AI-Customized Red Packet Cover Trojan: Counterfeit Short-Video Fission Red-Packet Links for Backend Data Theft and Unauthorized Billing
The primary victim groups include users in lower-tier markets across third- and fourth-tier cities and rural areas, middle-aged and elderly populations, and young netizens enthusiastic about short-video platform holiday campaigns. These individuals are often defenseless against phrases such as 'free cash red packets' or 'limited holiday red-packet covers,' and their psychological weakness of coveting small gains is easily exploited by black-industry groups. At the same time, they lack sufficient awareness of underlying smartphone permission risks, cannot distinguish between high-imitation applications and legitimate official campaigns, and easily authorize accessibility permissions or allow the installation of apps from unknown sources. This ultimately leads to the theft of contact lists and SMS verification codes as well as stealth billing, resulting not only in direct financial losses but also potentially making them accomplices in the further fission and dissemination of the trojan.
Key Fields
FIELD STAMPSWho Gets Targeted
The primary victim groups include users in lower-tier markets across third- and fourth-tier cities and rural areas, middle-aged and elderly populations, and young netizens enthusiastic about short-video platform holiday campaigns. These individuals are often defenseless against phrases such as 'free cash red packets' or 'limited holiday red-packet covers,' and their psychological weakness of coveting small gains is easily exploited by black-industry groups. At the same time, they lack sufficient awareness of underlying smartphone permission risks, cannot distinguish between high-imitation applications and legitimate official campaigns, and easily authorize accessibility permissions or allow the installation of apps from unknown sources. This ultimately leads to the theft of contact lists and SMS verification codes as well as stealth billing, resulting not only in direct financial losses but also potentially making them accomplices in the further fission and dissemination of the trojan.
骗局怎么运作
- Black-industry syndicates use large AI models to batch-generate short-video copy and posters featuring personalized addresses and holiday greetings, disguising them as official year-end or holiday reward campaigns of a short-video platform. They claim that clicking the link allows users to claim up to 888 yuan or specific limited-edition red-packet covers, utilizing ultra-low-cost automated content matrices to distribute them massively in comment sections or private messages.
- Once victims are lured into clicking the link, they are redirected to a highly simulated campaign page. The page not only requires victims to input their mobile numbers and verification codes for so-called account binding, but also silently triggers the download command for a malicious installation package in the background, completing the initial implantation of the trojan program using invisible web frameworks.
- After victims install the package disguised as a red-packet plugin or accelerator, the trojan immediately requests device administrator permissions or accessibility service permissions. Once approved, the trojan actively hides its icon so victims cannot detect its presence on the desktop, while silently intercepting and forwarding all of the victim's SMS content to a remote server.
- During its stealth operation, the trojan program not only steals funds from the victim's payment accounts by intercepting SMS verification codes, but also triggers a phantom billing mechanism, simulating clicks in the background to send high-priced SMS messages or subscribe to billed services, deducting stealth fees ranging from several yuan to dozens of yuan each time, causing victims to bleed continuously without realizing it.
- To achieve viral propagation, the trojan automatically steals the victim's mobile contact list, analyzes the relationship network using AI technology, and generates customized scam text messages or private messages targeting their friends and family. Leveraging trust among acquaintances, it continues to spread malicious links disguised as 'I also claimed one, you should claim yours too,' forming exponential fission.
红旗信号(看到这些快跑)
- 🚩 Comment sections or private messages on short videos promise high cash red packets and require clicking external unknown links or jumping to unofficial app stores to download specific plugins in order to claim them.
- 🚩 The link page requires entering a mobile number and receiving an SMS verification code, while prompting that accessibility services must be enabled or installation from unknown sources must be allowed to complete the so-called red-packet withdrawal or cover activation.
- 🚩 After clicking a link or installing a related app, an unknown icon appears on the desktop and then suddenly disappears, or the phone experiences abnormal heating, a surge in battery consumption, and unknown processes running silently in the background.
- 🚩 Frequent receipt of text messages or social media private messages in a customized tone, containing exclusive forms of address with attached links urging the user to claim a red packet, where the sender's number or account is not a familiar official customer service number.
- 🚩 Phone bills show unknown value-added service charges, or SMS verification codes are frequently received without the user performing related operations, and abnormal SMS records that are automatically deleted or blocked appear in the SMS inbox.
真实案例
- On May 25, 2026, Beijing Daily reported and exposed the 'phantom billing' lurking in mobile phones: since 2025, elderly individuals browsing short videos clicked 'claim red packet,' leading users to a payment interface and ultimately completing a 'phantom charge' of 150 to 199 yuan. A reporter reproduced the entire process using the phone of interviewee Mr. Zhang's mother, finding that the ad link pointed to an unfamiliar domain name, and after clicking pages such as 'watch videos to make money, chance at 888 yuan,' the payment amounts jumped to 159 yuan, 198 yuan, and 199 yuan respectively. (Source: [https://news.bjd.com.cn/2026/05/25/11764999.shtml](https://news.bjd.com.cn/2026/05/25/11764999.shtml))
- On August 3, 2026, China News Service reported on Kuaishou Security Center's summer anti-fraud reminder: 14-year-old middle school student Shi Moumou saw 'free electronic book' diversion info on Kuaishou; after entering the group, someone impersonating public security personnel claimed he was involved in a crime requiring investigation, and he successively scanned codes to transfer a cumulative total of over 13,000 yuan. Wang Moumou added a third-party social contact, and the other party impersonated Beijing police, demanding she use her mother's phone to 'prove her innocence,' transferring 200,000 yuan to the other party's account. (Source: [https://www.chinanews.com.cn/sh/2026/08-03/10671322.shtml](https://www.chinanews.com.cn/sh/2026/08-03/10671322.shtml))
- In February 2026, Yuanbao red-packet links inducing users into high-frequency sharing went viral on social networks. WeChat authorities urgently intervened and blocked such links, restricting them from opening directly within WeChat to cut off the trojan propagation path utilized by black-industry syndicates via AI-generated personalized links within acquaintance networks.
Official Stance
- In February 2026, the WeChat Security Center issued a notice urgently blocking Yuanbao red-packet links that induced users into high-frequency sharing, restricting them from opening directly within WeChat and prompting users to be vigilant against fake red packets with external links.
- In August 2026, the Douyin platform announced the launch of the Anti-Fraud Long March, relying on upgraded AI risk control technology to jointly build an anti-telecom-fraud wall, focusing on combating AI-generated fake red-packet links and trojan propagation chains.
- In July 2026, the Ministry of Public Security announced 20 typical cases, reporting a crackdown on fabricating and spreading online rumors and using AI to generate fake videos or links for fraud, with individuals involved in multiple locations receiving administrative penalties.
How to Protect Yourself
- ✅ For any red-packet collection auxiliary application not listed on an official app store that requests the enablement of accessibility services or device administrator permissions, firmly refuse installation and immediately uninstall similar suspicious software.
- ✅ When receiving red-packet collection messages with links, be sure to verify the sender's identity and link domain name; legitimate platform red packets are distributed within the app and never require jumping to external browsers to download plugins or input verification codes.
- ✅ Regularly check mobile phone bills and bank card statements, keeping an eye out for unknown small charges or value-added service subscriptions. Once abnormalities are found, immediately contact the operator to freeze related withholding services and modify payment passwords.
- ✅ Enable the phone's built-in security protection and harassment interception functions, and conduct regular virus scans. For phones that have already mistakenly installed the trojan, data should be backed up before restoring factory settings to completely clear malicious processes hidden at the bottom of the system.