Identity & AccessMar 27, 2026
AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion
Threat actors deploy AitM phishing against TikTok Business accounts using Cloudflare Turnstile bypass.
Vendor Watch
Run TikTok?
Get an email when a reviewed story names TikTok, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works
Summary
Threat actors are conducting adversary-in-the-middle (AitM) phishing attacks targeting TikTok for Business accounts, exploiting Cloudflare Turnstile CAPTCHA to evade detection. Compromised business accounts are then weaponized for malvertising and malware distribution. The campaign highlights how legitimate platform features can be abused once account credentials are compromised.
Indicators of Compromise
- malware — AitM phishing pages
Entities
TikTok (vendor)Cloudflare (vendor)Push Security (vendor)TikTok Business Account AitM Phishing Campaign (campaign)