AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
ID: 60490aae-7dc4-5921-976b-5aeb02c6b525
STIX ID: report--60490aae-7dc4-5921-976b-5aeb02c6b525
Feed Name: The Hacker News
Threat actors are running active phishing campaigns that use adversary-in-the-middle pages impersonating TikTok for Business (and Google Careers lookalikes) to capture credentials via Cloudflare Turnstile and weaponize compromised business accounts for malvertising and malware distribution; separately, attackers are delivering a Go-based malware (linked to BianLian activity) via malicious SVG attachments that redirect to download hosts. The report lists multiple malicious domains used for the phishing pages and describes the techniques and overlaps with known ransomware/infostealer families.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
