logo

TikTok videos continue to push infostealers in ClickFix attacks

ID: 39d9d7b0-743e-5c1c-995a-ac7bfd6bbf66

STIX ID: report--39d9d7b0-743e-5c1c-995a-ac7bfd6bbf66

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-10-19

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

Cybercriminals are using TikTok videos posing as activation guides for popular software to trick users into running a one-line PowerShell command (ClickFix attack). The command fetches scripts from slmgr.win which download an Aura Stealer variant and a secondary payload from Cloudflare Pages; the malware steals browser credentials, cookies, and crypto wallets and may compile and inject additional code in memory.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.