💻 This year, on July 4, 2024, while logging into the TikTok Seller US website, 11 unauthorized files auto-downloaded onto my computer. File 8 was detected as a Trojan by Kaspersky. At the time, I was running trace files and a screen recording to provide evidence for Kaspersky. However, I was unable to access the saved zip archive containing the screen recording and trace files due to missing permissions. Shortly afterward, all undetected files disappeared from the folder.
Following this, my computer began making a loud noise, and I noticed a high data usage notification in the top-right corner of my screen. When I tried to scroll toward the notification, my mouse immediately froze. In response, I powered off the computer and removed the battery. Over a month later, when I turned the computer back on, the system clock was stuck on July 4, 2024.
Upon further investigation, I discovered that both the SYSTEM and my username were missing from the permissions on the zip file. After manually restoring the permissions, I regained access to the zip file and, to my surprise, the undetected files were visible again. I restored file 8 and transferred all 11 files to a USB drive while disconnected from the internet.
On December 1, 2024, I successfully uploaded the Trojan and the undetected files to analysis websites for further review. I am confident the files had disappeared earlier, as the same issue occurred on another laptop, but on this device, the files disappeared much faster. I suspect the malware may have detected that it was being analyzed. Below are the most recent results for each file.
I urge
@tiktok_us to investigate and address this critical security vulnerability on the TikTok Seller US website. Despite reaching out with evidence and detailed findings, I have yet to receive a direct response or confirmation that this issue has been resolved. Until TikTok provides transparency and a resolution, users of the Seller platform may remain at risk. Please prioritize user safety and cybersecurity by thoroughly investigating and addressing this matter.
🚨 File 8 detected as Trojan: SHA256: 8a333b62d5c4580137ccd33ebbecb65b6fae4c45c78007c3becdef6beb95e067
filescan.io/uploads/674d0bc2… (Suspicious, anti-vm)
virustotal.com/gui/file/8a33…
metadefender.com/results/has…
👀 Hashes of other undetected files in the same folder:
File: a
SHA256: 27ba4d61c5cc66e6aa44f8c5833dd852c84c13b8d5cce91fab1a5bdbb1af23d3
filescan.io/uploads/674d191d…
File: b
SHA256: f66f910a7a1d524e3fa59671b153ef853dffc788a74229164cb6268c419e525a
filescan.io/uploads/674d1dbc…
File: c
SHA256: a4cbb4c983e8cccc7c8e59a45e9bb4930d496ce90ccc62ac48da1d9fc16eb315
filescan.io/uploads/674d2d89…
🤨 File: 2 (No threat, but valid Bitcoin address detected)
SHA256: c08a231039ccc18f97a87f95e3d150ca74e8bd896b4d400922e9f773fbff1b7c
filescan.io/uploads/674d27ef…
File: 3
SHA256: 7bca7fe838f17ed6f5ee0071cdd7fc24fc246fd1e74182a2198c2c95ea2c847f
filescan.io/uploads/674d26f3…
File: 4
SHA256: 6ab2820513708ea96f22dc8d040853e20228c41516d9b3085e51d3fb3f8cb29c
filescan.io/uploads/674d258a…
File: 5
SHA256: 3870b0e775c2eb868efc062e5a33c187265ca6616ddbe50dd7421baca3ad0f43
filescan.io/uploads/674d2510…
File: 6
SHA256: fd4bc9b7d765929a36d49aabd2b7b809419b08b7964f890a9c56cc47eb4aaa00
filescan.io/uploads/674d238a…
🚨 File: 7 (Suspicious)
SHA256: dd2f1ae3942d4ea1a78de292220134d23ec52fbcab1ca6f736714750a76dcf22
filescan.io/uploads/674d1fc4…
🚨 File: 9 (Suspicious)
SHA256: f977f1f35f4cc915d93c583804aea111402026629b26d01b28430bcc3eaad98d
filescan.io/uploads/674d1485…