Threats Tagged 'aurostealer'
View all threats tagged with 'aurostealer'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'aurostealer'
Click on any threat for detailed analysis and mitigation recommendations
Attackers are leveraging TikTok videos to distribute malware by masquerading as free software activations. The campaign uses social engineering to convince users to run malicious PowerShell scripts that download additional payloads, including the AuroStealer information stealer. Persistence is established via scheduled tasks, and one payload uses a self-compiling technique to inject shellcode directly into memory, evading detection. Multiple TikTok videos target various software products, employing the ClickFix technique to increase user trust. This threat exploits user interaction and social engineering on a popular platform, posing a medium risk due to its potential to compromise confidentiality and integrity. European organizations with users active on TikTok and those using targeted software products are at risk. Mitigations include user education, PowerShell execution restrictions, monitoring scheduled tasks, and blocking malicious domains. Countries with high TikTok usage and significant software user bases, such as Germany, France, and the UK, are more likely to be affected. Join the discussion | AlienVault OTX General | 10/21/2025, 15:38:59 UTC Added: 10/21/2025, 16:20:28 UTC |
Showing 1 to 1 of 1 result