logo

Let’s Talk About TikTok

ID: 775ba5b6-e6f9-5242-a211-503f65f77a21

STIX ID: report--775ba5b6-e6f9-5242-a211-503f65f77a21

Feed Name: Black Hills Infosec Blog

Date Published: 2020-07-23

Date Updated: 2026-04-27

Author: BHIS

...
...

The report documents a passive analysis of an Android device’s baseline network activity and subsequent inspection of TikTok traffic using a Raspberry Pi AP, tcpdump/Wireshark, Burp Suite, and MobSF. Baseline DNS anomalies were investigated and largely explained (e.g., CloudFront downloads of trust stores), while TikTok’s APK (com.zhiliaoapp.musically) exhibited a large attack surface and numerous permissions; intercepted API requests showed encrypted bodies with high entropy, and broader social media apps were noted to employ certificate pinning. The author found no clear signs of malicious exfiltration during observation but flagged the app’s extensive permissions and opaque encrypted communications as risk factors, emphasizing the difficulty of definitive conclusions without deeper reverse engineering.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.