Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraud — Threadlinqs Intelligence
As of 2026-08-03, Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment Fraud is a low-severity fraud threat attributed to DuckTail (Vietnam), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1826 · Severity: LOW · Status: ACTIVE · Category: FRAUD
Attribution: DuckTail · Vietnam · FINANCIAL
Malwarebytes documents an active TikTok engagement-fraud ecosystem in which SMM-panel services selling followers, likes, views and mass-messaging rely on bots, click farms, and hijacked accounts,
Malwarebytes researcher Stefan Dasic (via Help Net Security, 2026-08-03) analyzed the market of third-party services promising rapid TikTok growth and found three converging scam patterns: (1) bulk engagement sellers advertising 'real profiles, no bots, no click farms' while actually delivering bot- and click-farm-driven engagement that TikTok's fraud detection later strips, risking account flags/restrictions; (2) an 'aged'/pre-verified TikTok Ads account marketplace offering accounts with a 'replacement guarantee' that are, per Malwarebytes, frequently built using stolen or synthetic identities, fake personal information, or compromised payment cards — meaning a buyer inherits that fraud history along with suspension and lost-ad-budget risk; and (3) growth-framework funnels hosted on free platforms that collect victim email and phone numbers before pitching paid courses or 'done-for-you' management, ultimately requesting direct access to a victim's TikTok Shop or Ads account. Across all three patterns, the common technical exposure is the same: TikTok usernames, passwords, or third-party account-authorization scopes handed to unverifiable operators.
This credential/account-access exposure is not theoretical. In March 2026, Push Security (via BleepingComputer, Cybernews, The Hacker News and ThaiCERT) identified a live adversary-in-the-middle (AiTM) reverse-proxy phishing campaign that registered 11 lookalike domains (e.g. welcome.careerscrews[.]com) through registrar NiceNIC within a single automated 9-second window on 2026-03-24, hosted behind Cloudflare with a Turnstile bot-check gate, and impersonated both 'TikTok for Business' login pages and 'Google Careers — Schedule a Call' pages. Victims who authenticate — including via Google SSO — have their credentials and live, post-2FA session cookies relayed through the proxy, giving the attacker an authenticated session without needing to defeat MFA outright. The campaign was linked by researchers to a 2025 operation using the identical technique against Google Ad Manager accounts, and to an October 2025 precursor (flagged by Sublime Security) that distributed Vidar, StealC and Aura Stealer infostealers via ClickFix-style lures. TikTok confirmed the identified domains were taken down.
Separately, the Vietnam-origin actor cluster tracked as DuckTail (first documented publicly in 2022 and still active) specializes precisely in the account-resale sub-component Malwarebytes describes: DuckTail social-engineers digital-marketing and advertising professionals via fake LinkedIn recruiter profiles and job postings, delivers infostealer payloads disguised as 'job application packages' (executables, malicious Excel add-ins, browser extensions, fake AI-tool installers) hosted on iCloud/Google Drive/Dropbox/Transfer.sh/OneDrive/Trello, and harvests saved browser session cookies to hijack authenticated Facebook, TikTok, LinkedIn and Google Ads/Business sessions. After takeover, operators add attacker-controlled recovery email addresses, sometimes enable the platform's Encrypted Notifications feature specifically to block the victim's account-recovery communications, and route activity through private residential proxies to mask geolocation and evade platform anti-fraud checks. Compromised accounts are then priced by type, daily ad budget, verification status and account age, and traded on Telegram, Facebook, Zalo and other Vietnamese underground markets — from roughly $15 for low-grade personal accounts up to ~$340 for verified, high-budget business accounts.
No CVE, CVSS score, or platform vulnerability is implicated: this is a social-engineering and marketplace-fraud ecosystem, not a software exploit. Severity is assessed LOW at the individual-consumer level (account flagging, wasted spend, follower churn) but the TikTok-for-Business/Ads-account-takeover sub-component carries meaningful business/financial impact (stolen ad budget, fraudulent charges, locked-out recovery) and is under ac
Target sectors: social media creator economy, digital marketing and advertising, ecommerce, small business advertisers, consumer general public
Target regions: Global
Detections & IOCs
As of 2026-08-07, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
FRAUD, LOW, threat intelligence, cybersecurity, T1589, T1593.001, T1583.001, T1608.005, T1585.001, T1586.001, T1566.002, T1598.003, T1078.004, T1204.002