TikTok Pro is an Android spyware application that masquerades as a TikTok-related app to lure victims seeking alternative or unofficial versions of the service. It has been assessed as a full-featured mobile surveillance implant and has been linked by researchers to a builder or framework resembling SpyNote or SpyMax, while also exhibiting custom credential-phishing functionality.
On infected devices, TikTok Pro maintains execution through Android broadcast receivers that trigger on device boot and telephony events, enabling the malware to restart background services and persist across reboots. Its core functionality centers on surveillance, data theft, and remote command execution. Reported capabilities include collecting SMS messages, contacts, call logs, installed application lists, account information, photos, and credentials from other applications; capturing images and video through the device camera; recording audio; obtaining location data; sending SMS messages; placing calls; launching applications; deleting attacker-specified files; and executing attacker-issued commands.
A notable feature is its use of a fake Facebook login interface to steal credentials, indicating both spyware and credential-harvesting behavior. The malware also hides its icon after launch and uses deceptive notifications to reduce user suspicion, reflecting defense-evasion tradecraft. Observed storage and staging behavior indicates local collection of stolen data prior to exfiltration.
TikTok Pro targets Android devices and fits the pattern of mobile spyware distributed through social engineering and brand impersonation. Its combination of persistent background monitoring, broad device-data access, telephony abuse, credential theft, and remote operator control makes it suitable for surveillance, account compromise, and follow-on exploitation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 distinct techniques documented for this family, organized by ATT&CK tactic.
Gooligan steals authentication tokens that can be used to access data from multiple Google applications. RCSAndroid can collect passwords for Wi-Fi networks and online accounts, including Skype, Facebook, Twitter, Google, WhatsApp, Mail, and LinkedIn. Monokle can retrieve the salt used when storing the user’s password, aiding an adversary in computing the user’s plaintext password/PIN from the stored password hash.
Anubis can exfiltrate files encrypted with the ransomware module from the device and can modify external storage. BusyGasper can collect images stored on the device and browser history. CHEMISTGAMES can collect files from the filesystem and account information from Google Chrome.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Android spyware masquerading as TikTok. It hides its icon, persists via services and broadcast receivers, communicates with a C2 server, steals SMS, location, contacts, call logs, screenshots, photos, audio, Facebook credentials, can send SMS, place calls, launch apps, and execute attacker commands.
Android malware capable of capturing photos and videos from the device camera.
Android trojan that impersonates TikTok.
Spyware-laced fake TikTok-themed Android app that can send SMS messages.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.