19 C
London
Monday, September 1, 2025
HomeCAMPUS NEWSTechnologyScammers tricked TikTok users into downloading malware with AI videos

Scammers tricked TikTok users into downloading malware with AI videos

Date:

Related stories

MUBS Unveils Graduation List Ahead of 16th Graduation Ceremony

Makerere University Business School (MUBS) to Host 16th Graduation...

Gulu University appoints Ruhakana Rugunda as new Chancellor

Gulu University welcomes Dr. Ruhakana Rugunda as its new...

Metropolitan International University kicks off their 5th Graduation ceremony

Metropolitan International University (MIU) celebrates it's 5th Graduation ceremony...

Gulu University Set For 18th Graduation

Gulu University's Academic Registrar announced that the 18th Graduation Ceremony...
spot_imgspot_img

Cybercriminals are using AI-generated TikTok videos to trick users into running malware disguised as free software activations.The TikTok logo with a person holding a phone in their hand is seen in Knurow, Poland, on April 20, 2025.

Wake up, babe — a new form of social engineering just dropped.

Cybercriminals on TikTok used videos to trick users into downloading malware, according to researchers from Trend Micro, a global cybersecurity firm. The researchers say this was a “novel social engineering campaign” designed to take advantage of TikTok users.

In the videos, which are most likely AI-generated, users were promised free versions of Windows and Microsoft Office software or access to premium features in apps like CapCut and Spotify. All you have to do, the cybercriminals said, is execute a simple PowerShell command. People followed the instructions in the TikTok videos because they were being disguised as software activation steps, which the bad actors then used to inject malware like Vidar and StealC into the users’ systems. And according to Bleeping Computer, many of the videos had hundreds of thousands of views.

PowerShell commands are short lines of code that execute tasks on your device, and you should be extremely skeptical of any commands or software links you find on TikTok.

“In this campaign, attackers are using TikTok videos to verbally instruct users into executing malicious commands on their own systems,” Trend Micro explained in a report on the attack. “The social engineering occurs within the video itself, rather than through detectable code or scripts. There is no malicious code present on the platform for security solutions to analyze or block. All actionable content is delivered visually and aurally. Threat actors do this to attempt to evade existing detection mechanisms, making it harder for defenders to detect and disrupt these campaigns.”

TikTok declined to comment on this particular threat, but the company confirmed to Mashable that the accounts associated with the campaign have been deactivated. TikTok users can also learn more about scams and phishing attempts at the TikTok Safety Center.

UPDATE: May. 23, 2025, 5:22 p.m. EDT We’ve updated this article to make it more clear that the videos used in this scam have been removed.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Related stories

spot_img

LEAVE A REPLY

Please enter your comment!
Please enter your name here
Captcha verification failed!
CAPTCHA user score failed. Please contact us!

This site uses Akismet to reduce spam. Learn how your comment data is processed.