Threats · 172 days ago
Cloudflare-hosted AiTM phishing pages impersonate TikTok for Business and Google sign-in flows. Pages block security bots, capture credentials for account takeover, and enable ad fraud and malvertising. Push Security links the cluster to bulk-registered NiceNIC domains created March 24 and notes Google Storage redirects and Cloudflare Turnstile protections.
2 sources covering this story
New Wave of AiTM Phishing Targets TikTok for Business
Push Security has uncovered a new AiTM phishing campaign targeting TikTok for Business accounts using Google and TikTok themed login pages
TikTok for Business accounts targeted in new phishing campaign
Threat actors are targeting TikTok for Business accounts in a phishing campaign that prevents security bots from analyzing malicious pages.
Part of the PlainSec briefing for 2026-03-27