logo

Detailed Analysis of TikTok Spyware

ID: 2e2ac10e-d44e-53ba-9868-3a672fb8c025

STIX ID: report--2e2ac10e-d44e-53ba-9868-3a672fb8c025

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** This report analyzes an Android spyware sample masquerading as "TikTok Pro" (hash 9fed52ee7312e217bd10d6a156c8b988, package com.example.dat.a8andoserverx) distributed via SMS/WhatsApp links; the malware hides its icon, auto-starts at boot, persists via broadcast receivers, records calls and SMS, captures photos/audio/screenshots, tracks location, performs Facebook credential phishing, and exfiltrates data to a dynamic-DNS C2; 280 similar apps were observed and multiple C2 commands and filesystem indicators are documented.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.