Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Anduril raises $5B, doubles valuation to $61B

    May 13, 2026

    Kevin Hartz’s A* just closed its third fund with $450M

    May 13, 2026

    Riding an AI rally, Robinhood preps second retail venture IPO

    May 12, 2026
    Facebook X (Twitter) Instagram
    Tech Pulse
    • Anduril raises $5B, doubles valuation to $61B
    • Kevin Hartz’s A* just closed its third fund with $450M
    • Riding an AI rally, Robinhood preps second retail venture IPO
    • Korea’s biggest manufacturers back Config, the TSMC of robot data
    • Get ready for the whisper-filled office of the future
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Techurz
    • Home
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    Techurz
    Home - Cyber Reality - TikTok video promising you free Photoshop or Windows license? Don’t do it – it’s a scam
    Cyber Reality

    TikTok video promising you free Photoshop or Windows license? Don’t do it – it’s a scam

    TechurzBy TechurzOctober 21, 2025Updated:May 10, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    TikTok video promising you free Photoshop or Windows license? Don't do it - it's a scam
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Yosi Azwan/iStock /Getty Images Plus

    Follow ZDNET: Add us as a preferred source on Google.

    ZDNET’s key takeaways

    • TikTok is a delivery platform for ClickFix social engineering attacks.
    • We found live video examples of the scam for Photoshop and Windows.
    • Clickfix is a popular new method of choice for threat actors.

    TikTok is being exploited as a delivery platform to spread information-stealing malware and other payloads, with free software acting as the bait.

    On October 17, Senior ISC Handler Xavier Mertens said in a post published on the SANS Institute’s Internet Storm Center website that the wave of attacks on TikTok leverages ClickFix social engineering techniques to dupe victims into downloading malware onto their systems. 

    Also: This new cyberattack tricks you into hacking yourself. Here’s how to spot it

    In the example video posted by Mertens, a scammer has posted content — with over 500 likes — which pretends to provide watchers with an easy way to activate Photoshop for free. 

    The victim is asked to start PowerShell as an administrator and trigger one line of code, which then executes “Updater.exe,” which is actually AuroStealer, a Trojan designed to steal credentials and system information. An additional shellcode is also launched in memory. 

    ZDNET explored TikTok for similar videos and it was surprising how many were live. For example, in the screenshot below, the author was promoting a fake way to download and install Adobe Photoshop without the need for a license. Other examples we found included fake, free ways to license Microsoft Windows.

    Charlie Osborne/ZDNET

    What is Clickfix?

    Clickfix is a particularly nasty social engineering technique that tries to bypass traditional anti-phishing protections by tricking users into “hacking” themselves.

    Also: Best VPN services 2025: The fastest VPNs with the best networks, ranked

    Instructions are given, in one form or another, which could include using a Windows shortcut and copy-pasting a snippet of code into a command prompt to trigger a PowerShell script. These instructions are laid out in a way that is easy to understand and are given a fake purpose — such as for fixing a minor technical glitch, a way to use paid software for free, or as a “life hack” for improving popular streaming services. 

    Once the victim has unwittingly opened up their device for exploitation, a malicious payload is deployed and executed. Malware recorded in Clickfix campaigns includes information stealers, Remote Access Trojans (RATs), ransomware, and worms. 

    Is this the first time TikTok and Clickfix have been linked?

    Sadly, no. Back in March, cybersecurity researchers from Trend Micro reported that TikTok videos, potentially generated through AI tools, were being distributed on the platform to spread Vidar and StealC information stealers. A network of faceless accounts posted videos on topics including improving Spotify and included step-by-step instructions that, instead, launched a PowerShell command to load malware. 

    Also: 9 ways to delete yourself from the internet (and hide your identity online)

    “The vast user base and algorithmic reach of social media platforms provide an ideal delivery mechanism for threat actors,” the researchers noted. “For attackers, this means broad distribution without the logistical burden of maintaining an infrastructure.”

    Earlier this month, Microsoft warned that Clickfix is becoming increasingly popular as a method of infiltrating networks, stealing data, and deploying malware. 

    In the Redmond giant’s latest Digital Defense report, Microsoft said that since 2024, Clickfix tactics have been recorded as a method of initial access in 47% of attacks, ahead of phishing and password “spray and pray” attack methods.

    How do I protect myself against Clickfix attacks?

    Don’t execute a command on your device if you are not sure about the source of the code or its true purpose, especially if you find the instructions on social media, where they’re unlikely to be vetted. Now that you know this social engineering method exists, stay suspicious. Tell your friends, too.

    dont free License Photoshop Promising scam TikTok Video Windows
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSecuring AI to Benefit from AI
    Next Article Aura introduces a $499 e-ink digital photo frame that lets you go cordless
    Techurz
    • Website

    Related Posts

    Opinion

    BCI startup Neurable looks to license its ‘mind-reading’ tech for consumer wearables

    April 28, 2026
    Opinion

    SaySo is a new short-form video app that aims to restore users’ trust in news

    April 17, 2026
    Opinion

    Conntour raises $7M from General Catalyst, YC to build an AI search engine for security video systems

    March 26, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    College social app Fizz expands into grocery delivery

    September 3, 20252,288 Views

    A Former Apple Luminary Sets Out to Create the Ultimate GPU Software

    September 25, 202516 Views

    The Reason Murderbot’s Tone Feels Off

    May 14, 202512 Views
    Our Picks

    Anduril raises $5B, doubles valuation to $61B

    May 13, 2026

    Kevin Hartz’s A* just closed its third fund with $450M

    May 13, 2026

    Riding an AI rally, Robinhood preps second retail venture IPO

    May 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.