New TikTok Phishing Campaign Targets Influencer Accounts

November 16, 2021

As major social media platforms have expanded the ability of creators to monetize their content in the last few years, they and their users have increasingly found themselves the targets of malicious activity. TikTok is now no exception.

TikTok Now Impersonated Alongside Social Media Giants

An email campaign sent in two rounds on October 2, 2021, and November 1, 2021 to more than 125 individuals and businesses appeared to target large-volume TikTok accounts of all kinds and across disparate locales. Among the typical talent agencies and brand-consultant firms we would expect to see, this actor sent messages to social media production studios, influencer management firms, and content producers of all types.

Tiktok credential phishing email for account deletion

Sample email from November 2021 campaign.

From well-known digital media channels to individual actors, models, and magicians, the campaign reached out to content creators worldwide. Several emails were sent to the wrong company of the same name in the same country, and many of the email addresses used appear to have been lifted directly from social media.

Tiktok phishing email for verified badge

Sample email from October 2021 campaign.

This campaign indicates that attackers have linked TikTok with the social media giants, including Facebook and Twitter, in the impersonation game. In the original phishing email, designed to appear like a copyright violation notice from TikTok, the victim was instructed to respond to the message, lest their account be deleted in 48 hours. To learn more about how this tactic works on TikTok and the end goal, we decided to play along and engage with the actors.

Once we replied to the first phishing email, the attacker responded via email containing a shortened link titled “Confirm My Account,” which directed us to a WhatsApp chat conversation. Within the WhatsApp conversation, we were asked to verify the phone number and email address linkedin to the targeted TikTok account.

TikTok phishing email reply with WhatsApp link

Follow-up email containing a link to WhatsApp.

Next, the threat actor impersonating “TikTok officials" asked us to confirm our ownership of the account by providing the six-digit code we had received. This shows one way that attackers bypass multi-factor authentication.

Tiktok phishing attack chat on WhatsApp

WhatsApp engagement with the attacker.

Alas, this is where our engagement with this individual ended, likely when they checked our TikTok account and noticed that our audience engagement was below par. Unfortunately, we could not locate any influencers who would let us use their account for this experiment.

Why Attackers Target TikTok Users

While we were unable to identify the end goal of the campaign, past targeting of social media accounts on other platforms offers several options. Social media accounts have become increasingly valuable in recent years, creating the incentive to ransom them back to the original owners for a hefty fee. An underground economy has evolved to offer ban-as-a-service, manipulating abuse reporting mechanisms to harass and censor other users, primarily on Instagram.

Sadly, victim accounts in this scenario often end up deleted, especially for those on TikTok.

Tiktok terms of service confirming they bear no responsibility for lost accounts

TikTok Terms of Service.

Social media platforms explicitly state in their terms of service that they bear no responsibility for any data loss and advise users to store all account material externally. In most instances, data from deleted accounts is not recoverable by the platform. And so even if the ransom payment is paid, there may be no regaining access to your social media accounts—costing those who depend on it for their income to lose their entire livelihood in one swoop.


To learn more about how Abnormal stops credential phishing of all types, including those related to social media accounts, request a demo of the platform today.

Image

Prevent the Attacks That Matter Most

Get the Latest Email Security Insights

Subscribe to our newsletter to receive updates on the latest attacks and new trends in the email threat landscape.

0
Demo 2x 1

See the Abnormal Solution to the Email Security Problem

Protect your organization from the attacks that matter most with Abnormal Integrated Cloud Email Security.

Related Posts

B 10 3 22 Cobalt Terrapin Blog
Threat group Cobalt Terrapin uses sophisticated impersonation techniques with multiple steps to commit invoice fraud.
Read More
B 09 29 22 CISO Cybersecurity Awareness Month
October is here, which means Cybersecurity Awareness Month is officially in full swing! These five tips can help security leaders take full advantage of the month.
Read More
B Email Security Challenges Blog 09 26 22
Understanding common email security challenges caused by your legacy technology will help you determine the best solution to improve your security posture.
Read More
B 5 Crucial Tips
Retailers are a popular target for threat actors due to their wealth of customer data and availability of funds. Here are 5 cybersecurity tips to help retailers reduce their risk of attack.
Read More
B 3 Essential Elements
Legacy approaches to managing unwanted mail are neither practical nor scalable. Learn the 3 essential elements of modern, effective graymail management.
Read More
B Back to School
Discover how threat group Chiffon Herring leverages impersonation and spoofed email addresses to divert paychecks to mule accounts.
Read More
B 09 06 22 Rearchitecting a System Blog
We recently shared a look at how the Abnormal engineering team overhauled our Unwanted Mail service architecture to accommodate our rapid growth. Today, we’re diving into how the team migrated traffic to the new architecture—with zero downtime.
Read More
B Industry Leading CIS Os
Stay up to date on the latest cybersecurity trends, industry news, and best practices by following these 12 innovative and influential thought leaders on social media.
Read More
B Podcast Engineering 11 08 24 22
In episode 11 of Abnormal Engineering Stories, David Hagar, Director of Engineering and Abnormal Head of UK Engineering, continues his conversation with Zehan Wang, co-founder of Magic Pony.
Read More