stolen session tokens to gain unauthorized access to Facebook accounts without needing passwords or 2FA.
* **Automation:** Both actors use automated tools to verify the "value" of a compromised account (e.g., checking for linked credit cards or managed advertisement pages).
* **MITRE ATT&CK IDs:**
* T1566 (Phishing)
* T1539 (Steal Web Cookies)
* T1555 (Credentials from Password Stores)
* T1059 (Command and Scripting Interpreter)
## Targeting
* **Sectors:** Digital marketing, social media management, e-commerce, and general Facebook users with business/advertising permissions.
* **Geography:** Global targeting, though the operators are localized in Vietnam.
* **Victims:** Individuals managing Facebook Business Suite accounts and Meta Ads Manager accounts.
## Tools & Infrastructure
* **Malware Families:**
* **VietCredCare:** An information stealer specifically designed to target Facebook credentials.
* **DuckTail:** A long-standing malware family focused on hijacking Facebook Business accounts.
* **Infrastructure:**
* **C2:** Telegram bots are frequently used for data exfiltration (exfil).
* **Domains:** Malicious domains used for hosting malware payloads (e.g., `example-phish-link[.]com`).
* **Defanged Examples:** `hxxps[://]www[.]group-ib[.]com/blog/vietcredcare-stealer/`
## Implications
These actors represent a specialized segment of the "Cybercrime-as-a-Service" market focused on social media equity. By compromising ad accounts, they facilitate financial fraud through unauthorized advertising spend or resell high-value access on the dark web. The resilience of DuckTail post-arrest suggests a highly decentralized or geographically dispersed operation compared to VietCredCare.
## Mitigations
* **Identity Protection:** Enforce hardware-based Two-Factor Authentication (2FA) where possible, as session theft can bypass SMS/App-based 2FA.
* **Session Management:** Implement corporate policies to regularly clear browser cookies and log out of active sessions on sensitive business platforms.
* **Monitoring:** Use Digital Risk Protection (DRP) services to identify brand impersonation and phishing sites targeting employees.
* **Endpoint Security:** Deploy EDR/XDR solutions to detect the execution of unauthorized scripts or credential-dumping tools.
* **Incident Response:** In the event of compromise, immediately revoke all active session tokens via the Facebook "Log out of all devices" feature.