TikTok for Business accounts targeted in new phishing campaign
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。用户给的文章是关于TikTok Business账户被钓鱼攻击的情况。首先,我得通读全文,抓住主要信息。 文章提到威胁者利用TikTok Business账户进行钓鱼攻击,目的是绕过安全机器人分析恶意页面。这些账户常被用于恶意广告和欺诈活动。攻击者使用Cloudflare托管的钓鱼页面,并通过NiceNIC注册域名,这个 registrar 常被用于网络犯罪。 钓鱼页面模仿TikTok和Google的登录界面,诱骗用户提供基本信息和凭证。即使启用了双重认证,攻击者也能劫持账户。文章还建议用户提高警惕,检查链接和域名,并使用安全密钥保护账户。 接下来,我需要将这些信息浓缩到100字以内。要涵盖攻击目标、方法、技术手段以及防范建议。确保语言简洁明了,不使用复杂的术语。 最后,检查字数是否符合要求,并确保所有关键点都被涵盖。这样用户就能快速了解文章的主要内容。 </think> 威胁者针对TikTok Business账户发起钓鱼攻击,利用恶意页面绕过安全机器人分析。这些账户常被用于恶意广告和欺诈活动。攻击者通过Cloudflare托管的钓鱼页面诱导用户输入信息并窃取凭证,甚至绕过双重认证保护。用户需警惕可疑链接并检查域名以确保安全。 2026-3-26 14:16:13 Author: www.bleepingcomputer.com(查看原文) 阅读量:2 收藏

TikTok for Business accounts targeted in new phishing campaign

Threat actors are targeting TikTok for Business accounts in a phishing campaign that prevents security bots from analyzing malicious pages.

TikTok Business accounts may be targeted due to their high potential for abuse in malvertising campaigns, ad fraud, and the distribution of malicious content.

Browser threat detection and response company Push Security links the campaign to one documented last year, which targeted Google Ad Manager accounts.

TikTok has previously been used to spread information-stealing malware via malicious videos, as well as cryptocurrency scams via fake promotions. TikTok for Business accounts are ideal for such purposes due to their increased reach and perceived legitimacy.

In a report shared with BleepingComputer, Push Security says that victims are lured to Cloudflare-hosted phishing pages registered on March 24 via NiceNIC, a registrar often reported by cybersecurity researcher for being used for cybercriminal activities.

Push Security could not determine the initial delivery mechanism, but believes that the threat actor uses a similar method as observed in activity reported by Sublime Security.

The initial link redirects via a legitimate Google Storage URL, blocks bots using a Cloudflare Turnstile check, and then redirects to the malicious pages.

The domains feature similar names, and are all hosted on the same Google Storage bucket:

  • welcome.careerscrews[.]com
  • welcome.careerstaffer[.]com
  • welcome.careersworkflow[.]com
  • welcome.careerstransform[.]com
  • welcome.careersupskill[.]com
  • welcome.careerssuccess[.]com
  • welcome.careersstaffgrid[.]com
  • welcome.careersprogress[.]com
  • welcome.careersgrower[.]com
  • welcome.careersengage[.]com
  • welcome.careerscrews[.]com

The malicious pages impersonate TikTok for Business and Google Careers “Schedule a Call” pages, requesting visitors to enter basic information in a form to validate they’re using a business email address.

Collecting basic information in a first validation step
Collecting basic information in a first validation step
Source: Push Security

After this step, victims are served a fake login page, which is a reverse proxy designed to capture credentials and session cookies, and to exfiltrate them to the attacker.

Since the page acts as an intermediary between the legitimate user and the service, the threat actor can hijack accounts even when the two-factor authentication (2FA) protection is active.

The TikTok themed (top) and Google (bottom) phishing pages
The TikTok themed (top) and Google (bottom) phishing pages
Source: Push Security

Push Security also notes that business account holders often log into TikTok via Google single sign-on (SSO) service. "This means that anyone using Google to login to their TikTok account will effectively have both accounts used to distribute ads compromised in one go."

Users should be extremely cautious with suspicious invites and job offers, and never trust links sent from unknown contacts. Always check the domain before entering credentials, and use passkeys to protect valuable accounts.

tines

Red Report 2026: Why Ransomware Encryption Dropped 38%

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.


文章来源: https://www.bleepingcomputer.com/news/security/tiktok-for-business-accounts-targeted-in-new-phishing-campaign/
如有侵权请联系:admin#unsafe.sh