Mashable 05月24日 01:09
AI videos on TikTok are tricking users into downloading malware
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

网络安全公司Trend Micro的研究人员发现,TikTok上出现了新型社会工程攻击,网络犯罪分子利用视频诱骗用户下载恶意软件。这些视频通常承诺提供免费的Windows、Microsoft Office软件或CapCut、Spotify等应用的付费功能,诱导用户执行PowerShell命令。这些命令实际上是恶意软件的植入步骤,如Vidar和StealC,会危害用户的系统。尽管TikTok已删除相关账号,但这种新型攻击方式对用户构成了严重威胁。

📢 网络犯罪分子在TikTok上发布视频,承诺免费软件或应用高级功能,诱导用户执行PowerShell命令。

💻 这些PowerShell命令被伪装成软件激活步骤,实际用于植入恶意软件,如Vidar和StealC,从而危害用户系统。

👁️‍🗨️ 攻击者通过视频口头指示用户执行恶意命令,试图规避现有的检测机制,使得安全防护更难发现和阻止此类攻击。

⚠️ 视频内容通常是AI生成的,欺骗性强,许多视频已获得数十万次观看,可见其传播范围之广。

Wake up, babe — a new form of social engineering just dropped.

Cybercriminals on TikTok are using videos to trick users into downloading malware, according to researchers from Trend Micro, a global cybersecurity firm. The researchers say this is a "novel social engineering campaign" designed to take advantage of TikTok users.

In the videos, which are most likely AI-generated, users are promised free versions of Windows and Microsoft Office software or access to premium features in apps like CapCut and Spotify. All you have to do, the cybercriminals say, is execute a simple PowerShell command. People are following the instructions in the TikTok videos because they're being disguised as software activation steps, which the bad actors then use to inject malware like Vidar and StealC into the users' systems. And according to Bleeping Computer, many of the videos have hundreds of thousands of views.

PowerShell commands are short lines of code that execute tasks on your device, and you should be extremely skeptical of any commands or software links you find on TikTok.

"In this campaign, attackers are using TikTok videos to verbally instruct users into executing malicious commands on their own systems," Trend Micro explained in a report on the attack. "The social engineering occurs within the video itself, rather than through detectable code or scripts. There is no malicious code present on the platform for security solutions to analyze or block. All actionable content is delivered visually and aurally. Threat actors do this to attempt to evade existing detection mechanisms, making it harder for defenders to detect and disrupt these campaigns."

TikTok declined to comment on this particular threat, but the company confirmed to Mashable that the accounts associated with the campaign have been deactivated. TikTok users can also learn more about scams and phishing attempts at the TikTok Safety Center.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

TikTok 恶意软件 社会工程 网络安全
相关文章