• News/
  • https://www.bleepingcomputer.com/news/security/ctm360-spots-malicious-clicktok-campaign-targeting-tiktok-shop-users/

CTM360 spots Malicious ‘ClickTok’ Campaign Targeting TikTok Shop users

BleepingComputer
·
Sponsored by CTM360
·
Published Aug 4, 2025
·
Updated

CTM360 has discovered a new global malware campaign dubbed "ClickTok" that spreads the SparkKitty spyware through fake TikTok shops to steal cryptocurrency wallets and drain funds. The unique unique spyware trojan discovered by CTM360 is specifically engineered to exploit TikTok Shop users across the globe. Dubbed as “ClickTok”, this highly coordinated scam operation employs a hybrid scam model that combines phishing and malware to deceive buyers and affiliate program participants on TikTok’s growing e-commerce platform. In the ClickTok campaign, TikTok shops were identified embedded with SparkKitty spyware, a variant closely resembling SparkCat, previously identified by Kaspersky. Once installed, it infiltrates the user’s device, accesses the photo gallery, and extracts screenshots that may contain cryptocurrency wallet credentials. What makes ClickTok unique is its simultaneous use of phishing and malware tactics, significantly increasing its impact and stealth. The scam begins with the impersonation of TikTok’s commercial ecosystem, including TikTok Shop, TikTok Wholesale, and TikTok Mall. Threat actors create fake TikTok websites that closely mimic the official interface, deceiving users into thinking they’re interacting with the real platform. Victims are lured into logging in and attempting to make purchases. During the checkout process, they are instructed to pay via cryptocurrency wallets. Once payment is made, the trojanized app embedded with SparkKitty spyware, cov...

Read full article

Affected Software

1 affected component
TikTok Shop
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a global malware campaign called 'ClickTok' targeting TikTok Shop users to spread spyware.

2

What security implications are discussed in this campaign?

The campaign involves stealing cryptocurrency wallet information and draining user funds through malicious tactics.

3

What products or software are affected by the ClickTok campaign?

The affected software is TikTok Shop, which is targeted through fake shopping sites.

4

How does the ClickTok campaign operate?

The ClickTok campaign spreads SparkKitty spyware through counterfeit TikTok shops.

5

Who discovered the ClickTok malware campaign?

The campaign was discovered by CTM360, a cybersecurity research firm.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203