TikTok for Business accounts targeted in new phishing campaign
ID: eb5c436d-4ccd-5bb4-bd5f-a5fba19382b3
STIX ID: report--eb5c436d-4ccd-5bb4-bd5f-a5fba19382b3
Feed Name: Bleeping Computer
Threat Score
Threat actors are conducting an active phishing campaign targeting TikTok for Business accounts by redirecting victims through legitimate Google-hosted URLs to Cloudflare-hosted phishing pages that block bots with Turnstile and present reverse-proxy login pages to capture credentials and session cookies (allowing account takeover even with 2FA); multiple malicious domains hosted in a single Google Storage bucket are listed as indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
