LinkedIn Also Targeted
WithSecure reports that DUCKTAIL is scouting for and phishing its targets via LinkedIn, where it selects users likely to have high-level access to a Facebook Business account, especially those with admin privileges.As Mohammad Kazem Hassan Nejad, researcher for WithSecure™ Intelligence, explained:"We believe that the DUCKTAIL operators carefully select a small number of targets to increase their chances of success and remain unnoticed. We have observed individuals with managerial, digital marketing, digital media, and human resources roles in companies to have been targeted."
Partnering with MSPs and MSSPs
WithSecure, which offers partner programs for MSPs and MSSPs, notes that it has detections in place for endpoint protection platforms (EPP) and endpoint detection and response (EDR) solutions. These include static and behavioral detection signatures and detections for multiple stages of the attack lifecycle, according to WithSecure.Hassan Nejad advises that vigilance and alertness are key to avoiding becoming a victim to DUCKTAIL:"Many spear phishing campaigns target users on LinkedIn. If you are in a role that has admin access to corporate social media accounts, it is important to exercise caution when interacting with others on social media platforms, especially when dealing with attachments or links sent from individuals you are unfamiliar with."