Categories: Tech & Ai

AI videos on TikTok are tricking users into downloading malware


Wake up, babe — a new form of social engineering just dropped.

Cybercriminals on TikTok are using videos to trick users into downloading malware, according to researchers from Trend Micro, a global cybersecurity firm. The researchers say this is a “novel social engineering campaign” designed to take advantage of TikTok users.

In the videos, which are most likely AI-generated, users are promised free versions of Windows and Microsoft Office software or access to premium features in apps like CapCut and Spotify. All you have to do, the cybercriminals say, is execute a simple PowerShell command. People are following the instructions in the TikTok videos because they’re being disguised as software activation steps, which the bad actors then use to inject malware like Vidar and StealC into the users’ systems. And according to Bleeping Computer, many of the videos have hundreds of thousands of views.

Mashable Light Speed

PowerShell commands are short lines of code that execute tasks on your device, and you should be extremely skeptical of any commands or software links you find on TikTok.

“In this campaign, attackers are using TikTok videos to verbally instruct users into executing malicious commands on their own systems,” Trend Micro explained in a report on the attack. “The social engineering occurs within the video itself, rather than through detectable code or scripts. There is no malicious code present on the platform for security solutions to analyze or block. All actionable content is delivered visually and aurally. Threat actors do this to attempt to evade existing detection mechanisms, making it harder for defenders to detect and disrupt these campaigns.”

TikTok declined to comment on this particular threat, but the company confirmed to Mashable that the accounts associated with the campaign have been deactivated. TikTok users can also learn more about scams and phishing attempts at the TikTok Safety Center.



Source link

Abigail Avery

Share
Published by
Abigail Avery

Recent Posts

Ondo Finance Positions to Dominate the $16 Trillion Tokenization Market After Strategic Acquisition

Ondo Finance has acquired Oasis Pro as the RWA tokenization platform secures its place in…

42 seconds ago

European VC breaks taboo by investing in pure defense tech from Ukraine’s war zones

Defense tech has gone from a no-go zone for VCs to a hot investment sector.…

9 minutes ago

Tokenized Equities: Big Promise, Bigger Hurdles in the Race to Democratize Investing

The tokenization of equities, while seen as a promising way to democratize access to publicly…

11 minutes ago

Ethereum Is Becoming What Treasuries Are to Traditional Finance: Research

“Stablecoins are spreading the dollar faster than any financial tech in history,” said Electric Capital…

1 hour ago

Imagen Network (IMAGE) to Integrate Advanced Llama 4-Based AI for Multimodal Personalization

Integration of the latest multimodal intelligence model boosts content relevance, user targeting, and cross-format…

1 hour ago

Get a lifetime subscription to iScanner for just £29.42

TL;DR: Scan anything, anywhere, with this lifetime subscription to iScanner, now £29.42. Raise your hand…

1 hour ago