TikTok and Instagram Reels Used to Spread Malware via Fake Software Tutorials
Key Takeaways Cybercriminals are leveraging TikTok and Instagram Reels to distribute malware through deceptive software tutorials and enticing lure videos. The primary payload is Vidarstealer, an...
Key Takeaways
- Cybercriminals are leveraging TikTok and Instagram Reels to distribute malware through deceptive software tutorials and enticing lure videos.
- The primary payload is Vidarstealer, an information stealer designed to exfiltrate credentials, financial data, and session tokens.
- Attackers exploit social media algorithms and user trust, creating seemingly legitimate content that bypasses platform moderation.
- Social media platforms struggle to effectively counter these campaigns, making user vigilance and robust organizational defenses critical.
Cybercriminals have established a new vector for malware distribution, weaponizing short-form video platforms like TikTok and Instagram Reels. They are exploiting these popular social media channels to disseminate malicious software, primarily Vidarstealer, by luring users with fake premium software tutorials and deceptive content.
Table Of Content
This evolving threat capitalizes on the platforms’ massive reach and the inherent trust users place in digital content. Attackers craft highly polished videos that appear legitimate, promising free access to popular premium applications. These videos then subtly direct unsuspecting viewers to download malicious files, effectively transforming entertainment platforms into formidable attack surfaces.
The efficacy of this method stems from its seamless integration into typical social media feeds. The malicious videos are indistinguishable from the vast quantity of legitimate tech tips and how-to guides shared daily. Accumulating thousands of views and hundreds of likes, these deceptive posts create a false sense of credibility, which attackers exploit to great effect.
Threat intelligence researchers at ReversingLabs, led by Zaria Vuksan, have meticulously analyzed two distinct campaign methodologies. Both approaches successfully manipulate social media recommendation algorithms, enabling them to reach enormous audiences and spread malware at scale. The research underscores how threat actors skillfully leverage platform engagement mechanics to achieve widespread distribution.
Despite their differing tactics, both campaigns share a singular objective: to funnel users to third-party websites hosting malicious software, disguised as legitimate, free premium applications. The malware deployed in these attacks is Vidarstealer, a notorious information stealer available as a service. Vidarstealer is capable of exfiltrating sensitive data, including login credentials, financial information, and session tokens from infected devices.
Vidarstealer received a significant update in October of the previous year, enhancing its evasive capabilities and making it more challenging to detect. With a lifetime license priced at approximately $300, it remains a favored tool among threat actors across various campaigns. In a report shared with Cyber Security News (CSN), ReversingLabs highlighted that the combination of extensive social media reach and readily available malware tools creates a hazardous threat landscape for both individual users and organizations.
Hackers Abuse TikTok and Instagram Reels
The first observed campaign employs accounts with usernames such as “windows.tips” or “windows.insights,” often featuring a blue and white profile image designed to mimic the official Windows social media branding. These accounts publish professional-looking tutorial videos, complete with AI-generated voiceovers, instructing users to execute a specific PowerShell command. This command purportedly unlocks “Spotify Premium for free.”
However, the PowerShell command silently downloads and executes a script from a remote address. Unsuspecting users who follow these instructions unknowingly trigger the download and execution of Vidarstealer. The danger of this method is amplified by the authoritative and clean appearance of the videos, many of which garner over 100,000 views, along with thousands of saves and shares.
The second campaign adopts a more informal approach to ensnare victims. These accounts post brief, ambiguous video clips showcasing premium Spotify features, often set to trending music. They then encourage viewers to comment, piquing curiosity. Once engagement increases, the attacker responds to comments with links directing users to malicious websites, such as pluginchad[.]xyz or d4ug[.]site. These sites host fake software downloads, frequently hidden behind survey walls.
Why These Social Engineering Attacks Are Difficult to Stop
A significant challenge in combating this threat lies in the limited capabilities of social media platforms to effectively detect and mitigate such attacks. ReversingLabs researchers reported that their attempts to flag malicious Instagram accounts as scams were consistently rejected. Even when content is eventually flagged, platform responses are often slow, allowing significant damage to occur before an account is removed.
Furthermore, attackers effectively suppress community warnings. If a user posts a comment alerting others to the scam, the attacker promptly deletes the comment and blocks the user. This dynamic severely hinders genuine self-policing efforts, shifting the primary burden of defense onto organizations and individual users.
What You Should Do
- Verify Sources: Always question offers for free premium software. Download applications only from official app stores or trusted vendor websites.
- Inspect URLs: Before clicking any link, carefully examine the URL for suspicious spellings or unusual domains.
- Enable Multi-Factor Authentication (MFA): Protect your social media and other online accounts with MFA to prevent unauthorized access even if credentials are stolen.
- Exercise Caution with PowerShell Commands: Never execute PowerShell commands or any scripts provided by unverified sources, especially those promising free software or system “enhancements.”
- Report Suspicious Accounts: Consistently report any accounts or content that appears to be a scam or is distributing malware to the respective social media platform. Higher report volumes can increase the likelihood of platform action.
- Implement Endpoint Protection: Ensure all devices have up-to-date antivirus and anti-malware software with real-time protection enabled.
- Conduct Regular Security Awareness Training: For organizations, regularly update phishing and social engineering awareness training to include social media as a significant attack vector.
- Restrict Installation Permissions: Organizations should audit and restrict software installation permissions on company devices to prevent unauthorized software from being installed.
Indicators of Compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Hash | 03bbc4fa1fd784276da135ab62fef85aaddea66e6eb176d7e59c3398f818b153 | SHA-256 hash of build.exe, identified as Vidarstealer |
| Domain | pluginchad[.]xyz | Malicious site hosting fake free software downloads |
| Domain | maxapk[.]xyz | Malicious site hosting fake free software downloads |
| Domain | d4ug[.]site | Fake site claiming to “Unlock premium games and AI tools” |
| Domain | slmgr[.]sh | Domain used in malicious PowerShell command delivery |
| Domain | msget[.]run | Domain used to deliver Vidarstealer via iex irm command |
| Account | tiktok[.]com/@windows.tips1 | Malicious TikTok account used in tutorial campaign |
| Account | tiktok[.]com/@windows.insight | Malicious TikTok account used in tutorial campaign |
| Account | tiktok[.]com/@davidcooksey47 | Malicious TikTok account associated with campaign |
| Account | tiktok[.]com/@tracyhughe | Malicious TikTok account associated with campaign |
| Account | tiktok[.]com/@mr.capcut.pro2 | Malicious TikTok account associated with campaign |
| Account | instagram[.]com/wtips404 | Malicious Instagram account used in campaign |
| Account | instagram[.]com/wndwstips | Malicious Instagram account used in campaign |
| Account | instagram[.]com/epemberton369 | Malicious Instagram account used in campaign |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.