Poisoning corporate marketing accounts? First nationwide! Police: Do not open such documents. Personnel | enterprises | poisoning

Release time:Apr 14, 2024 05:24 AM

Poison the enterprise marketing account! Have you heard of it?

It is to first launch Trojan programs to gain the trust of enterprise sales personnel, and then redirect customers within the enterprise's marketing account to overseas wire fraud groups to carry out fraud. Take a look at the case.

Case Review

In April 2023, the Cybersecurity Bureau of Hangzhou Public Security Bureau in Zhejiang Province discovered during work that multiple criminal gangs were using Trojan horse control programs to commit infringement on enterprises on online platforms.

After investigation by the police, it was found that the criminal gang obtained control over the company's marketing account through targeted online Trojan programs and offline shopping malls to gain the trust of sales personnel.


Poisoning corporate marketing accounts? First nationwide! Police: Do not open such documents. Personnel | enterprises | poisoning

Finally, they will impersonate the identity of employees of the victim company and attract their customers to overseas wire fraud groups through "attracting large groups and sending red envelopes", providing them with "gold powder" and implementing precise fraud.

Technique Analysis

There are two ways to poison, one is to target online Trojan programs:

Zhang from Hubei is usually idle. In March of this year, he saw on foreign social media that someone was publicly recruiting personnel to launch Trojan viruses. The threshold is low and the salary is considerable.

As long as you contact the staff on the company's official website, pretend to talk about business, and send files containing Trojan viruses, it is considered to be half done. If the enterprise staff opens this file, the Trojan virus can invade the enterprise, and Zhang can receive commissions.


Poisoning corporate marketing accounts? First nationwide! Police: Do not open such documents. Personnel | enterprises | poisoning

Without hesitation, Zhang started working and unexpectedly earned 100000 yuan in just one week. He immediately told his family and friends about this way of making money, so three or four people formed a small team to specialize in this matter.

Another way is to wait for an opportunity in offline shopping malls to log in to the enterprise marketing account:

Zhang is from Linquan County, Anhui Province, and is one of the local promoters of the gang. He is 27 years old this year. He himself is an unemployed wanderer who has been wandering around internet cafes and other places for years.

Last March, he signed up to participate in the "buying and selling" of this gang and formed a four person team to operate in pairs. One person is responsible for sales, while the other person takes advantage of the teller's distraction and scans the QR code with his phone to log in to the employee's corporate marketing account in the background.

As long as this step is achieved, their work is considered complete.


Poisoning corporate marketing accounts? First nationwide! Police: Do not open such documents. Personnel | enterprises | poisoning

Over the course of several months, their four member small group ran through major shopping malls across the country, first from Jiangsu to Zhejiang, and then to Guangdong, Chongqing, Shaanxi, and Hubei.

The salary has also increased from 800 yuan/account, 1000 yuan/account, to 10000 yuan per day without any account assessment. At its peak, they earned 800000 yuan per month.

While they were still dreaming of making big money, they didn't expect to be targeted by the police.

Arrest and capture

After finding out the criminal methods and chains of the gang, recently, under the guidance of the Ministry of Cyber Security and the Provincial Department of Cyber Security Corps, the Cyber Police Sub bureau, together with the Xiaoshan, Linping, Qiantang and Shangcheng Sub bureaus, went to Hunan, Hebei, Henan, Guangdong and Anhui provinces to carry out centralized network collection operations, and captured a total of 39 suspect from 7 gangs, 35 of whom were taken compulsory criminal detention measures according to law for suspected of illegally controlling the computer information system.


Poisoning corporate marketing accounts? First nationwide! Police: Do not open such documents. Personnel | enterprises | poisoning

There are over 2500 companies involved in the case nationwide, covering multiple industries such as securities investment, medical insurance, and technology education. At present, the case is still under further investigation.

This case is the first nationwide crackdown on the illegal use of Trojan horses to control computer information systems in enterprise marketing accounts. According to monitoring, after the closure of the case, the number and success rate of trojans deployed by such black and gray production gangs have significantly decreased, eliminating the network and data security risks faced by enterprises.

Next, the Hangzhou Public Security Bureau will guide enterprises in Hangzhou to carry out Trojan horse cleaning and investigation, timely eliminate risks and hidden dangers related to enterprises, and build a strong firewall for enterprise data security. And we will rely on the city wide network security notification mechanism to carry out risk warning and notification, helping enterprises comprehensively enhance their awareness of network security protection and effective anti infringement capabilities.

Police reminder


1. Don't easily open files sent by strangers, pay special attention to files in. exe/. zip/. rar/. bat format.




Poisoning corporate marketing accounts? First nationwide! Police: Do not open such documents. Personnel | enterprises | poisoning

2. It is recommended to install professional virus/Trojan protection software and check and kill it regularly.




3. If you accidentally open a suspicious file, it is recommended to exit the chat software immediately and carry out comprehensive antivirus treatment.




4. If the enterprise finds that it is controlled by Trojan horse program or data is stolen, it shall report to the police in time and actively cooperate with the police to carry out investigation and evidence collection.



Two women were stabbed to death and reported to have committed a crime 4 days before the follow-up visit for schizophrenia. Suspect of a bloody murder case in a Hong Kong shopping mall appeared in court today. Male | Last Friday | Murder case
Two women were stabbed to death and reported to have committed a crime 4 days before the follow-up visit for schizophrenia. Suspect of a bloody murder case in a Hong Kong shopping mall appeared in court today. Male | Last Friday | Murder case

According to Hong Kong's Wen Wei Po, a bloody knife stabbing case occurred at Hollywood Square in Diamond Hill last Friday. The police arrested a 39 year old man on suspicion of stabbing two young women, one of whom was stabbed over 30 times. The suspect appeared in the Kwun Tong Magistrates Court this morning. The police at the Kwun Tong Magistrate's Court temporarily charged the suspect with two counts of murder last Sunday. The suspect appeared in court this morning at the Kwun Tong Magistrate's Court. Acting Chief Magistrate Zheng Jihang, after listening to the opinions of both the prosecution and defense, decided to postpone the hearing for two weeks until 9:30 am on June 19th, waiting for two psychiatric expert reports to be obtained. The defense did not object. Zheng Jihang approved the application, and the defendant needs to be temporarily detained at Xiaolan Mental Hospital. When the suspect appeared in court, he wore black framed glasses, a light gray shirt, and camouflage green shorts, and was able to answer the judge's questions normally. accordingly

Secretary of the Provincial Party Committee: The focus of Henan's "summer harvest" has shifted to agricultural machinery in the northern region of Henan Province. | Support | Science | Organization | Province | Northern Henan | Summer Harvest | Rush Harvest
Secretary of the Provincial Party Committee: The focus of Henan's "summer harvest" has shifted to agricultural machinery in the northern region of Henan Province. | Support | Science | Organization | Province | Northern Henan | Summer Harvest | Rush Harvest

Currently, the highly anticipated summer harvest work in Henan has shifted its focus to the northern region of Henan. According to the Henan Daily client, on June 4th, Lou Yangsheng, Secretary of the Henan Provincial Party Committee, presided over a special video scheduling meeting on the "Three Summers" work in the province, listened to the situation report, analyzed and judged the situation, and arranged and deployed the next steps of work. Governor Wang Kai made specific arrangements. On the evening of May 31, 2023, in Xiafutou Village, Xuliang Town, Boai County, Jiaozuo, Henan Province, villagers braved light rain in the wheat fields to harvest wheat. Visual China Map Lou Yangsheng pointed out that the current summer harvest battle in the province has entered the decisive stage. Doing a good job in summer harvest in northern Henan Province is related to the summer grain yield and seed safety. We should focus on seizing opportunities and make every effort to organize the wheat harvesting work in the northern Henan region, minimize losses, and protect the interests of farmers to the greatest extent possible. Accurate forecasting is essential

Xinhua All Media+| Welcome home! What innovative technologies are protecting the return journey of Shenzhou 15? Spaceship | Shenzhou | Technology
Xinhua All Media+| Welcome home! What innovative technologies are protecting the return journey of Shenzhou 15? Spaceship | Shenzhou | Technology

On June 4th, the return capsule of the Shenzhou-15 manned spacecraft successfully landed at the Dongfeng landing site. Astronauts Fei Junlong, Deng Qingming, and Zhang Lu all safely and smoothly exited the spacecraft, and the Shenzhou-15 manned flight mission was a complete success. What innovative technologies are there to safeguard the return journey of Shenzhou 15 in this mission? On June 4th, the return capsule of the Shenzhou-15 manned spacecraft successfully landed at the Dongfeng landing site. Xinhua News Agency reporter Lian Zhen photographed that "the sky and the ground" ensure the high-precision return of spacecraft. For the Shenzhou series spacecraft, the return and re-entry GNC technology is directly related to the life safety of astronauts. Taking the success of this return mission as a symbol, China has comprehensively upgraded its GNC system since the Shenzhou-12 manned spacecraft, which features autonomous rapid rendezvous and docking, autonomous adaptive prediction and re-entry return guidance, and has completed a comprehensive update and replacement

The Chinese naval fleet has arrived! Assembly | Navy | Chinese Fleet
The Chinese naval fleet has arrived! Assembly | Navy | Chinese Fleet

At noon today, a Chinese naval fleet consisting of Zhanjiang and Xuchang ships arrived at the assembly area of the "Comodo-2023" multinational maritime joint exercise. It is understood that the assembly anchorage for this exercise is 3 nautical miles long and 1.5 nautical miles wide, capable of anchoring up to 50 ships. Naval vessels from various countries participating in the exercise will also arrive at the anchorage today to complete the assembly of the "Komodo 2023" multinational maritime joint exercise, which is held every two years by the Indonesian Navy. This year is already the fourth edition of the exercise. The exercise will be held from June 5th to 8th in the city of Jakarta, South Sulawesi Province, Indonesia, including the port and sea phases. In the coming days, participating navies from various countries will participate in ship reading style search and rescue exercises, maritime interception and damage management exercises, aerial exercises, and other course objectives exercises

New comment: Donkey like "morale" limit pulls US debt "bomb" fuse hard to dismantle US | debt | morale
New comment: Donkey like "morale" limit pulls US debt "bomb" fuse hard to dismantle US | debt | morale

On the evening of June 1st, the US Senate passed a bill on the federal government's debt ceiling and budget, and the flame of the US debt bomb was temporarily extinguished at the last moment. The two parties in the United States have staged an extreme tug of war over the US debt bomb. Some experts believe that the US debt crisis is the result of the reckless politics promoted by the US dollar hegemony, and the underlying cause of this crisis is the highly polarized political system of the US. Since the end of World War II, the US Congress has adjusted the debt ceiling more than a hundred times. The recurring debt crisis will not only have a catastrophic impact on the US economy and people's livelihoods, but also continuously erode the value of US dollar assets such as government credit and US bonds, bringing significant and far-reaching impacts to the global economic landscape. 【