• News/
  • https://www.zdnet.com/article/if-a-tiktok-tech-tip-tells-you-to-paste-code-its-a-scam-heres-whats-really-happening/

If a TikTok 'tech tip' tells you to paste code, it's a scam. Here's what's really happening

ZDNet
·
Charlie Osborne
·
Published Oct 22, 2025
·
Updated

Follow ZDNET: Add us as a preferred source on Google. TikTok is being exploited as a delivery platform to spread information-stealing malware and other payloads, with free software acting as the bait. On October 17, Senior ISC Handler Xavier Mertens said in a post published on the SANS Institute's Internet Storm Center website that the wave of attacks on TikTok leverages ClickFix social engineering techniques to dupe victims into downloading malware onto their systems. Also: This new cyberattack tricks you into hacking yourself. Here's how to spot it In the example video posted by Mertens, a scammer has posted content -- with over 500 likes -- which pretends to provide watchers with an easy way to activate Photoshop for free. The victim is asked to start PowerShell as an administrator and trigger one line of code, which then executes "Updater.exe," which is actually AuroStealer, a Trojan designed to steal credentials and system information. An additional shellcode is also launched in memory. ZDNET explored TikTok for similar videos and it was surprising how many were live. For example, in the screenshot below, the author was promoting a fake way to download and install Adobe Photoshop without the need for a license. Other examples we found included fake, free ways to license Microsoft Windows. Clickfix is a particularly nasty social engineering technique that tries to bypass traditional anti-phishing protections by tricking users into "hacking" themselves. Also: Best VPN serv...

Read full article

Affected Software

2 affected components
Unknown AuroStealer
Microsoft PowerShell
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a scam involving TikTok that encourages users to paste code, which leads to malware being installed.

2

What type of malware is being spread through TikTok?

Information-stealing malware, specifically the AuroStealer, is being distributed through this scam.

3

How are users being lured into this scam?

Users are attracted to the scam through free software promotions that instruct them to paste malicious code.

4

What software is mentioned as being exploited in this scam?

Microsoft PowerShell and the AuroStealer malware are mentioned as being exploited in the scam.

5

What security implications are highlighted in relation to the TikTok scam?

The security implications include the risk of identity theft and loss of sensitive information due to the malware being distributed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203