Cybersecurity & Intelligence — 2026-03-28

AiTM Phishing Campaign Targets TikTok Business Accounts, Bypasses MFA with Reverse Proxy Kit

Push Security identified a new adversary-in-the-middle phishing campaign targeting TikTok for Business accounts, with multiple domains registered within a 9-second window on March 24. The kit acts as a reverse proxy behind Cloudflare Turnstile checks, capturing credentials and session cookies in real time to bypass multi-factor authentication. Compromised TikTok Business accounts can expose connected Google accounts, enabling ad fraud, malvertising, and data theft across multiple platforms. The campaign uses bulk domain registration through Nicenic International Group.

2 sources
  1. Business TikTok accounts targeted with AITM phishing kits - Push Security
  2. AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion - The Hacker News

View in full brief →

UNCLASSIFIED // OPEN SOURCE