Cybercriminals are using AI-generated TikTok videos to spread Vidar and StealC malware in ClickFix attacks.
The videos trick users into executing PowerShell commands disguised as software activation steps, reaching over 500,000 views.
Malware-laden TikTok videos provide step-by-step instructions to download Vidar or StealC malware, connecting to command-and-control servers after infection.
Traditional security controls focusing on malicious code detection are less effective against social media-based malware distribution, highlighting the need for a more holistic defense approach.