Overview
Threat actors are using adversary-in-the-middle (AitM) phishing pages to seize control of TikTok for Business accounts in a new campaign, according to a report from Push Security. Business accounts associated with social media platforms are a lucrative target, as they can be weaponized by bad actors for malvertising and distributing malware. "TikTok has been historically abused to distribute
Organisations Involved
The following organisations are mentioned in relation to this incident: Cloudflare, Phishing Targets, Push Security.
Multi-Source Coverage
This event has been reported across multiple outlets:
- AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion — thehackernews
- TikTok for Business accounts targeted in new phishing campaign — bleepingcomputer
Sources: bleepingcomputer, thehackernews. Aggregated by Cybernews Agency pipeline.