logo

TikTok videos now push infostealer malware in ClickFix attacks

ID: 1b19522f-3584-53cb-87e1-3155d4d819a6

STIX ID: report--1b19522f-3584-53cb-87e1-3155d4d819a6

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-05-23

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Trend Micro observed a TikTok-based ClickFix campaign using likely AI-generated videos that instruct viewers to run PowerShell commands which fetch and execute scripts from attacker-controlled URLs (e.g., https://allaivo.me/spotify and https://amssh.co/script.ps1). The payloads install Vidar and StealC info-stealers that can capture screenshots, credentials, credit cards, browser cookies, crypto wallets and Authy data, and establish persistence via registry keys; the campaign leverages TikTok's wide reach to amplify impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.