Back to Feed
Identity & AccessMar 27, 2026

AitM Phishing Targets TikTok Business Accounts Using Cloudflare Turnstile Evasion

Threat actors deploy AitM phishing against TikTok Business accounts using Cloudflare Turnstile bypass.

Vendor Watch

Run TikTok?

Get an email when a reviewed story names TikTok, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch works

Summary

Threat actors are conducting adversary-in-the-middle (AitM) phishing attacks targeting TikTok for Business accounts, exploiting Cloudflare Turnstile CAPTCHA to evade detection. Compromised business accounts are then weaponized for malvertising and malware distribution. The campaign highlights how legitimate platform features can be abused once account credentials are compromised.

Indicators of Compromise

  • malware — AitM phishing pages

Entities

TikTok (vendor)Cloudflare (vendor)Push Security (vendor)TikTok Business Account AitM Phishing Campaign (campaign)