Cybersecurity & Intelligence — 2026-03-28
AiTM Phishing Campaign Targets TikTok Business Accounts, Bypasses MFA with Reverse Proxy Kit
Push Security identified a new adversary-in-the-middle phishing campaign targeting TikTok for Business accounts, with multiple domains registered within a 9-second window on March 24. The kit acts as a reverse proxy behind Cloudflare Turnstile checks, capturing credentials and session cookies in real time to bypass multi-factor authentication. Compromised TikTok Business accounts can expose connected Google accounts, enabling ad fraud, malvertising, and data theft across multiple platforms. The campaign uses bulk domain registration through Nicenic International Group.