TikTok videos continue to push infostealers in ClickFix attacks
ID: 39d9d7b0-743e-5c1c-995a-ac7bfd6bbf66
STIX ID: report--39d9d7b0-743e-5c1c-995a-ac7bfd6bbf66
Feed Name: Bleeping Computer
Threat Score
Cybercriminals are using TikTok videos posing as activation guides for popular software to trick users into running a one-line PowerShell command (ClickFix attack). The command fetches scripts from slmgr.win which download an Aura Stealer variant and a secondary payload from Cloudflare Pages; the malware steals browser credentials, cookies, and crypto wallets and may compile and inject additional code in memory.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
