TikTok and Malware
ID: 281825ff-7e38-59f0-8be5-1252080f9158
STIX ID: report--281825ff-7e38-59f0-8be5-1252080f9158
Feed Name: Censys Blog
Date Published: 2025-05-27
Date Updated: 2026-04-27
Author: Jean Pierre Ruiz Ocampo; Mark Ellzey; Senior Security Researcher
This report details an active info-stealer campaign leveraging AI-generated TikTok tutorial videos to trick viewers into running PowerShell commands that fetch malware (Vidar, StealC and a Lumma Stealer sample). Censys and historical DNS analysis link domains (amssh.co, allaivo.me, winbox.ws) and IPs (notably 91.92.46.76, 91.92.46.219, 91.92.46.70) to hosted PowerShell payloads and a Lumma binary that contacts a confirmed C2; it also highlights use of a likely bulletproof hosting ASN (AS214196) and updates TrendMicro's IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
