logo

New Wave of AiTM Phishing Targets TikTok for Business

ID: ba58b024-2490-5c60-9eef-beb5dad07948

STIX ID: report--ba58b024-2490-5c60-9eef-beb5dad07948

Feed Name: Infosecurity Magazine (News)

Threat Score
65/100

Date Published: 2026-03-27

Date Updated: 2026-04-22

...
...

Push Security identified a March 24 cluster of AiTM phishing pages hosted behind Cloudflare and registered via Nicenic International Group that use a welcome.careers*.com naming pattern to impersonate TikTok- or Google-themed content; victims are redirected (via Google Cloud Storage) to pages protected by Cloudflare Turnstile and ultimately presented with a reverse-proxy AiTM login to harvest credentials, risking simultaneous compromise of TikTok and Google accounts and potential ad manager abuse for malvertising.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.