Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Linux Kernel SCTP Vulnerability Lets Attackers Gain Root
August 7, 2026
Critical WordPress XSS2Shell Flaw Allows Remote Code Execution
August 7, 2026
Critical Windows Hello for Business Bug Lets Attackers Impersonate Users in Entra ID
August 7, 2026
Home/Threats/TikTok and Instagram Reels Used to Spread Malware via Fake Software Tutorials
Threats

TikTok and Instagram Reels Used to Spread Malware via Fake Software Tutorials

Key Takeaways Cybercriminals are leveraging TikTok and Instagram Reels to distribute malware through deceptive software tutorials and enticing lure videos. The primary payload is Vidarstealer, an...

Marcus Rodriguez
Marcus Rodriguez
June 10, 2026 5 Min Read
57 0

Key Takeaways

  • Cybercriminals are leveraging TikTok and Instagram Reels to distribute malware through deceptive software tutorials and enticing lure videos.
  • The primary payload is Vidarstealer, an information stealer designed to exfiltrate credentials, financial data, and session tokens.
  • Attackers exploit social media algorithms and user trust, creating seemingly legitimate content that bypasses platform moderation.
  • Social media platforms struggle to effectively counter these campaigns, making user vigilance and robust organizational defenses critical.

Cybercriminals have established a new vector for malware distribution, weaponizing short-form video platforms like TikTok and Instagram Reels. They are exploiting these popular social media channels to disseminate malicious software, primarily Vidarstealer, by luring users with fake premium software tutorials and deceptive content.

Table Of Content

  • Key Takeaways
  • Hackers Abuse TikTok and Instagram Reels
  • Why These Social Engineering Attacks Are Difficult to Stop
  • What You Should Do

This evolving threat capitalizes on the platforms’ massive reach and the inherent trust users place in digital content. Attackers craft highly polished videos that appear legitimate, promising free access to popular premium applications. These videos then subtly direct unsuspecting viewers to download malicious files, effectively transforming entertainment platforms into formidable attack surfaces.

The efficacy of this method stems from its seamless integration into typical social media feeds. The malicious videos are indistinguishable from the vast quantity of legitimate tech tips and how-to guides shared daily. Accumulating thousands of views and hundreds of likes, these deceptive posts create a false sense of credibility, which attackers exploit to great effect.

Threat intelligence researchers at ReversingLabs, led by Zaria Vuksan, have meticulously analyzed two distinct campaign methodologies. Both approaches successfully manipulate social media recommendation algorithms, enabling them to reach enormous audiences and spread malware at scale. The research underscores how threat actors skillfully leverage platform engagement mechanics to achieve widespread distribution.

Despite their differing tactics, both campaigns share a singular objective: to funnel users to third-party websites hosting malicious software, disguised as legitimate, free premium applications. The malware deployed in these attacks is Vidarstealer, a notorious information stealer available as a service. Vidarstealer is capable of exfiltrating sensitive data, including login credentials, financial information, and session tokens from infected devices.

Vidarstealer received a significant update in October of the previous year, enhancing its evasive capabilities and making it more challenging to detect. With a lifetime license priced at approximately $300, it remains a favored tool among threat actors across various campaigns. In a report shared with Cyber Security News (CSN), ReversingLabs highlighted that the combination of extensive social media reach and readily available malware tools creates a hazardous threat landscape for both individual users and organizations.

Hackers Abuse TikTok and Instagram Reels

The first observed campaign employs accounts with usernames such as “windows.tips” or “windows.insights,” often featuring a blue and white profile image designed to mimic the official Windows social media branding. These accounts publish professional-looking tutorial videos, complete with AI-generated voiceovers, instructing users to execute a specific PowerShell command. This command purportedly unlocks “Spotify Premium for free.”

However, the PowerShell command silently downloads and executes a script from a remote address. Unsuspecting users who follow these instructions unknowingly trigger the download and execution of Vidarstealer. The danger of this method is amplified by the authoritative and clean appearance of the videos, many of which garner over 100,000 views, along with thousands of saves and shares.

The second campaign adopts a more informal approach to ensnare victims. These accounts post brief, ambiguous video clips showcasing premium Spotify features, often set to trending music. They then encourage viewers to comment, piquing curiosity. Once engagement increases, the attacker responds to comments with links directing users to malicious websites, such as pluginchad[.]xyz or d4ug[.]site. These sites host fake software downloads, frequently hidden behind survey walls.

Why These Social Engineering Attacks Are Difficult to Stop

A significant challenge in combating this threat lies in the limited capabilities of social media platforms to effectively detect and mitigate such attacks. ReversingLabs researchers reported that their attempts to flag malicious Instagram accounts as scams were consistently rejected. Even when content is eventually flagged, platform responses are often slow, allowing significant damage to occur before an account is removed.

Furthermore, attackers effectively suppress community warnings. If a user posts a comment alerting others to the scam, the attacker promptly deletes the comment and blocks the user. This dynamic severely hinders genuine self-policing efforts, shifting the primary burden of defense onto organizations and individual users.

What You Should Do

  • Verify Sources: Always question offers for free premium software. Download applications only from official app stores or trusted vendor websites.
  • Inspect URLs: Before clicking any link, carefully examine the URL for suspicious spellings or unusual domains.
  • Enable Multi-Factor Authentication (MFA): Protect your social media and other online accounts with MFA to prevent unauthorized access even if credentials are stolen.
  • Exercise Caution with PowerShell Commands: Never execute PowerShell commands or any scripts provided by unverified sources, especially those promising free software or system “enhancements.”
  • Report Suspicious Accounts: Consistently report any accounts or content that appears to be a scam or is distributing malware to the respective social media platform. Higher report volumes can increase the likelihood of platform action.
  • Implement Endpoint Protection: Ensure all devices have up-to-date antivirus and anti-malware software with real-time protection enabled.
  • Conduct Regular Security Awareness Training: For organizations, regularly update phishing and social engineering awareness training to include social media as a significant attack vector.
  • Restrict Installation Permissions: Organizations should audit and restrict software installation permissions on company devices to prevent unauthorized software from being installed.

Indicators of Compromise (IoCs):-

Type Indicator Description
Hash 03bbc4fa1fd784276da135ab62fef85aaddea66e6eb176d7e59c3398f818b153 SHA-256 hash of build.exe, identified as Vidarstealer
Domain pluginchad[.]xyz Malicious site hosting fake free software downloads
Domain maxapk[.]xyz Malicious site hosting fake free software downloads
Domain d4ug[.]site Fake site claiming to “Unlock premium games and AI tools”
Domain slmgr[.]sh Domain used in malicious PowerShell command delivery
Domain msget[.]run Domain used to deliver Vidarstealer via iex irm command
Account tiktok[.]com/@windows.tips1 Malicious TikTok account used in tutorial campaign
Account tiktok[.]com/@windows.insight Malicious TikTok account used in tutorial campaign
Account tiktok[.]com/@davidcooksey47 Malicious TikTok account associated with campaign
Account tiktok[.]com/@tracyhughe Malicious TikTok account associated with campaign
Account tiktok[.]com/@mr.capcut.pro2 Malicious TikTok account associated with campaign
Account instagram[.]com/wtips404 Malicious Instagram account used in campaign
Account instagram[.]com/wndwstips Malicious Instagram account used in campaign
Account instagram[.]com/epemberton369 Malicious Instagram account used in campaign

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitHackerMalwarephishingSecurityThreat

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical Multi-Stage ClickFix Flaw Lets Attackers Deploy MLTBackdoor Malware

Next Post

Critical Microsoft Vulnerability: 73 Packages Deploy Password Stealers

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
August 7, 2026
Critical SharePoint Vulnerability Let Hackers Breach Swiss Government
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us