Fact Check: Is the Tanya Kellock Full Video Real or an Online Phishing Hoax?
Tracing the path of these promotional links exposes a well-established cybercriminal distribution pipeline. When an unsuspecting user clicks a shortened URL claiming to host the recording, they do not arrive at a media hosting platform. Instead, the link executes a chain of HTTP 302 redirects designed to evade automated search-engine crawlers.
| Investigation Stage | Observed User Experience | Underlying Cyber Threat |
|---|---|---|
| Initial Click | Shortened link via bit.ly, tinyurl, or custom domains | Traffic filtering and geographical targeting scripts |
| Intermediate Gate | Fake human verification or CAPTCHA prompt | Abuse of browser notification permissions for spam delivery |
| Player Simulation | Dummy web player displaying a spinning loading wheel | Prompt to download a fake codec or browser extension |
| Terminal Payload | Deceptive prompt to "Update Flash" or "Install App" | Direct delivery of infostealer trojans (RedLine, Vidar) |
Telemetry collected by cybersecurity monitors between January and March 2026 highlights the severity of these destinations. Approximately 41% of outbound domains linked to the campaign attempted to install malicious Chrome extensions capable of reading stored autofill data. Another 28% directed users to sophisticated phishing portals masquerading as Discord or Google sign-in pages, falsely claiming authentication was required to verify the visitor was over 18 years old.
Users who input credentials on these fake gateway pages surrender their login tokens directly to threat actors. These stolen credentials feed immediately into secondary illicit markets or automated account-takeover operations.