Facebook-Centric Malware Operations – Mohammad Kazem, WithSecure
A new infostealing malware, DUCKTAIL, targets marketing and HR professionals through LinkedIn spear phishing campaigns to hijack Facebook business accounts. The report identifies the potential threat actor and also reports that this is the first instance that researchers are aware that utilizes a component that includes functionality specifically designed to hijack Facebook Business accounts – this such functionality separates this particular malware from earlier Facebook-centric malware operations.
Transcript
This is texturing TV. Hey everyone, welcome to techstruck TV got another interview here for you. Now with the first time person on our show.
I want to introduce you to Muhammad kazem. His friends call him cause him so if it's okay, we're gonna call him cosm as well. Muhammad is with what with secure to wit there.
He's with with secure. And for those who are familiar with Sakura was actually formally part of that secure, but Mohamed maybe can tell us about that because then welcome to text drug TV. Nice to have you on Hi Alan, thank you for having me.
I'm a present. Yeah, I've people used to call me because I'm and yeah, I've been working at with secure as a security researcher for four years now ever since graduating and I've been doing threat analysis and threat intelligence and detection engineering ever since then and I'm quite excited to be here and to talk to you today about an interesting piece of research that we've been working on for the past couple of months. Very cool.
You know what army there are people watching this out there who have also recently graduated. Well, maybe not four years ago, but I recently graduated with some sort of cybersecurity training and you know, all we hear about is there's so many job openings in cybersecurity. But yet there are a lot of people who had just coming out of school with cyber security training.
Who can't seem to get those jobs one of the biggest questions we hear is how do I how do I get my first job? How do I break into this business? It sounds like, you know four years ago.
That was where you were. If you wouldn't mind helping some of the folks out here, what advice would you give them? Sure, right it can be difficult to sort of get your foot in the door and sort of start your journey in cybersecurity.
But I think one greatly and the way that I started was through internship and that sort of like I didn't start like I didn't graduate as a cyber security individual. I I studied software engineering but it cyber security keeps my interest and and that's how I started as an intern in F secure and and I think that's a great way because you sort of get a pretty wide scope of the field and also like at which secure we have a lot of Junior like openings and and every now and then we have internship positions that open up so you can you can always give it a shot and and the entry level for like internship and Junior positions with with like usually be for It for for people that have just graduated from universities. actually for that you've worked been working on lately.
Sure, so maybe I can give you a little bit of a story on how it all started. So right a couple yeah a couple months ago, basically. One of our ndr clients came across a suspicious sample that they sent to us for analysis.
And once we analyzed the sample, we quickly identified that it was an enforce information Steeler malware. And I mean information Steeler malware are quite common. Usually what they do is they scan or enumerate someone the victim's machine and and try to steal as much information as they can.
Sometimes they're targeted and that's what the case was here. So it was a Facebook Centric malware. So while it acted as a general information stealer, it was primarily interested in stealing Facebook related information.
And Facebook Centric malware is relatively uncommon there have been some scenarios in the past like the covers dealer or silent phase Campaign which was actually discovered by meta security team themselves. And in that case, it was also targeting the Facebook business and ads platform and there was a report that suggested there was around 4 million dollar in in financial Damage Done by that campaign. So it's a pretty lucrative vector.
But once we got the sample and we analyzed it there were a couple of interesting features that peaked our interest and set it apart from these previous Facebook malware and information stealer. First it was an unknown malware. We weren't able to attribute it to any thread actor or any known malware family or campaign.
net core and using its single file feature, which is basically unheard of for malware. And third it was trying to directly hijack a Facebook business accounts from the victims machine, which was again unheard of in for example silent fate case. It didn't try to hijack the Facebook business account.
But what this malware tried to do is basically try to add the thread actors email address with with the highest privilege as an administrator. So basically trying to get through taxes in essentially to the Business accounts and these basically got us interested to start tracking the campaign and investigating further and what we found was that the threat actor had been actively developing and distributing the malware since late since basically the second half of 2021. net core and what made it and it is that so that basically been lurking in the dark for over a year and they're one of the main reasons among other was that it is targeted in nature while the previous campaigns like the Cooper covers theater and Silent fate where distributed through potentially on one it application and bundles like crack software This Thread actor was directly targeting its victims.
Hmm. So let's let's dive in here a little bit. So first of all, just you know, we have some folks here who are more on the developer side than the security side.
And when we talk about hijacking a Facebook page or LinkedIn group or something like that what we really mean right because I'm is that somehow or another the the malicious? entity takes over the administration of that Facebook or LinkedIn property or could be a Twitter account too. I guess or YouTube or any account, you know like that.
They they hijack the account in that they become the administrator and oftentimes once they become the administrative they'll lock out the you know, legitimate administrators. So it's not easy to go take back control of of that page. Number one.
Number two you saying this was done in dot net does that mean it was only aimed at Windows users not Mac or Linux or anything? Yes, so to serve dive into the first point you mentioned. So basically the thread actor is interested in the Facebook business and ads platform and what basically they try to do is get an admin access with Finance editor role and the threat actors history motives and the technical indicators that we've seen suggest that what the thread actor is interested in because I mean with an administrator role you're basically able to as you mentioned lockout the actual administrators from the business and blackmail them.
But what we believe the chain of evidence suggested is that the threat actor was interested in using the links financial payment methods of those business accounts to run their own malicious ads and use this for monetary gains because and that's one of the reasons like it also makes sense because they it has been working in the dark for quite some time and if they were to block out the administrators and try to make a lot of noise that would bring a lot of bells and and like obviously if the business contacts The Meta like they could gain access back to the back to the account. So it doesn't really make sense for them to want to block out the administrator, but rather quietly run their own malicious ads using the payment methods because you can imagine some big Corp Chance could be spending. Tens of thousands of dollars maybe per month on at like ads and a couple thousand dollars extra wouldn't really make wouldn't bring any bells but it would be but if before the threat actor targeting let's say hundreds of organizations stay with the making a lot of money from this and regarding the usage of dot net.
net core offers cross platform the malware of that was used in the ductile operation specifically targeted windows. Yeah, and how is it delivered? You mentioned, you know prior.
Kind of malicious takeover malware was delivered, you know, hidden and cracked software. How is this one delivered? so based on detail Elementary and the incidents that we had investigated we found out that all of the organizations that were targeted operated on the Facebook business and that's platform and all of the individuals the victims themselves that were targeted all had LinkedIn and all and our Direction and response team had also handle some incidents where the malware was delivered through Linkedin to the victims.
So it basically used a more targeted or spearfishing attack rather than some other common distribution methods like malicious Pam campaigns. And again, this makes also perfect sense for this red actor because with medicine campaigns for instance What the thread actor tries to do is send out the malware or distribute the malware to as many people recipients as possible and hope that they hit the right target But Here by targeting individuals within businesses and companies that you that might have access to this business to this Facebook business accounts, you're basically limiting your scope and and increasing your success rate. as well as remaining under the radar because once you start Distributing this this malware widely, it's going to be picked up rather quickly by by the security industry and by meta, for example, and we saw some of the individuals that we saw were targeted all had all were either part of the digital media or digital marketing human resource rules and managerial roles, which basically indicated that the thread actor would only Target first businesses that did operate on Facebook business and that's platform and own the individuals that might have had Access to the Facebook business account of that company that would allow them to basically invite themselves or open the door for the threat actor to come in and add themselves as an administrator.
hmm interesting stuff there interesting so Muhammad this so we're clear with our rights. This was delivered via like faced LinkedIn messaging and and stuff like that where they would Target someone specifically because they already knew he had Facebook. kind of access and they'd go on LinkedIn and send them a message and but how to click the link to to download the malware Yeah, yeah interesting.
So you mentioned the name ducktail. This is something and I'm sure a lot of our audience probably has no idea. How did you come up with the name?
You know all these malware programs are giving names and ransomware gangs and stuff. Would you guys come up with ducktel here? And this scenario I mean added I know like it's it's quite a it's very exciting or quite interesting like how the malware campaign is named.
But in this case, it doesn't really have any profound meaning like we basically it's basically a spin-off of some of the artifacts we saw while conducting this investigation, so it doesn't really have any profound meaning got it. Let me let me go back up to 50,000 feet because I'm is this the kind of stuff? That keeps you excited that brings you to work every day that makes being a security researcher worthwhile for you.
Yeah, I mean did like analyzing malware and like trying to find these like uncovering these sort of campaigns is definitely one of the things that makes this job very interesting and and exciting because I mean we're out here to protect the people in this like people in businesses in the digital space and that's what we do. Like, that's I mean It's all the technical mythy gritty reversing and and technical stuff that that sort of gives the excitement. But once you manage to uncover these campaigns and and help protect people that's sort of what makes you sleep.
Well at night that you you're you're having an impact in the digital space for people in businesses because everyone's I mean cybersecurities more relevant today than ever and everyone operates in the digital space these days. So yeah, that's that's the exciting part of the job. Very cool.
Hey one last question for people who really want to get more information on ducktail. Where is there an easy URL or should they just go to the opening? Page where can they get more info?
Sure. So the ducktal research is published on our Labs blog so you can just search for ducktale with secure in Google and I'm sure it'll show up as as one of the first first links and And yeah. Check it out.
Hey, yeah. Cuz I'm thank you Mohammed. Thank you for coming on.
We appreciate we appreciate the hard work you're doing too right? It's security researchers like you, you know, try to keep us as safe as we can in these crazy times. Thanks for what you do.
Thanks for coming on techstroke TV, and we'll speak to you soon. Thank you. Take care.
See you. Alrighty, we're gonna take a break here on Tech strong. We'll be back in just a moment.