Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

AI Red Packet Bomb Link Trojan: Short-Video Viral High-Copy Apps for Remote Control and Information Theft

The victims are mainly middle-aged and elderly short-video users, side-hustle task-matching groups, and young netizens keen on 'cash-grabbing' red packet activities. The elderly lack vigilance against terms like 'cash red packet' and 'limited-time claim,' easily lowering their guard upon seeing high-traffic links forwarded by relatives, friends, or in short-video comment sections; younger people fall into traps out of curiosity or petty gains, dragged down by messaging like 'everyone can claim' and 'first come, first served' as they click strange links. Scammers exploit people's trust inertia toward 'platform red packets'—assuming content seen within official short-video apps has been vetted—coupled with urgency-driven designs like countdown timers and remaining slots, giving people no time to verify domain names and sources before downloading and installing.

SCAM

Key Fields

FIELD STAMPS
IndustryContent / Creator Economy
RegionChina(中国大陆)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The victims are mainly middle-aged and elderly short-video users, side-hustle task-matching groups, and young netizens keen on 'cash-grabbing' red packet activities. The elderly lack vigilance against terms like 'cash red packet' and 'limited-time claim,' easily lowering their guard upon seeing high-traffic links forwarded by relatives, friends, or in short-video comment sections; younger people fall into traps out of curiosity or petty gains, dragged down by messaging like 'everyone can claim' and 'first come, first served' as they click strange links. Scammers exploit people's trust inertia toward 'platform red packets'—assuming content seen within official short-video apps has been vetted—coupled with urgency-driven designs like countdown timers and remaining slots, giving people no time to verify domain names and sources before downloading and installing.

骗局怎么运作

  • Step 1: Batch-generating red packet scripts and synthetic voice with large models. Scammers input copywriting such as 'Congratulations on winning an 888 yuan red packet' and 'Click the link to withdraw cash to WeChat' into AI tools, batch-producing short-video talking-head scripts in various dialects and tones, and then using AI synthetic voices paired with red packet screenshots to create tens of seconds of traffic-driving videos, generating thousands of items a day and distributing them to multiple short-video accounts.
  • Step 2: Publishing in volume and boosting via ad spend on short-video platforms. Scammers batch-publish AI-generated videos to platforms like Douyin and Kuaishou while using virtual accounts to flood popular red packet video comment sections with messages like 'I claimed it, it actually arrived,' attracting users to direct message or click homepage links. Some gangs also run information-flow ads, pushing videos to users who frequently search for 'red packet' and 'benefits' to expand reach.
  • Step 3: Directing users to phishing pages or high-copy apps. After users click links in short-video comment sections or direct messages, they are first redirected to a 'red packet claiming page' mimicking WeChat or Alipay, displaying '888 yuan has arrived, please download the app to withdraw.' The entire page is generated by web templates with cheap domain names like .top and .xyz consisting of random characters, paired with AI-generated customer service avatars and rolling arrival notifications to create a sense of authenticity.
  • Step 4: Inducing the download of APK installation packages embedded with remote control Trojans. After victims click the 'withdraw' button on the phishing page, the page automatically downloads an APK installation package of tens of megabytes, usually named 'Red Packet Assistant,' 'Express Withdrawal,' or disguised with a WeChat icon. This package embeds a remote control Trojan; upon installation, it requests 'Accessibility Service' or 'Device Manager' permissions. Once granted, scammers can remotely read SMS verification codes, intercept bank notifications, and even impersonate victims to send money-borrowing messages to contacts.
  • Step 5: Secondary exploitation in the name of 'unfreezing fees' or 'security deposits.' If the Trojan fails to directly siphon funds, scammers inform victims via online customer service inside the app that 'the account is frozen due to anomalies, and a 500 yuan unfreezing fee must be paid' or 'the withdrawal amount is too large and requires a top-up to activate.' Some victims, eager to recover the already 'received' 888 yuan, continue transferring funds, creating secondary losses. Once users find withdrawal impossible, scammers have long shut down servers and switched to new domains to continue the next round of deployment.

红旗信号(看到这些快跑)

  • 🚩 Abnormal short links or domains: Links do not come from official app domains, but rather low-cost domains with random characters like .top, .xyz, and .cc, or go through short-link redirects before bouncing to another unfamiliar domain.
  • 🚩 Unusual download methods: Legitimate red packet withdrawals require no additional app downloads whatsoever, but scam pages force-download APK installation packages after clicking 'withdraw,' and the package names are completely unrelated to red packet purposes.
  • 🚩 Demands for accessibility or device manager permissions: Pop-up windows during installation request sensitive permissions such as 'Accessibility Service,' 'Device Manager,' and 'Allow installation of apps from unknown sources.' Legitimate apps never request these permissions upon first use.
  • 🚩 Scripts carrying extreme urgency: Pages repeatedly feature countdown text such as 'Only 3 slots remaining,' 'Expires in 5 minutes,' and 'Miss it and wait another year,' and refreshing the page after the countdown hits zero restarts it, designed to leave people no time to verify authenticity.
  • 🚩 Claiming pages lack official customer service entry points: The entire page features only a 'Withdraw Now' button and a fake customer service avatar, lacking any platform official complaint, report, or help center entry, along with genuine user agreements and privacy policies.

真实案例

  • During the 2024 Spring Festival, CCTV exposed a 'WeChat Red Packet' scam: a victim received a text message reading 'Click the link to claim an 888 yuan cash red packet,' clicked it, followed page prompts to enter their name, bank card number, and mobile phone number, and subsequently received debit text messages with thousands of yuan in the card transferred out in batches. The broadcast reminded netizens not to trust any 'red packet links' requiring bank card information input.
  • In July 2026, the Ministry of Public Security announced 20 typical cases cracking down on fabricating and spreading online rumors, several of which involved unlawful elements using AI to generate fake videos and links on short-video platforms to create panic or induce clicks, resulting in administrative penalties for multiple individuals. The briefing specifically noted that AI tools have been used to batch-generate fake content, and public security organs will continue high-pressure crackdowns on such illegal crimes utilizing new technologies.
  • In early February 2026, an AI product named 'Yuanbao' launched red packet sharing links, which were blocked by WeChat for inducing users to share at high frequencies. WeChat responded that this behavior violated platform standards. Although not a scam case, the incident exposed how the model of 'AI-generated red packet links + social platform sharing' can spread rapidly at extremely low cost, providing a complete operational path for the subsequent dissemination of Trojan links.

Official Stance

  • On July 23, 2026, the Ministry of Public Security announced 20 typical cases, reporting over 170 cases investigated in the first half of the year involving the use of AI tools to generate online rumors, emphasizing that severe crackdowns in accordance with the law will target acts utilizing AI to commit fraud and spread malicious links.
  • In August 2026, the Kuaishou Security Center released summer anti-fraud reminders for minors, listing six types of high-incidence scams including 'red packet rebate fraud,' advising users not to click strange links or download apps from unknown sources.
  • On February 4, 2026, Beijing Daily reported WeChat's official response to the handling of the 'Yuanbao' red packet links, clarifying that 'inducing users to share at high frequencies' violates platform norms and warrants blocking, reminding users to remain vigilant regarding red packet links spread within social platforms.

How to Protect Yourself

  • ✅ When encountering any 'red packet link,' first check whether the domain is an official one; if not, exit and report immediately. Official red packet events take place exclusively within the app and are never sent via SMS or comment section direct messages.
  • ✅ Never download APK installation packages outside of official app stores. If already downloaded, do not click 'install,' let alone permit 'unknown sources' permissions; delete the installation package immediately and run a mobile antivirus scan.
  • ✅ When installing any app, reject any pop-up window requesting permissions such as 'Accessibility Service,' 'Device Manager,' or 'Read SMS.' Legitimate utility apps function properly without requiring these permissions.
  • ✅ Do not enter bank card numbers, ID numbers, or SMS verification codes into any unfamiliar webpage. Real red packet withdrawals do not require this information; treat anything demanding it as fraud, and call 96110 to consult and verify.