New Wave of AiTM Phishing Targets TikTok for Business
ID: ba58b024-2490-5c60-9eef-beb5dad07948
STIX ID: report--ba58b024-2490-5c60-9eef-beb5dad07948
Feed Name: Infosecurity Magazine (News)
Push Security identified a March 24 cluster of AiTM phishing pages hosted behind Cloudflare and registered via Nicenic International Group that use a welcome.careers*.com naming pattern to impersonate TikTok- or Google-themed content; victims are redirected (via Google Cloud Storage) to pages protected by Cloudflare Turnstile and ultimately presented with a reverse-proxy AiTM login to harvest credentials, risking simultaneous compromise of TikTok and Google accounts and potential ad manager abuse for malvertising.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
