Recently, the “Silver Fox” trojan has become popular, and criminals use it to remotely control victims’ computers and carry out economic fraud activities. We urge WeCom users to take precautions.
Once a victim’s computer is controlled, criminals will operate all software on the computer in the victim’s name. Including but not limited to:
When the WeCom PC client detects the above-mentioned threats, it will lock itself and require scanning the QR code via mobile for verification. It will also notify the affected members and administrators, prompting them to take appropriate action.
When the WeCom for Mobile app detects the above threats, it will automatically log out from the current device and require the mobile to log in again. It will also notify members at risk to handle the issue according to the corresponding prompts.
1. Behavior of WeCom Upon Detecting a Threat
(1) When a threat is detected on the PC, after logging out the WeCom for PC app, corresponding alerts will be sent to the WeCom app of the member or administrator based on the level of risk.
At the same time, enterprise administrators will receive risk scanning reminders issued by the following enterprise WeCom security teams:
Please promptly upgrade the antivirus software and firewalls installed on members’ computers at risk of infection to the latest version, conduct virus scanning and removal, and restart the computer after eliminating the threats to defend against various Trojan and malicious software attacks.
Next, taking Tencent PC Manager as an example, follow the steps below to perform a comprehensive antivirus scan (for detailed operation instructions, please refer to: Tencent PC Manager Silver Fox Special Scan Guide):
If the virus has already been manually removed, please complete the following two steps to ensure it is thoroughly eliminated:
1. Restart your device: Be sure to click on “Start Menu” → “Restart”. Please note that you must select “Restart”; do not select “Shut down”. Ensure the system restarts successfully to guarantee the virus is completely removed.
2. Verify the result: After the restart is complete, please check whether the system still pops up virus alerts or abnormal warnings.
Should the antivirus scan yield no results, or if virus alerts continue to appear post-removal, we recommend either contacting the Tencent PC Manager Security Team via QQ: 3158116896 (Tencent PC Manager Silver Fox Special Scan), or use the method of reinstalling the system to completely repair the system environment.
(2) When a threat is detected on the mobile, after logging out of the WeCom for Mobile app, corresponding alerts will be sent to the member’s WeCom app.
Upon receiving the reminder, please promptly follow the instructions below to inspect the mobile of the member at risk of malware infection:
① Locate Settings, search for “Accessibility”, go to the “Downloaded Apps” section under Accessibility, and check for any suspicious apps.
② Check the mobile’s home screen for any suspicious app icons. Try to uninstall by pressing and holding the icon. If the action is blocked by a Trojan, you can also remove the Trojan app in the following ways:
a. Open the mobile’s antivirus software, go to App Management, locate the suspicious app, and uninstall it.
b. Open the mobile’s built-in “App Store”, locate App Uninstall, and remove the suspicious app.
After WeCom locks a member, operation logs will be recorded on the admin side. Administrators can log in to the Admin Console or retrieve member operation logs via API to identify members at risk.
When a member’s device is infected and has been exploited by malicious actors to send harmful information, these messages need to be addressed to prevent the harm from spreading further.
If the infected member account has sent virus files or fraudulent messages in the group chat, it is necessary to promptly contact the group owner to recall the group messages, disband the group chat as needed, and send a group announcement to warn others. For specific details, please refer to [How Members Can Recall Conversation Messages]
If an infected member account has created virus or fraudulent related events, it is necessary to promptly contact the infected member to delete them;
If the event creator is unable to perform the operation, the super administrator can navigate to [Admin Console - Security & Management - Security Management - Data Asset Handover], handover the departing member’s events to another member, and then the transferred member can carry out the operation. For specific details, please refer to [How to Use “Data Asset Handover”]
If an infected account has sent emails containing virus files to external parties, the user of the infected account can click “Recall Email” in [WeCom on Computer - Mail - Sent], supporting the recall of emails sent within 24 hours.
Enterprise administrators can navigate to [Admin Console - Collaboration - Security Management - Recall Member Emails]. After automatically matching emails via sender or subject information, click “Recall”. For specific details, please refer to [“Email Recall” Feature Introduction]
Accounts with basic features only support recalling emails sent within 24 hours, while accounts with advanced features can recall emails sent within the last 15 days.
Before the infected member completes a full antivirus scan, administrators can locate the corresponding account in “Admin Console - Contacts” and disable it. After the full antivirus scan is completed, the account can be re-enabled.
Preventing potential risks before they occur is the best form of security. We recommend that administrators refer to the [WeCom Administrator Security Guide] and implement the following preventive measures.