{"id":230256,"date":"2026-03-27T08:03:00","date_gmt":"2026-03-27T12:03:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/03\/27\/aitm-phishing-targets-tiktok-business-accounts-using-cloudflare-turnstile-evasion\/"},"modified":"2026-04-02T01:10:16","modified_gmt":"2026-04-02T05:10:16","slug":"aitm-phishing-targets-tiktok-business-accounts-using-cloudflare-turnstile-evasion","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/03\/27\/aitm-phishing-targets-tiktok-business-accounts-using-cloudflare-turnstile-evasion\/","title":{"rendered":"AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/aitm-phishing-targets-tiktok-business.html\">AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/aitm-phishing-targets-tiktok-business.html\">https:\/\/thehackernews.com\/2026\/03\/aitm-phishing-targets-tiktok-business.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-03-27 08:03:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Mar 27, 2026<\/span><\/span><span class=\"p-tags\">Ransomware \/ Malware<\/span><\/p>\n<p>Threat actors are using adversary-in-the-middle (AitM) phishing pages to seize control of TikTok for Business accounts in a new campaign, according to a report from Push Security.<\/p>\n<p>Business accounts associated with social media platforms are a lucrative target, as they can be weaponized by bad actors for malvertising and distributing malware.<\/p>\n<p>&#8220;TikTok has been historically abused to distribute malicious links and social engineering instructions,&#8221; Push Security said. &#8220;This includes multiple infostealers like Vidar, StealC, and Aura Stealer delivered via ClickFix-style instructions with AI-generated videos posed as activation guides for Windows, Spotify, and CapCut.&#8221;<\/p>\n<p>The campaign begins with tricking victims into clicking on a malicious link that directs them to either a lookalike page impersonating TikTok for Business or a page that&#8217;s designed to impersonate Google Careers, along with an option to schedule a call to discuss the opportunity.<\/p>\n<p>It&#8217;s worth noting that a prior iteration of this credential phishing campaign was flagged by Sublime Security in October 2025, with emails masquerading as outreach messages used as a social engineering tactic.<\/p>\n<p>Regardless of the type of page served, the end goal is the same: perform a Cloudflare Turnstile check to block bots and automated scanners from analyzing the contents of the page and serve a malicious AitM phishing page login page that&#8217;s designed to steal their credentials.<\/p>\n<p><img decoding=\"async\" alt=\"\" border=\"0\" data-original-height=\"954\" data-original-width=\"1802\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj2y_7VDGoJkbMTXJPYUne7q0TPXAUPBRaahyphenhyphenp_SfI0lpfBNlAqBw3y4MlD77YlA3Gbzpue6y3z8fjoRJ0aoOsaC44oBpz6w4tMgVfmYXL4ZGyqjDe7kD0TVJEwCGW3MXY23R_L3zoLTMTTXbF323BLjp1UyjlKoNUvSrVyxVSZgdqoNkwZDwIHzR4FmQjk\/s1600\/timeline.png\"\/><\/p>\n<p>The phishing pages are hosted on the following domains &#8211;<\/p>\n<ul>\n<li>welcome.careerscrews[.]com<\/li>\n<li>welcome.careerstaffer[.]com<\/li>\n<li>welcome.careersworkflow[.]com<\/li>\n<li>welcome.careerstransform[.]com<\/li>\n<li>welcome.careersupskill[.]com<\/li>\n<li>welcome.careerssuccess[.]com<\/li>\n<li>welcome.careersstaffgrid[.]com<\/li>\n<li>welcome.careersprogress[.]com<\/li>\n<li>welcome.careersgrower[.]com<\/li>\n<li>welcome.careersengage[.]com<\/li>\n<li>welcome.careerscrews[.]com<\/li>\n<\/ul>\n<p>The development comes as another phishing campaign has been observed using Scalable Vector Graphics (SVG) file attachments&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/03\/aitm-phishing-targets-tiktok-business.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion https:\/\/thehackernews.com\/2026\/03\/aitm-phishing-targets-tiktok-business.html Publish Date: 2026-03-27 08:03:00&#8230;<\/p>\n","protected":false},"author":1,"featured_media":230257,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg9MSv7TxvzRXdcpb_tW0hSC0Jq5_7-VYEhbddL8im1K25nOcjSr0T3_Y2f9zG8Q9l7K3U_zOXBKWgnHAO9rWvYG9158OKLKcZif_lq7e5fpqwxrW3IdPWzgTko6ogQSQg77hmiWszgf3OOT7baBY8vI8XcPt0h8R_0p7oBX2WmVQUSgsJXfPQmCzOGTMX9\/s1600\/tiktok-b.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[26,32,25],"class_list":["post-230256","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-ai","tag-malware","tag-phishing"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/230256"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=230256"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/230256\/revisions"}],"predecessor-version":[{"id":230258,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/230256\/revisions\/230258"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/230257"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=230256"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=230256"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=230256"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}