DUCKTAIL
- Malware type
- spyware, credential-stealer
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:32:05
- Profile updated
- 2026-07-07 14:59:13
Targeted industries: technology-and-telecommunications media-and-entertainment
Context
According to Tony Lambert, this is a malware written in .NET. It was observed to be delivered using the .NET Single File deployment feature.
Detection coverage
- 6 YARA rules
Detection rules
- RUSSIANPANDA_Ducktail_Myrdpservice_Bot (yara-rule)
- RUSSIANPANDA_Ducktail_Mainbot (yara-rule)
- RUSSIANPANDA_Ducktail (yara-rule)
- DITEKSHEN_MALWARE_Win_Ducktail (yara-rule)
- WITHSECURELABS_Ducktail_Nativeaot (yara-rule)
- SIGNATURE_BASE_MAL_Compromised_Cert_Ducktail_Stealer_Jun23 (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Ducktail (report)
- deepinstinct.com — Ducktail Threat Operation Re Emerges With New Lnk Powershell And Other Custom Tactics To Avoid Detection (report)
- labs.withsecure.com — Withsecure Research Ducktail (report)
- harfanglab.io — Reverse Engineering Ida Pro Aot Net (report)
- appgate.com — Vietnamese Information Stealer Campaigns Target Professionals On Linkedin (report)
- forensicitguy.github.io — Analyzing Net Core Single File Ducktail (report)
- yoroi.company — Ducktail Dissecting A Complex Infection Chain Started From Social Engineering (report)
- f-secure.com — Withsecure Research Ducktail (report)
- Kaspersky — 111017 (report)
- Trend Micro — Managed Xdr Investigation Of Ducktail In Trend Micro Vision One (report)
- labs.withsecure.com — Withsecure Research Ducktail (report)
- zscaler.com — Look Ducktail (report)