TikTok Challenge Used To Circulate Information-Stealing Malware

Risk:
high
Damage:
high
Platform(s):
Mobile Networks and Telephones
Advisory ID:
ngCERT-2022-0100
Version:
N/A
CVE:
N/A
Published:
December 1, 2022

Summary


Threat actors have taken advantage of a viral TikTok challenge, known as the Invisible Challenge, to disseminate an information-stealing malware known as the WASP (or W4SP) stealer. WASP stealer is a persistent malware hosted on discord that its developer claim is undetectable.

Description & Consequence


The Invisible Challenge involves wrapping a somewhat transparent body contouring filter around a presumed naked individual. Attackers are uploading videos to TikTok with a link to software that they claim can reverse the filter's effects. Those who click on the link and attempt to download the software, known as "unfilter," are infected with the WASP stealer. Suspended accounts had amassed over a million views after initially posting the videos with a link. Following the link leads to the "Space Unfilter" Discord server, which had 32,000 members at its peak but has since been removed by its creators.

Successful installation will allow the malware to harvest keystrokes, screenshots, network activity, and other information from devices where it is installed. It may also covertly monitor user behaviour and harvest personally identifiable information (PII) including names and passwords, keystrokes from emails, chat programs, websites visited, and financial activity.This malware may be capable of covertly collecting screenshots, video recordings, or the ability to activate any connected camera or microphone.

Solution


Some ways to forestall such an attack include:

  1. Avoid clicking on suspicious links.
  2. Use anti-malware software on your devices.
  3. Check app tray and remove any apps that you do not remember installing or that are dormant.
  4. Embrace healthy password hygiene practices such as using a password manager. 

Reference


Revision


Related Articles