Help Center
Security guidelines for WeCom admins

Internet fraud seriously endangers the security of property and information of companies, so it is everyone’s duty to prevent fraud.

Meanwhile, there has been a surge in computer Trojan viruses like “Silver Fox”across China recently. After gaining remote control of computers through viruses, cybercriminals rapidly create a large number of groups and distribute fraudulent links. Under the guise of activities like inviting votes, they steal WeChat account passwords from group members. Alternatively, they send phishing messages disguised as prize notifications, financial/tax notices, or similar themes to commit financial fraud.

Although WeCom employs robust security protections, cybercriminals still exploit vulnerabilities, such as tricking employees into downloading Trojan viruses, bribing corporate staff, or phishing employees for account credentials to perpetrate malicious activities. Based on WeCom’s industry-grade anomaly detection and prevention capabilities, enterprises are advised to strengthen security awareness and implement protective measures against such fraud and Trojan virus to avoid the impact on your enterprise.

The following are suggestions for administrators:
1. Be on high alert to the following new fraud methods and learn the preventive measures.
2. Remind all employees to strengthen their security awareness: Do not hand over mobiles to strangers, refrain from scanning QR codes indiscriminately, refrain from renting out account, and do not open files with extensions such as .exe, .com, .bat, .msi, etc., without proper verification. Never allow momentary negligence or enticement of gain to create exploitable opportunities for cybercriminals;
3. Set the security settings of WeCom to the highest level to strengthen the security protection.
4. Ensure timely updates to your computer’s operating system, keep your antivirus software and firewall updated to the latest versions, and perform regular scanning and killing to protect against Trojan virus and malware attacks.

Below are the new types of fraudulent tactics we have identified:
1. Luring employees into downloading Trojan viruses
Cybercriminals employ various methods to lure corporate employees into downloading software embedded with Trojan viruses like “Silver Fox”. For example, sending counterfeit tax audit notices as “bait” to induce finance staff into clicking malicious download links or forwarding fake files with viruses to employees; or spoofing official websites of office software or popular AI tools to mimic legitimate platforms, making employees mistakenly believe that they are downloading genuine software.

2. Compromising employee accounts
Fraudsters wearing work clothes visit the company’s office and borrow employees’ mobile phones under the pretext of performing offline marketing for a certain company or data labeling for a certain map app. However, in fact, fraudsters are hacking the employees’ mobile number and verification code to log in to WeCom.

Criminals will also ask employees to scan unknown QR codes to compromise their accounts under the guise of tasks or gifts in crowded places such as universities, companies, and subways. Once the user scans the QR code, criminals will be authorized to log in, and the account will be compromised when the task is completed.

After compromising the account, criminals may carry out fraud within the company, and may also leak confidential information such as the corporate directory and chat history, resulting in serious consequences.

3. Renting or buying accounts from employees or join the corporate directory by being invited by employees
Some employees with weak security awareness and who are greedy for petty advantages rented or sold their WeCom accounts to network attackers. Then, the network attackers used the rented employee account to swindle. Once the criminals are caught, the employees should also bear legal responsibility.

Some companies have set up in the admin console to allow employees to invite users to join the corporate directory, but employees who are deceived or bribed by criminals may invite unknown users, which may cause security hazards.

4. Infiltrating into companies via APIs
Some companies have developed their own Mini Program/web page to quickly complete the corporate directory and make it available to external users. Employees are invited to fill in their information and join the company. During identity verification, if only employees’ name, mobile number, and employee ID rather than HR’s verification is required, criminals can infiltrate into the company with the compromised information of employees.

5. Defrauding admin permissions after entering companies
Criminals pretended to be entrusted by leaders such as the chairman and the principal by forging chat history, and asked the super admin to grant them admin permissions or verify their identity by scanning a QR code and log in to the admin console.
Be cautious about activating an admin account, because it owns many permissions of the company. A compromised admin account may put the company at great risks. For example, criminals may use their admin account to harass and defraud internal employees, customers, and suppliers and distributors in Partner Space.

In response to potential information security risks, we suggest that WeCom administrators implement the following specific preventive measures:
I. Countering Trojan Virus Attacks
(I) Administrators Strengthen Enterprise Security Protections

Ensure computer operating systems are promptly updated. Upgrade antivirus software and firewall to the latest versions, and conduct regular scanning and killing to defend against various Trojan viruses and malware attacks.
● Implement strict access control policies at internal network boundaries to block unauthorized external devices or networks from accessing internal resources.
● Upgrade WeCom to the latest version in a timely manner.

(II) Key Points for Employee Attention
● Office computers should be set to “Auto-lock the screen when not in use”; Log out of WeCom or shut down computers when leaving the office.
● When WeCom pops up an unusual prompt, immediately scan the QR code to confirm whether it is operated by yourself. This prevents remote control of your computer by Trojan malware or account theft by cybercriminals. If unauthorized activity is detected, log out immediately and report to the administrator.

● If you encounter suspicious files, propagation of links, harassment, or suspected virus infections in WeCom, report to the administrator immediately.
● Be cautious when clicking on files or links from unverified sources, with a focus on files with suffixes such as [.exe], [.zip], [.rar], [.7z], [.tgz], [.cab], [.bat], [.com], [.chm], [.iso], and [.msi].
● Don’t indiscriminately download or install software without official certification to prevent malicious code from infiltrating the system.
● Avoid using WeCom in unsafe environments such as others’ mobiles or public computers. In situations where multiple people use one device, always log out immediately after use and disable auto-login feature.

II. For information leakage caused by employees in companies, we recommend that WeCom admins take the following preventive measures:
(I) Strengthen information security education for all employees of the company
Admins can remind all employees to pay attention to account security.
● Do not lend your mobile phone with WeCom to strangers.
● Do not invite external personnel into the company
Otherwise, employees may be subject to internal penalties and even legal sanctions.

(II) Strictly manage the setting of joining companies and the use of contacts-related APIs
● When the corporate directory is completed, it is recommended that employees be prohibited from inviting users to join the company in the admin console, and those who join the company must be reviewed by admins to reduce the possibility of criminals infiltrating into the company.

● When creating custom apps and authorizing third-party apps, check whether the use of the contacts API is reasonable. If the company has developed its own Mini Program/webpage to complete the contacts, make sure that only employees registered in the company’s HR system are invited.

(III) Strengthen the risk monitoring of employee accounts
● Clear contacts regularly and remove the offboarded employees and external personnel from the contacts.
● Check the operation records of members on a regular basis. If it is found that employees use new login devices multiple times, change mobile numbers/WeChat accounts and other abnormal situations, you can communicate with the employees.
● It is strongly recommended that companies with high information security requirements develop the feature of secondary verification for employee login. An API is available in WeCom to help companies verify the login frequency of employees.
For the API, see: https://developer.work.weixin.qq.com/document/path/90203.

(IV) Strengthen the self-inspection of admin accounts and strictly manage admin permissions
● When adding admins, their identities need to be verified.
● It is recommended to enable SMS verification for admin login. After scanning a QR code, admins can only log in to the admin console with a SMS verification code. Under no circumstances should admins scan QR codes or receive verification codes for others to authorize them to log in to the admin console, preventing criminals from obtaining admin permissions.

● Regularly check admins’ operation records and confirm whether there are security hazards in the abnormal operation records.

(V) Protect the information security within companies
● To prevent impostors to add WeChat contacts for fraud, it is recommended that only employees who need to communicate with external users be granted permission to connect to WeChat.

● To prevent impostors from defrauding partners, after the Partner Space of the company are completed, it is recommended to prohibit employees from creating Partner Space in the admin console.

● To prevent impostors from leaking screenshots of internal messages, it is recommended to enable watermarks in chat, app, and contact pages to track the account with leakage.

The property and data security of a company requires the efforts of all members. In addition to the above preventive measures, admins can also remind all employees to put more emphasis on account security and obedience of the law, and never endanger the collective interests of the company to accomplish their own end.
For illegal and criminal acts that endanger the security of platforms and companies, the WeCom security team will handle them in strict accordance with
WeCom User Account Usage Rules and relevant national laws and regulations, and continue to protect the security of companies.

Admins can distribute the following security-related materials to employees for publicity and education.