• News/
  • https://www.bleepingcomputer.com/news/security/ctm360-spots-malicious-fraudontok-campaign-targeting-tiktok-shop-users/

CTM360 spots Malicious ‘FraudOnTok’ Campaign Targeting TikTok Shop users

BleepingComputer
·
Sponsored by CTM360
·
Published Aug 4, 2025
·
Updated

CTM360 has discovered a new global malware campaign dubbed "FraudOnTok" that spreads the SparkKitty spyware through fake TikTok shops to steal cryptocurrency wallets and drain funds. The unique spyware trojan discovered by CTM360 is specifically engineered to exploit TikTok Shop users across the globe. Dubbed as “FraudOnTok”, this highly coordinated scam operation employs a hybrid scam model that combines phishing and malware to deceive buyers and affiliate program participants on TikTok’s growing e-commerce platform. In the FraudOnTok campaign, TikTok shops were identified embedded with SparkKitty spyware, a variant closely resembling SparkCat, previously identified by Kaspersky. Once installed, it infiltrates the user’s device, accesses the photo gallery, and extracts screenshots that may contain cryptocurrency wallet credentials. What makes FraudOnTok unique is its simultaneous use of phishing and malware tactics, significantly increasing its impact and stealth. The scam begins with the impersonation of TikTok’s commercial ecosystem, including TikTok Shop, TikTok Wholesale, and TikTok Mall. Threat actors create fake TikTok websites that closely mimic the official interface, deceiving users into thinking they’re interacting with the real platform. Victims are lured into logging in and attempting to make purchases. During the checkout process, they are instructed to pay via cryptocurrency wallets. Once payment is made, the trojanized app embedded with SparkKitty spyware, co...

Read full article

Affected Software

1 affected component
TikTok Shop
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new malware campaign called 'FraudOnTok' targeting TikTok Shop users.

2

What security implications are discussed?

The campaign spreads spyware that can steal cryptocurrency wallets and drain funds from users.

3

What products or software are affected?

The affected product is TikTok Shop which is being exploited by the FraudOnTok malware campaign.

4

Who discovered the FraudOnTok campaign?

The malware campaign was discovered by the security research firm CTM360.

5

What type of malware is associated with the FraudOnTok campaign?

The campaign utilizes a spyware trojan known as SparkKitty.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203