Help Center
Guidelines for Identifying Remote Control and Trojans
[TOC]

I. Threats of Remote Control and Trojans

Recently, the “Silver Fox” trojan has become popular, and criminals use it to remotely control victims’ computers and carry out economic fraud activities. We urge WeCom users to take precautions.

1. Characteristics of Trojans

  • Easy to spread:
    Spreads through means such as downloads via search engines and personal social software; users become infected after opening them;
  • Capable of remote control:
    Once infected, the computer will be remotely controlled by criminals to carry out fraud in the victim’s name;
  • Difficult to detect and remove
    Evades detection by antivirus software through various means, leading to intense countermeasures;

2. Hazards of Trojan

Once a victim’s computer is controlled, criminals will operate all software on the computer in the victim’s name. Including but not limited to:

  • Spreading Trojans
    Forwarding malicious Trojan files to group chats, inducing group members to click and download, leading to infections of more devices and thus controlling more computers;
  • Impersonating colleagues or superiors to carry out fraud
    Taking control of the victim’s personal social media accounts, sending forged fake web pages such as “National Financial Subsidies”, “Performance Subsidies”, and “Salary Subsidies”, tricking company colleagues or business clients into making payments or disclosing sensitive information;

II. Identifying Methods When WeCom Prompts an Abnormal Environment

When the WeCom PC client detects the above-mentioned threats, it will lock itself and require scanning the QR code via mobile for verification. It will also notify the affected members and administrators, prompting them to take appropriate action.
When the WeCom for Mobile app detects the above threats, it will automatically log out from the current device and require the mobile to log in again. It will also notify members at risk to handle the issue according to the corresponding prompts.

1. Behavior of WeCom Upon Detecting a Threat

  • Upon detecting a threat on the PC, the WeCom for PC app will log out and require re-login by scanning the QR code with a mobile within a specified period to prevent remote control by malicious actors.

  • If a threat is detected on the mobile, the WeCom for Mobile app will log out and require the user to re-login to prevent remote control by malicious actors.

(1) When a threat is detected on the PC, after logging out the WeCom for PC app, corresponding alerts will be sent to the WeCom app of the member or administrator based on the level of risk.

  • There is remote control behavior detected on the member’s computer
    This alert is only sent to members. If the current remote control behavior is not performed by the member themselves, it is recommended to leave the WeCom PC client and conduct a full antivirus scan on the computer. If the current remote control behavior is confirmed by the user as a normal work requirement with no risk, you can scan the QR code on the security verification page of the computer for verification. After verification, a lockout will not be triggered again within 24 hours.

  • The member’s computer may be infected with viruses/Trojans
    Members whose computers are at risk of being infected with the “Silver Fox” virus/Trojan will receive the following lock alerts. At this time, it is crucial to conduct a comprehensive antivirus scan; otherwise, the account/device will remain locked.

At the same time, enterprise administrators will receive risk scanning reminders issued by the following enterprise WeCom security teams:

Please promptly upgrade the antivirus software and firewalls installed on members’ computers at risk of infection to the latest version, conduct virus scanning and removal, and restart the computer after eliminating the threats to defend against various Trojan and malicious software attacks.
Next, taking Tencent PC Manager as an example, follow the steps below to perform a comprehensive antivirus scan (for detailed operation instructions, please refer to: Tencent PC Manager Silver Fox Special Scan Guide):

If the virus has already been manually removed, please complete the following two steps to ensure it is thoroughly eliminated:
1. Restart your device: Be sure to click on “Start Menu” → “Restart”. Please note that you must select “Restart”; do not select “Shut down”. Ensure the system restarts successfully to guarantee the virus is completely removed.
2. Verify the result: After the restart is complete, please check whether the system still pops up virus alerts or abnormal warnings.

Should the antivirus scan yield no results, or if virus alerts continue to appear post-removal, we recommend either contacting the Tencent PC Manager Security Team via QQ: 3158116896 (Tencent PC Manager Silver Fox Special Scan), or use the method of reinstalling the system to completely repair the system environment.

(2) When a threat is detected on the mobile, after logging out of the WeCom for Mobile app, corresponding alerts will be sent to the member’s WeCom app.

Upon receiving the reminder, please promptly follow the instructions below to inspect the mobile of the member at risk of malware infection:
① Locate Settings, search for “Accessibility”, go to the “Downloaded Apps” section under Accessibility, and check for any suspicious apps.

② Check the mobile’s home screen for any suspicious app icons. Try to uninstall by pressing and holding the icon. If the action is blocked by a Trojan, you can also remove the Trojan app in the following ways:
a. Open the mobile’s antivirus software, go to App Management, locate the suspicious app, and uninstall it.
b. Open the mobile’s built-in “App Store”, locate App Uninstall, and remove the suspicious app.

3. How do administrators identify members at risk

After WeCom locks a member, operation logs will be recorded on the admin side. Administrators can log in to the Admin Console or retrieve member operation logs via API to identify members at risk.

  • Log in to the Admin Console, navigate to Security & Management - Management Tools - Usage Analysis - Member Operation Records, and select “Lock Device” for the operation type.

  • Pull member operation logs via API.

III. Post-event Remediation

When a member’s device is infected and has been exploited by malicious actors to send harmful information, these messages need to be addressed to prevent the harm from spreading further.

1. Disband the group or recall group messages

If the infected member account has sent virus files or fraudulent messages in the group chat, it is necessary to promptly contact the group owner to recall the group messages, disband the group chat as needed, and send a group announcement to warn others. For specific details, please refer to [How Members Can Recall Conversation Messages]

2. Handling of fraud events

If an infected member account has created virus or fraudulent related events, it is necessary to promptly contact the infected member to delete them;
If the event creator is unable to perform the operation, the super administrator can navigate to [Admin Console - Security & Management - Security Management - Data Asset Handover], handover the departing member’s events to another member, and then the transferred member can carry out the operation. For specific details, please refer to [How to Use “Data Asset Handover”]

3. Handling of fraud emails

If an infected account has sent emails containing virus files to external parties, the user of the infected account can click “Recall Email” in [WeCom on Computer - Mail - Sent], supporting the recall of emails sent within 24 hours.
Enterprise administrators can navigate to [Admin Console - Collaboration - Security Management - Recall Member Emails]. After automatically matching emails via sender or subject information, click “Recall”. For specific details, please refer to [“Email Recall” Feature Introduction]
Accounts with basic features only support recalling emails sent within 24 hours, while accounts with advanced features can recall emails sent within the last 15 days.

4. Disable Members

Before the infected member completes a full antivirus scan, administrators can locate the corresponding account in “Admin Console - Contacts” and disable it. After the full antivirus scan is completed, the account can be re-enabled.

IV. Preventive Measures In Advance

Preventing potential risks before they occur is the best form of security. We recommend that administrators refer to the [WeCom Administrator Security Guide] and implement the following preventive measures.

  • Strengthen information security education for all employees in the enterprise
  • Strictly control the settings for joining the enterprise and the use of Contacts-related APIs
  • Enhance risk monitoring for employee accounts
  • Strengthen self-inspection of administrator accounts and strictly control administration permissions
  • Protect internal information security of enterprise