Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Short Video AI Red Packet Trojan Scam: Forged Red Packet Links Inducing Remote Access Trojan Installation

The victims are primarily internet users in third- and fourth-tier cities and the elderly, who lack the ability to discern the legitimacy of promotional activities on short video platforms. They are often lured by gimmicks such as 'Spring Festival subsidies' or 'platform anniversary red packets' worth hundreds of yuan, exploiting their tendency to seek small gains. Unfamiliar with smartphone permission management, they easily follow prompts to download installation packages from non-official app stores after clicking links, ultimately leading to personal privacy leaks and unauthorized fund transfers.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionChina(全国)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The victims are primarily internet users in third- and fourth-tier cities and the elderly, who lack the ability to discern the legitimacy of promotional activities on short video platforms. They are often lured by gimmicks such as 'Spring Festival subsidies' or 'platform anniversary red packets' worth hundreds of yuan, exploiting their tendency to seek small gains. Unfamiliar with smartphone permission management, they easily follow prompts to download installation packages from non-official app stores after clicking links, ultimately leading to personal privacy leaks and unauthorized fund transfers.

骗局怎么运作

  • Scammers use AI tools to generate fake red packet pages featuring logos of well-known platforms in bulk. They distribute links promising hundreds of yuan in cash via short video comment sections or private messages, exploiting the public's lowered guard during holidays.
  • After clicking the link, users are redirected to a highly convincing page that mimics the withdrawal process of legitimate platforms. It prompts users to complete identity verification or download a 'dedicated plugin' to withdraw funds, inducing them to install packages named 'Red Packet Assistant' or 'Withdrawal Patch'.
  • The installation package is actually a remote access Trojan (RAT) or banking Trojan. During installation, users are prompted to grant high-risk permissions such as Accessibility Services and floating windows. Once authorized, the Trojan lurks silently and secretly intercepts SMS verification codes, payment passwords, and bank card information.
  • The Trojan also accesses the user's contact list and uses the hijacked account to send the same red packet links to friends and family, creating a viral spread. Some advanced Trojans can automatically intercept and forward bank transaction SMS messages in the background, leaving victims unaware while their funds are being stolen.
  • Scammers receive sensitive data transmitted back to their servers in real-time, allowing them to quickly log into the victim's online banking or third-party payment accounts to launder money, or sell the personal information to other cybercriminal groups, completing the fraud cycle.

红旗信号(看到这些快跑)

  • 🚩 The link domain may mimic a legitimate platform, but the suffix is often an uncommon or unofficial domain containing random characters, rather than the official domain of the short video platform.
  • 🚩 Clicking the red packet link prompts the download of a third-party installation package from outside an app store, and requests Accessibility Service permissions under the guise of 'upgrading a plugin' for withdrawal.
  • 🚩 The page often uses countdowns or 'limited quota' claims to create a sense of urgency, and may trigger security warnings or be blocked when opened within WeChat or other legitimate social apps.
  • 🚩 The installation package lacks an official digital signature, has a small file size, yet requests high-risk permissions unrelated to withdrawals, such as reading SMS, accessing contacts, or using Accessibility Services.
  • 🚩 The withdrawal page requests sensitive information like bank card numbers, ID numbers, and payment passwords, far exceeding the scope of normal red packet activities, which typically only require a phone number or platform account binding.

真实案例

  • According to CCTV, during the Spring Festival, scams involving '888 yuan red packets' appeared in many regions. Victims clicked links in SMS or short video comments and were induced to download installation packages, resulting in Trojans being implanted and bank funds being rapidly stolen.
  • In August 2026, police in multiple regions reported a phishing case involving remote access Trojans hidden in cooperation contracts. Scammers used a similar mechanism to send forged files; once downloaded, the devices were remotely controlled, mirroring the mechanism of the red packet Trojan.
  • In February 2026, the 'Yuanbao' platform was blocked by WeChat for inducing users to share red packet links frequently, with WeChat restricting direct access within its app. Such viral sharing mechanisms are often exploited by cybercriminals to funnel users to Trojan download pages.
  • In June 2026, the Linghu Police Station of the Huzhou Nanxun District Public Security Bureau in Zhejiang Province dismantled a telecom fraud gang using 'dating and task-brushing' as a lure. The victim transferred money 66 times, losing over 10,000 yuan. Police arrested gang members in other provinces, revealing a new fraud chain involving short video traffic redirection and group-based task-brushing. (Source: https://hznews.hangzhou.com.cn/shehui/content/2026-06/05/content_9234454.htm)
  • In May 2026, police in Korla, Xinjiang, intervened to stop an 'AI learning' payment scam. Ms. Zheng saw an 'AI learning registration portal' on a short video platform claiming an 88 yuan entry fee. She was nearly defrauded of over 610,000 yuan in retirement savings, but the Sayibage Street Police Station intercepted the transfer in time, saving all her funds. (Source: https://m.thepaper.cn/newsDetail_forward_33111224)

Official Stance

  • On August 3, 2026, the Kuaishou Safety Center issued a summer warning, cautioning against six types of scams targeting minors, including fake welfare links used to induce Trojan downloads.
  • In 2026, the Ministry of Public Security announced several typical cases, noting that over 170 cases involving the use of AI tools to generate online rumors and fraud were investigated in the first half of the year, emphasizing the dangers of AI-generated fake links.
  • On February 4, 2026, WeChat officially responded by blocking red packet links from platforms like Yuanbao that induced frequent sharing, restricting them from being opened directly within WeChat to prevent users from being redirected to external risky pages.

How to Protect Yourself

  • ✅ Do not click on any red packet links sent in short video comment sections or private messages. Always claim platform red packets directly within the official app; never withdraw funds via external links.
  • ✅ Keep mobile security software enabled and updated to block high-risk app installations. Strictly refuse to download apps from non-official app stores and do not install packages from unknown sources.
  • ✅ Disable the 'install from unknown sources' permission in system settings. If a so-called 'withdrawal plugin' requests Accessibility Services or floating window permissions, uninstall it immediately and run a virus scan.
  • ✅ If you have accidentally clicked a link and installed an app, disconnect from the network immediately, perform a factory reset on your phone or take it to a professional service center, and promptly change your linked bank and payment passwords.