AI-Powered Scam Campaign Targets TikTok Shop Users with Fake Domains and Malware

3 Sources

Share

A widespread cybercrime operation is exploiting TikTok Shop's popularity using AI-generated content and fake domains to steal cryptocurrency and distribute malware.

Sophisticated Scam Operation Targets TikTok Shop Users

Cybersecurity researchers have uncovered a widespread malicious campaign, codenamed "ClickTok," targeting TikTok Shop users globally. The operation, discovered by Bahrain-based cybersecurity firm CTM360, exploits the popularity and trust in TikTok's e-commerce platform to steal cryptocurrency and distribute malware

1

.

Source: Tom's Guide

Source: Tom's Guide

AI-Powered Deception and Fake Domains

The scammers have deployed a multi-pronged strategy that includes:

  1. Creating over 15,000 fake domains resembling legitimate TikTok URLs
  2. Utilizing AI-generated videos to mimic influencers and brand ambassadors
  3. Circulating fake ads on Facebook and TikTok promising significant discounts

These tactics are designed to trick users into believing they are interacting with genuine TikTok Shop sellers or affiliates

2

.

Malware Distribution and Cryptocurrency Theft

The scam operates through several methods:

  1. Phishing pages that steal user credentials
  2. Distribution of trojanized apps containing SparkKitty malware
  3. Fraudulent storefronts encouraging cryptocurrency deposits

SparkKitty, a cross-platform malware, can harvest data from both Android and iOS devices. It employs sophisticated techniques such as device fingerprinting and optical character recognition to analyze screenshots for cryptocurrency wallet seed phrases

2

.

Source: The Hacker News

Source: The Hacker News

Monetization Strategies

The cybercriminals employ various tactics to generate illicit gains:

  1. Deceiving buyers with bogus discounted products and requesting cryptocurrency payments
  2. Convincing affiliate participants to "top up" fake on-site wallets with promises of future payouts
  3. Stealing user credentials through fake TikTok Shop login pages

Protective Measures for Users

To avoid falling victim to these scams, experts recommend the following precautions:

  1. Be skeptical of deals that seem too good to be true
  2. Double-check URLs for any suspicious elements
  3. Be wary of pressure tactics or urgency in online deals
  4. Avoid non-traditional payment methods like gift cards or cryptocurrency for unfamiliar platforms
  5. Use reputable antivirus software with online shopping protection features

    3

Broader Implications and Regulatory Response

The rise of such sophisticated scams has caught the attention of regulatory bodies. The U.S. Department of the Treasury's Financial Crimes Enforcement Network (FinCEN) has issued an advisory urging financial institutions to be vigilant in identifying and reporting suspicious activities involving convertible virtual currency (CVC) kiosks

2

.

As cybercriminals continue to exploit innovative technologies and popular platforms, the need for enhanced cybersecurity measures and user awareness becomes increasingly critical in safeguarding the digital asset ecosystem.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo