QQ以及微信内藏危险的木马软件 难清除

作者:8288  于 2017-9-18 15:12 发表于 最热闹的华人社交网络--贝壳村


What to Make of the Explosive New WeChat and QQ Spying Revelations?

Safeguard Defenders, September 10, 2017


saveguard defenders _ a project by


A new report by a Lookout, a Cybersecurity company, has generated renewed interest in the security, or lack thereof, of WeChat and QQ (https://blog.lookout.com/xrat-mobile-threat). Despite this, there has been limited attention paid to this explosive new revelation.

It has long been known that due to WeChat keeping its servers inside China, the lack of legal protection of privacy data, and the control over companies by police, that WeChat data is not safe, and can, without protection, be accessed by police or other state actors more or less at will. This has naturally made people shy away from using WeChat for any more serious or political discussions. More and more court cases of people being prosecuted simply based on private chat messages to friends have further illustration this. At the same time, at the time of the Occupy Central movement in Hong Kong, it was shown that a ‘Trojan’ virus was being employed to surveil users remotely.

xRAT. That’s the name of the new discovery. Like the earlier virus found, it’s a ‘Trojan’ virus, meaning it masks itself as something else, for example a PDF file, and you will be unaware of if you have it on your phone by now. It specifically targets you through your WeChat or QQ account.

So what’s the big deal?

The ‘Trojan’ operates with administrator privileges. It means it can access and control any and all aspects of your phone. It also means it can do so without you noticing. In fact, it can remotely get ‘full control’. If you want to understand what this means it is this: it has as much access to your phone as if you were to give it to someone, and then tell them your PIN code. Full control.

This means that not only your WeChat or QQ use is exposed. All of your phone is exposed. Photos stored, downloads, documents, any Apps to other services installed, chat logs, phone records, contact lists, and of course, your browser and its entire browsing history, which may include credit card and password and login information to other service, for example encrypted emailing you use.

In short, any phone that has WeChat on it, and is also used to access work emails, or secure chat programs like Telegram or Signal, can now be in the hands of Chinese police or state security. For the community of supporters of human rights in China it moves from bad to terrible. You can now, if you communicate with human rights defenders in China through secure Apps or emailing on a phone that has WeChat or QQ installed, inadvertently be giving the Chinese police material that will incriminate those human rights defenders and land them in prison.

To make matters worse, administrator privilege means you microphone can be turned on, and stream whatever is heard to the Chinese police. Same with video camera and camera. It is a most sophisticated spying tool with far-reaching consequences. It can, it goes without saying, read you location, as well as the specific meta-data of your phone.

If that wasn’t enough, there is one last thing, which makes it such a sophisticated virus. It can auto destruct itself. And when doing so, it can not only delete itself from your phone, but wipe much of your phone log data, making it hard even for technically skilled people to know that the virus was ever there. In short, you might never know if your phone, your use, is the reason someone has landed in prison.

A number of control centers in China has been identified to where such data and traffic goes. The code is such that there is little doubt that this ‘Trojan’ comes from the same people behind the earlier ‘Trojan’ targeting Hong Kong Occupy Central people, just much more sophisticated.

Should I worry? What to do?

First off, there is still some lack of understanding how the infection spreads to your phone. At the same time, there is little reason to think resources would be spent to develop such a tool, and then not try to use it. An earlier, much less sophisticated version, was used extensively during the Occupy Central movement. Why would the police and state security organs not use a tool if it’s already been developed, and if it’s this powerful? It should go without saying that you need to operate as if it’s being used widely, and as if you were a target.

Most people with risk awareness will already have made sure to not use WeChat or QQ, or if they felt a strong need to have it, have it installed on a second phone which is not used for anything else. If you need WeChat, like many unfortunately feel they do, at the very least, install it on a blank, factory-reset second phone, like a super cheap android phone. Due to microphone remote control, make sure to never have it in your office or at any discussions.

Secondly, your current phone, if infected, will not be secure just by uninstalling WeChat and QQ. You will have no choice but to do a factory reset. This may be an inconvenience, but it is the only way. It goes without saying that any existing PIN codes, passwords to work emails, etc., will need be changed after you have done this factory reset.




From the editors:

Since this post was launched, we have heard several complaints such as this one: “the article misrepresents the malware report, which does not mention WeChat or QQ as delivery method, but instead as targeted data.” It is true that the threat is posed by a ‘Trojan’ virus, an external program designed to utilize weaknesses through WeChat and QQ. The vulnerability begins when the xRAT “Trojan” has infected your phone, and the “Trojan” aims at infecting those using WeChat or QQ. The WeChat and QQ programs themselves do not contain the “Trojan.” The silent mode in which it can operate nonetheless makes it hard to know if your phone has been infected. The mode of infection, for example through having downloaded and opened a PDF or other type of file, continues to be studied and the mode of infection is not yet clear.






微信的服务器在中国大陆,那里缺少对私人数据的法律保障,公司处于公安的控制下,所以微信的数据没有安全保障,随时可以被警方或其他政府部门监控以及浏览。这是早已为人所知的事实。因此很多人在进行政治或比较严肃的讨论时都不再使用微信。在越来越多的法庭案件中,一个人被起诉仅仅是基于和朋友的私密聊天记录,这也证实了微信是不安全的。与此同时,在香港占中运动期间,一种 “特洛伊”木马病毒被用来远程监视用户。













原文连接 https://chinachange.org/2017/09/10/what-to-make-of-the-explosive-new-wechat-and-qq-spying-revelations/









刚表态过的朋友 (4 人)

发表评论 评论 (4 个评论)

8 回复 徐福男儿 2017-9-19 03:24
7 回复 8288 2017-9-19 03:40
徐福男儿: 最好办法是不要在手机上玩微信,八哥,是这样吗?
7 回复 前兆 2017-9-24 21:16
6 回复 8288 2017-9-25 05:54
前兆: 在电脑上安装微信,也会这样吗?

facelist doodle 涂鸦板

您需要登录后才可以评论 登录 | 注册

  1. 究竟是省水馬桶還是「漏水馬桶」 [2020/10]
  2. 在美国65岁以上可以享受这么多福利 [2016/06]
  3. 一个新上海人的观察 [2020/09]
  4. 你适合养什么狗?不同品种狗狗性格、特点大揭秘 [2021/04]
  5. 在白牆創作逼真畫作 [2021/04]
  6. 疫期返中難 南加網紅分享攻略…錯一步就無法登機 [2021/08]
  7. 北美超市里那些看不懂的Cheese种类及吃法 [2016/01]
  8. 免费看电影电视剧的19个网站:最新在线电影热播剧 [2021/04]
  9. 空气炸锅究竟好不好用?炸锅评测告诉你 [2019/11]
  10. 看清美國超市那些令人目眩的牛奶! [2016/08]
  11. 28种超实用的美国家庭常备药 [2017/05]
  12. 美国华人注意了! 这些你常在自家后院做的事万万碰不得... 一不小心就吃上罚单! [2019/09]
  13. 再来说在美国如何看免费的中文电视 [2016/01]
  14. 逛旧金山湾区9个风情小镇 [2016/05]
  15. 華人濫用福利遭調查被遣返 [2018/01]
  16. 我们回不了中国了......... [2019/09]
  17. 外國上海人: “作孽,外國待久了,人戇掉了。” [zt] [2010/06]
  18. 穷人为什么怀念毛泽东,富人为什么崇拜毛泽东,一些人为什么疯狂吹捧毛泽东? zt(转载 [2010/04]
  19. 百年中国三大怪胎:义和团、红卫兵、爱国贼 [2020/03]
  20. 金曲情牽半世紀演唱會 [广东话] [2012/05]
  21. 欢迎新朋友春苗 ( 季家凰 ) [2010/04]
  22. 久违的朋友你在何方? [2011/11]
  23. 毕业了 [2012/06]
  24. 狼心狗肺 的东西 [2023/06]
  25. 大家都该忏悔 [2024/03]
  26. 说一下美国这里的一个新的现象 [2023/10]
  27. 清零三年的代价 [2023/05]
  28. 所谓的台湾问题是大陆一面之词 [2023/01]
  29. 《評馬英九的避戰與謀和》 [2022/10]

关于本站 | 隐私政策 | 免责条款 | 版权声明 | 联络我们 | 刊登广告 | 转手机版 | APP下载

Copyright © 2001-2013 海外华人中文门户:倍可亲 (http://www.backchina.com) All Rights Reserved.

程序系统基于 Discuz! X3.1 商业版 优化 Discuz! © 2001-2013 Comsenz Inc. 更新:GMT+8, 2024-3-25 18:06

