Phishing Attacks Leverage TikTok, Instagram Reels
June 10, 2026, 11 a.m.
Description
Threat actors are exploiting short-form video platforms like TikTok and Instagram Reels to conduct social engineering attacks. Two distinct campaign methods have been identified: professional-looking fake tutorials with AI-generated voiceovers promising free premium software, and casual videos showcasing premium features to generate engagement through comments. Both approaches direct victims to malicious websites hosting infostealer malware, particularly Vidarstealer. The campaigns leverage platform algorithms through high engagement rates including saves, shares, and comments. Attackers use multiple accounts with Windows-themed branding and manipulate PowerShell commands to download malicious executables. These techniques are difficult to counter as creators can delete warning comments and platform reporting mechanisms prove ineffective. The attacks target non-technical users seeking free access to premium services like Spotify, Microsoft Office, and other software, making social media feeds an emerging p...
Tags
Date
- Created: June 9, 2026, 8:11 p.m.
- Published: June 9, 2026, 8:11 p.m.
- Modified: June 10, 2026, 11 a.m.
Indicators
- 03bbc4fa1fd784276da135ab62fef85aaddea66e6eb176d7e59c3398f818b153
Attack Patterns
- Vidarstealer
Additional Informations
- pluginchad.xyz
- d4ug.site
- maxapk.xyz