Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

New Variant of Short Video AI Red Packet Trojan: Impersonating Friends and Family via Voice to Plant Ghost Billing Malware

The primary victims are middle-aged and elderly individuals unfamiliar with smartphone operations, heavy users of short video platforms, and those involved in part-time 'brushing' (fake order) groups. They generally lack the ability to assess the risks of unfamiliar links and are easily lured by the prospect of small gains or trust in messages that appear to come from friends or family. Scammers exploit this psychology to induce them to click links and install so-called 'Red Packet Assistants,' ultimately leading to silent deductions from phone bills, bank accounts, or more severe financial theft.

SCAM

Key Fields

FIELD STAMPS
IndustryContent / Creator Economy
RegionChina(中国大陆)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The primary victims are middle-aged and elderly individuals unfamiliar with smartphone operations, heavy users of short video platforms, and those involved in part-time 'brushing' (fake order) groups. They generally lack the ability to assess the risks of unfamiliar links and are easily lured by the prospect of small gains or trust in messages that appear to come from friends or family. Scammers exploit this psychology to induce them to click links and install so-called 'Red Packet Assistants,' ultimately leading to silent deductions from phone bills, bank accounts, or more severe financial theft.

骗局怎么运作

  • Step 1: Create AI-generated impersonation content. Criminals use open-source AI voice synthesis tools to collect short voice clips from popular influencers or the victim's friends and family to generate 'claim your red packet' prompts. They also clone red packet pages, using interface designs highly similar to WeChat or Douyin red packets to lower the target's guard. This process is typically completed on the dark web or in encrypted groups, with a generation cost of less than 100 yuan per instance.
  • Step 2: Spread fake red packet links on short video platforms. Scammers register batches of short video accounts to post 'red packet bomb' links in the comment sections of popular livestreams, local pages, and via direct messages, using urgency-inducing tactics like 'Click to claim' or 'Last 5 minutes.' They also use AI to generate large numbers of fake 'claimed' screenshots to create a sense of authenticity and lure more users.
  • Step 3: Induce the download of a 'Red Packet Tool' app. When users click the link, they are not taken to a claim page but are instead prompted to download an Android installation package named 'Red Packet Assistant' or 'Accelerated Claim.' The page claims that 'security components must be installed to verify the red packet.' In reality, the APK is embedded with a ghost billing Trojan that requests permissions to read SMS, contacts, and display over other apps during installation.
  • Step 4: Ghost billing and silent theft. Once installed, the Trojan hides its desktop icon and monitors system notifications and SMS in the background. When the user uses WeChat, Alipay, or banking apps, the Trojan simulates clicks and reads verification codes to complete small, password-free payments or subscribe to high-priced value-added services without the user's knowledge. Each deduction typically ranges from tens to hundreds of yuan.
  • Step 5: Data theft and secondary monetization. The Trojan continuously collects sensitive information such as the user's contacts, SMS verification codes, and bank card numbers, uploading them to the attacker's server via remote commands for subsequent targeted fraud or sale on the black market. Some Trojans use AI voice synthesis to contact the victim's friends and family using the victim's own voice, further spreading the 'red packet bomb' links in a pyramid-scheme-like fashion.

红旗信号(看到这些快跑)

  • 🚩 The domain name of the red packet link does not match the official one, often consisting of random numbers and letters or using cheap top-level domains, and cannot be opened directly within WeChat.
  • 🚩 Claiming the red packet requires downloading a standalone app and enabling 'install from unknown sources,' whereas legitimate payment platforms do not require additional app installations for red packets.
  • 🚩 The red packet page is filled with exaggerated amounts like '888 yuan' or '199 yuan,' but requires multiple prerequisites such as sharing, filling out forms, or downloading apps before claiming.
  • 🚩 The installation package name is unrelated to the red packet, such as 'com.pay.update' or 'Red Packet Assistant,' and requests high-risk permissions like SMS, call logs, and location during installation.
  • 🚩 After clicking the link, the phone displays prompts about automatic SMS subscriptions, personal information being read, or the user receives billing notifications from their carrier.
  • 🚩 The AI-synthesized voice or video lip-sync does not match the sound, the voice has a noticeable mechanical quality, and the content includes instructions like 'click the link' or 'claim the red packet.'

真实案例

  • On May 25, 2026, Beijing Daily reported that an elderly person (Mr. A) received a 'claim red packet' link on a short video platform; after clicking it, 199 yuan was deducted from their phone. Investigation confirmed the link induced the installation of a Trojan app capable of 'ghost billing,' which initiated small deductions without the user's knowledge. (Source: https://news.bjd.com.cn/2026/05/25/11764999.shtml)
  • Around the 2026 Spring Festival, CCTV reported that criminals were mass-sending 'click link to claim 888 yuan red packet' messages on short video platforms, inducing users to download fake apps. Some users experienced abnormal pop-ups and billing SMS after clicking. CCTV warned the public not to trust such red packet links. (Source: https://news.bjd.com.cn/2026/05/25/11764999.shtml)
  • On August 4, 2026, Guangming Online reported that cyber police intercepted an overseas phishing attack using 'cooperation contract' documents to spread remote-control Trojans. This attack, like the red packet bomb, is a download-and-execute Trojan scam; once infected, the Trojan can control the phone's camera, read SMS, and steal funds from accounts.

Official Stance

  • On August 3, 2026, the Kuaishou Security Center issued a summer anti-fraud reminder via China News Service, warning users to be vigilant against six types of fraud involving minors, such as 'red packet rebates,' and emphasizing not to click on unfamiliar links.
  • On July 23, 2026, the Ministry of Public Security announced 20 typical cases of cracking down on the fabrication and spread of online rumors, many of which involved using AI tools to generate fake content for fraud, with those involved receiving administrative penalties.
  • On February 4, 2026, WeChat responded to the 'Yuanbao red packet link blocking' issue, stating that it had restricted links containing induced sharing and security risks from being opened directly within WeChat and reminded users to be cautious.
  • The National Computer Network Emergency Response Technical Team (CNCERT) issued a cybersecurity warning on July 27, 2026, regarding the new trend of using AI technology to spread malicious links.

How to Protect Yourself

  • ✅ Do not click on unfamiliar red packet links in short video comment sections or direct messages, especially 'red packet tools' that require app downloads. Stick to the rule: if you have to install an extra app to claim a red packet, don't do it.
  • ✅ Keep the 'install from unknown sources' setting on your phone turned off and only download software from official app stores. Refuse any app that requests sensitive permissions like SMS or contacts during installation.
  • ✅ Disable password-free small payments in payment platforms and banking apps, and enable features like nighttime locks or location-based locks to reduce the possibility of silent theft by Trojans.
  • ✅ If you notice abnormal charges or SMS messages being intercepted, immediately disconnect from the network, enable airplane mode, call your carrier to suspend SMS services, and use security software to scan for and remove Trojans.
  • ✅ When receiving 'claim red packet' messages from friends or family via voice or video, verify their identity through a second channel such as a phone call or in-person meeting. Be wary of AI-synthesized voices impersonating acquaintances.