When users click links associated with these viral posts, they encounter a multi-stage redirect loop. The initial URL, masked behind standard URL shorteners like TinyURL or bit.ly, routes through intermediary redirectors to evade automated spam checkers. The end destination is almost never a functioning video player or photo gallery.
Users land instead on spoofed landing pages mimicking trusted platforms such as Google Drive, Mega, or Dropbox. A modal dialog box informs the visitor that access requires identity confirmation, prompting them to enter social media or email account credentials. This tactic, classic credential harvesting, hands the attacker instant session tokens and account passwords.
In other instances, the destination page displays a false media codec error. A prominent button instructs the victim to download a required "player update" or uncompress a password-protected zip file. Executing these payloads bypasses native antivirus software, releasing remote access trojans or infostealers such as LummaC2 or RedLine into the victim's operating system.