DUCKTAIL

Malware type
spyware, credential-stealer
Family
Malware family
Last IoC activity
2026-07-22 00:32:05
Profile updated
2026-07-07 14:59:13

Targeted industries: technology-and-telecommunications media-and-entertainment

Context

According to Tony Lambert, this is a malware written in .NET. It was observed to be delivered using the .NET Single File deployment feature.

Detection coverage

  • 6 YARA rules

Detection rules

  • RUSSIANPANDA_Ducktail_Myrdpservice_Bot (yara-rule)
  • RUSSIANPANDA_Ducktail_Mainbot (yara-rule)
  • RUSSIANPANDA_Ducktail (yara-rule)
  • DITEKSHEN_MALWARE_Win_Ducktail (yara-rule)
  • WITHSECURELABS_Ducktail_Nativeaot (yara-rule)
  • SIGNATURE_BASE_MAL_Compromised_Cert_Ducktail_Stealer_Jun23 (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Ducktail (report)
  • deepinstinct.com — Ducktail Threat Operation Re Emerges With New Lnk Powershell And Other Custom Tactics To Avoid Detection (report)
  • labs.withsecure.com — Withsecure Research Ducktail (report)
  • harfanglab.io — Reverse Engineering Ida Pro Aot Net (report)
  • appgate.com — Vietnamese Information Stealer Campaigns Target Professionals On Linkedin (report)
  • forensicitguy.github.io — Analyzing Net Core Single File Ducktail (report)
  • yoroi.company — Ducktail Dissecting A Complex Infection Chain Started From Social Engineering (report)
  • f-secure.com — Withsecure Research Ducktail (report)
  • Kaspersky — 111017 (report)
  • Trend Micro — Managed Xdr Investigation Of Ducktail In Trend Micro Vision One (report)
  • labs.withsecure.com — Withsecure Research Ducktail (report)
  • zscaler.com — Look Ducktail (report)

External references