TikTok fans beware – experts warn dangerous malware spread by AI fake videos
- Trend Micro saw a new malware campaign on TikTok
- The videos demonstrate how to activate “premium” features in different software
- The clips were AI-generated and trick the victims into downloading infostealers
Hackers are posting AI-generated videos on TikTok to trick users into downloading infostealing malware, cybersecurity researchers Trend Micro have warned.
The premise is simple: the attackers use AI to generate numerous videos demonstrating how to easily “activate” Windows and Microsoft Office, or enable “premium features” in apps such as Spotify or CapCut.
They then share these videos on TikTok, whose algorithm makes it more likely to turn the video viral, making the success of the attack more likely.
A new spin on old tricks
In the clip, a person is shown bringing up the Run program on Windows, and then executing a PowerShell command.
While in the video the command results in the activation of special features, in reality, users running the command would download a malicious script which, in turn, deploys Vidar and StealC infostealers.
These infostealers can take screenshots, steal login credentials, grab credit card data, exfiltrate cookies, cryptocurrency wallet information, 2FA codes, and more.
“This attack uses videos (possibly AI-generated) to instruct users to execute PowerShell commands, which are disguised as software activation steps. TikTok’s algorithmic reach increases the likelihood of widespread exposure, with one video reaching more than half a million views,” Trend Micro said.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“The videos are highly similar, with only minor differences in camera angles and the download URLs used by PowerShell to fetch the payload,” the researchers added.
“These suggest that the videos were likely created through automation. The instructional voice also appears AI-generated, reinforcing the likelihood that AI tools are being used to produce these videos.”
One of the videos has roughly 500,000 views, more than 20,000 likes, and more than 100 comments, making it quite successful.
Videos were being used to deliver malware in the past, too, but this new campaign is a significant departure from earlier methods.
The difference is that before, the link to the malware was shared in the video’s description, or comment, where it could still be picked up by security solutions. By delivering the bait in a video format, the attackers successfully bypass almost all security measures.
Via BleepingComputer
You might also like
Trend Micro saw a new malware campaign on TikTok The videos demonstrate how to activate “premium” features in different software The clips were AI-generated and trick the victims into downloading infostealers Hackers are posting AI-generated videos on TikTok to trick users into downloading infostealing malware, cybersecurity researchers Trend Micro have…
Recent Posts
- This chunky little tablet got my kid to clean up his toys
- OpenAI will let the US government review its AI models before release
- Seagate FireCuda X Vault review: Large capacity and decent transfer rates make this external hard drive a great solution for video and photography
- I customized a MacBook Neo with colorful spare parts
- EveryPlate Meal Kit Review (2026): Low Cost, Simplicity, Flavor
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023