Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Why developers using AI are working longer hours

    Put the zipcode first

    Caitlin Kalinowski: I resigned from OpenAI

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      What the polls say about how Americans are using AI

      February 27, 2026

      Tensions between the Pentagon and AI giant Anthropic reach a boiling point

      February 21, 2026

      Read the extended transcript: President Donald Trump interviewed by ‘NBC Nightly News’ anchor Tom Llamas

      February 6, 2026

      Stocks and bitcoin sink as investors dump software company shares

      February 4, 2026

      AI, crypto and Trump super PACs stash millions to spend on the midterms

      February 2, 2026
    • Business

      Google PM open-sources Always On Memory Agent, ditching vector databases for LLM-driven persistent memory

      March 8, 2026

      Regulate AWS and Microsoft, says UK cloud provider survey

      March 8, 2026

      Google releases Gemini 3.1 Flash Lite at 1/8th the cost of Pro

      March 4, 2026

      Huawei Watch GT Series

      March 4, 2026

      Weighing up the enterprise risks of neocloud providers

      March 3, 2026
    • Crypto

      Banks Respond to Kraken’s Federal Reserve Access as Trump Sides with Crypto

      March 4, 2026

      Hyperliquid and DEXs Break the Top 10 — Is the CEX Era Ending?

      March 4, 2026

      Consensus Hong Kong 2026: The Institutional Turn 

      March 4, 2026

      New Crypto Mutuum Finance (MUTM) Reports V1 Protocol Progress as Roadmap Enters Phase 3

      March 4, 2026

      Bitcoin Short Sellers Caught Off Guard in New White House Move

      March 4, 2026
    • Technology

      Why developers using AI are working longer hours

      March 8, 2026

      Put the zipcode first

      March 8, 2026

      Caitlin Kalinowski: I resigned from OpenAI

      March 8, 2026

      LangChain’s CEO argues that better models alone won’t get your AI agent to production

      March 8, 2026

      $3T flows through U.S. nonprofits every year

      March 8, 2026
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»CTM360 spots Malicious ‘ClickTok’ Campaign Targeting TikTok Shop users
    Technology

    CTM360 spots Malicious ‘ClickTok’ Campaign Targeting TikTok Shop users

    TechAiVerseBy TechAiVerseAugust 5, 2025No Comments4 Mins Read3 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    CTM360 spots Malicious ‘ClickTok’ Campaign Targeting TikTok Shop users
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    CTM360 spots Malicious ‘ClickTok’ Campaign Targeting TikTok Shop users

    CTM360 has discovered a new global malware campaign dubbed “ClickTok” that spreads the SparkKitty spyware through fake TikTok shops to steal cryptocurrency wallets and drain funds.

    The unique spyware trojan discovered by CTM360 is specifically engineered to exploit TikTok Shop users across the globe.

    Dubbed as “ClickTok”, this highly coordinated scam operation employs a hybrid scam model that combines phishing and malware to deceive buyers and affiliate program participants on TikTok’s growing e-commerce platform. 

    In the ClickTok campaign, TikTok shops were identified embedded with SparkKitty spyware, a variant closely resembling SparkCat, previously identified by Kaspersky.

    Once installed, it infiltrates the user’s device, accesses the photo gallery, and extracts screenshots that may contain cryptocurrency wallet credentials. What makes ClickTok unique is its simultaneous use of phishing and malware tactics, significantly increasing its impact and stealth. 

    The scam begins with the impersonation of TikTok’s commercial ecosystem, including TikTok Shop, TikTok Wholesale, and TikTok Mall. Threat actors create fake TikTok websites that closely mimic the official interface, deceiving users into thinking they’re interacting with the real platform.

    Victims are lured into logging in and attempting to make purchases. During the checkout process, they are instructed to pay via cryptocurrency wallets.

    Once payment is made, the trojanized app embedded with SparkKitty spyware, covertly captures sensitive data, including wallet credentials, by reading screenshots and images stored on the device, ultimately enabling the theft of digital funds.

    The Motive Behind ClickTok – A Hybrid Scam Structure

    The attacker has two main objectives: 

    Phishing Websites: 

    They incite users to open the fake Shop URLs distributed through meta ads, prompting users to enter login credentials, payment details, or seller information, all of which are silently harvested. 

    CTM360 has tracked down a unique spyware trojan specifically engineered to exploit TikTok Shop users across the globe.

    Dubbed as “ClickTok”, this highly coordinated scam operation employs a hybrid scam model that combines phishing and malware to deceive buyers and affiliate program participants on TikTok’s growing e-commerce platform. 

    Trojanized Apps: 

    On mobile, the sites urge users to install modified TikTok Apps that are infected with SparkKitty, a malicious spyware variant capable of deep device surveillance, clipboard scraping, and credential theft.

    These fake apps have the exact user interfaces as original TikTok shops, tricking victims into believing they’re interacting with a legitimate TikTok App while silently siphoning sensitive data in the background.

    Fake Ads, AI Videos & Lookalike Domains

    ClickTok scammers use Fake AI-generated Videos and Meta ads to reach a wider audience. These ads direct users to fake cybersquatted domains carefully crafted to look like real TikTok URLs. 

    To date, CTM360 has observed:

    • 10,000+ impersonated TikTok websites, many using free or inexpensive TLDs such as .top, .shop, .icu, and others.

    • Over 5,000+ unique malicious app instances, spread via QR codes, messaging apps, and in-app downloads.

    Fraudulent campaigns impersonating not just TikTok Shop, but also TikTok Wholesale and TikTok Mall. 

    Motive & Monetization

    The ClickTok campaign uses fake TikTok Shop login pages to harvest user credentials and malware distribution through trojanized apps that enable account hijacking. It implements an alternative payment structure that excludes traditional card transactions, instead requiring payments through cryptocurrency wallets.

    Victims are often encouraged to “top up” fake TikTok wallets or digital currencies like USDT, ETH and more. 

    CTM360’s Recommendations

    CTM360 urges users and organizations to stay vigilant and take the following precautions:

    • Avoid downloading modded, cracked, or unknown software, especially from torrent sites and Telegram.

    • Always verify domain authenticity before entering login or payment information, and manually check for spelling errors or suspicious domain extensions.

    • Report any suspicious TikTok-related content, ads, or apps directly to TikTok or cybersecurity authorities in your country.

    • Brands and sellers should regularly monitor brand abuse and impersonation trends using threat intelligence platforms.

    • Strong antivirus or EDR Solution to prevent SparkKitty spyware breaches. 

    • If you use a crypto wallet, go for one that is clipboard-protected.

    Detect Cyber Threats 24/7 with CTM360

    Monitor, analyze, and promptly mitigate risks across your external digital landscape with the CTM360.

    Join our Community Edition 

    Sponsored and written by CTM360.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleNew Plague Linux malware stealthily maintains SSH access
    Next Article Microsoft: Outdated Office apps lose access to voice features in January
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Why developers using AI are working longer hours

    March 8, 2026

    Put the zipcode first

    March 8, 2026

    Caitlin Kalinowski: I resigned from OpenAI

    March 8, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025705 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025292 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 2025166 Views

    6 Best MagSafe Phone Grips (2025), Tested and Reviewed

    April 6, 2025125 Views
    Don't Miss
    Technology March 8, 2026

    Why developers using AI are working longer hours

    Why developers using AI are working longer hoursSoftware engineering was supposed to be artificial intelligence’s…

    Put the zipcode first

    Caitlin Kalinowski: I resigned from OpenAI

    LangChain’s CEO argues that better models alone won’t get your AI agent to production

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    Why developers using AI are working longer hours

    March 8, 20262 Views

    Put the zipcode first

    March 8, 20262 Views

    Caitlin Kalinowski: I resigned from OpenAI

    March 8, 20260 Views
    Most Popular

    7 Best Kids Bikes (2025): Mountain, Balance, Pedal, Coaster

    March 13, 20250 Views

    VTOMAN FlashSpeed 1500: Plenty Of Power For All Your Gear

    March 13, 20250 Views

    Best TV Antenna of 2025

    March 13, 20250 Views
    © 2026 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.