Cybercriminals are using TikTok and Instagram Reels to distribute Vidar malware by tricking users into running malicious command-line scripts that promise free access to popular software subscriptions.
Key Points
- Threat actors are promoting fake "free" subscriptions for Spotify, Microsoft Office, and Adobe to lure victims on short-form video platforms.
- Victims are instructed to open PowerShell and execute malicious commands, which download the Vidar infostealer onto their computers.
- The Vidar malware harvests sensitive data, including passwords, browser cookies, cryptocurrency wallet information, and personal documents.
- This campaign represents a shift from traditional email phishing toward social engineering tactics that require users to manually execute malicious code.
- Security experts recommend using multi-factor authentication and downloading software exclusively from official vendor websites to prevent infection.