Pro

joined 1 month ago
 

Extreme price swings in wholesale electricity markets and growing concerns around grid instability are opening up new markets for energy storage. Batteries are now a critical solution to drive value for both capital and consumers.

2
submitted 3 weeks ago* (last edited 3 weeks ago) by [email protected] to c/[email protected]
 

Full PDF Report.

CTM360 has discovered a widespread ongoing malicious campaign specifically aimed at TikTok Shop users across the globe. Threat actors are exploiting the official in-app e-commerce platform through a dual attack strategy that combines phishing and malware to target users. The core tactic involves a deceptive replica of TikTok Shop that tricks users into thinking theyʼre interacting with a legitimate affiliate or the real platform. We have dubbed this Tiktok Shop scam campaign as “ClickTokˮ.

The ongoing TikTok Shop scam campaign employs multiple sophisticated tactics to target different users including end users (buyers), and TikTok Shop Affiliate Program participants on the platform. The Threat actors are using fake Meta ads and AI-generated TikTok videos that mimic influencers or official brand ambassadors.

A key element of the campaign involves lookalike domains that closely mimic legitimate TikTok URLs. These domains serve two main purposes: hosting phishing pages designed to steal user credentials and distributing trojanized apps. Once installed, these trojanized apps mimic TikTokʼs interface but covertly deploy a variant of the SparkKitty Spyware, enabling deep data exfiltration from compromised devices.

Key Findings on ClickTok Scam Campaign:

  • The campaignʼs scope extends beyond TikTok Shop impersonation and includes fraudulent versions of TikTok Wholesale and TikTok Mall. Over 10,000 + impersonated websites have been identified to date, many hosted on dedicated spoofed domains.
  • TikTok shop sites have been observed using free or low-cost top-level domains such as .top, .shop, and .icu etc.
  • The threat actors distribute malicious App files through embedded download links and QR codes, with 5,000 distinct App download sites detected thus far.
  • The campaign cryptocurrency wallet as the payment method, subsequently hijacks transactions to carry out fraud and steal digital funds.
  • TikTok Shop is officially available in 17 countries, including the UK, US, Indonesia, and several in Europe and Asia; however, TikTok shop scams is rapidly increasing and spreading on a global scale, targeting users worldwide beyond these regions.
 

Online content creators spend significant time and effort building their user base through a long, often arduous process, which requires finding the right niche'' to cater to. So, what incentive is there for an established content creator known for cat memes to completely reinvent their page channel and start promoting cryptocurrency services or cover electoral news events? And, if they do, do their existing subscribers not notice? We explore this problem of \textit{repurposed channels}, whereby a channel changes its identity and contents. We first characterize a market for second-hand'' social media accounts, which recorded sales exceeding USD~1M during our 6-month observation period. By observing YouTube channels (re)sold over these 6~months, we find that a substantial number (37%) are used to disseminate potentially harmful content, often without facing any penalty. Even more surprisingly, these channels seem to gain rather than lose subscribers. To estimate the prevalence of channel repurposing ``in the wild,'' we also collect two snapshots of 1.4M quasi-randomly sampled YouTube accounts. In a 3-month period, we estimate that $\sim$0.25% channels -- collectively holding $\sim$44M subscribers -- were repurposed. We confirm that these repurposed channels share several characteristics with sold channels -- mainly, the fact that they had a significantly high presence of potentially problematic content. Across repurposed channels, we find channels that became disinformation channels, as well as channels that link to web pages with financial scams. We reason that abusing the residual trust placed on these channels is advantageous to financially- and ideologically-motivated adversaries. This phenomenon is not exclusive to YouTube and we posit that the market for cultivating organic audiences is set to grow, particularly if it remains unchallenged by mitigations, technical or otherwise.

 

Reddit.

Dilemma highlights emerging problems as AI replaces human moderators, tech expert says

 

Extreme price swings in wholesale electricity markets and growing concerns around grid instability are opening up new markets for energy storage. Batteries are now a critical solution to drive value for both capital and consumers.

view more: ‹ prev next ›