Xinhua News Agency, Hangzhou, August 4th. Title: You "clean your fans" and it "invades" you-be careful! WeChat "Clear Fans" Hidden Risks

  Xinhua News Agency reporters Zhang Xuan and Hu Linguo

  "The system is detecting the person who deleted me, please don't return" "Please forgive me for clearing fans. Follow the official account to check for free"... Currently, many WeChat users choose to use the "Friend Cleanup Service" to control the number of their WeChat friends. A reporter from Xinhua News Agency discovered that such "fan cleaning" services have hidden significant risks, which may lead to loss of control and theft of users' WeChat accounts, and in serious cases may also lead to the leakage of important personal information and online fraud.

Reporter's experience: Wechat account has been "recruited"!

  Mr. Liu, a citizen of Guangzhou, told reporters that not long ago, to clean up his WeChat friends, he tried to use the "cleaning fan" service, which has caused him a "headache" so far.

  "My account automatically posted advertisements under all the likes in the circle of friends, and strangers constantly invaded my WeChat workgroup and posted advertisements in it. Some of my WeChat friends were also harassed." According to Mr. Liu's recall , These situations all happened after he scanned the QR code sent by him according to the requirements of the "cleaning fans" service business.

  "Don't tell me that my WeChat group and circle of friends are smoky. It would be too dangerous if someone pretends to find me to find WeChat friends to cheat money." In order to prevent colleagues and friends from being deceived, Mr. Liu had to contact everyone on WeChat one by one. Explanation.

  The reporter searched on a well-known e-commerce platform and found that there are many online stores selling "fan cleaning" services, and the unit price is mostly 1 to 3 yuan. According to online store data, some monthly sales are as high as 100,000 orders. There are also a large number of WeChat public accounts that provide such services, some of which claim to be able to "0 mistakenly delete and 0 missed" and "Wuhen Qingfen".

  The reporter chose a business that claimed to provide "green powder cleaning" service. The merchant asked the reporter to add a WeChat ID provided by him as a friend and scan the QR code sent by the account. After completing the requirements, the reporter saw the prompt "WeChat is about to log in through a remote iPad". According to the requirements of the business, the reporter authorized and confirmed the prompt. Immediately, the reporter's WeChat began to pop up the cleared friends' business cards. After a few minutes, a message prompts that the cleanup is complete.

  However, shortly after the "cleaning of fans", the reporter found that after being directly added as friends by strangers, he was drawn into various advertising WeChat groups frequently, and WeChat was forced to go offline repeatedly. Cyber ​​security experts told reporters that the reporter’s WeChat account may have been out of control.

One more "eat": the chain of interests behind the "cleaning powder" service

  According to Xu Chao, an information security expert, the principle of "cleaning fans" is to control the WeChat account to be cleared through the application of cluster control software, so that the account will automatically send messages to all of its friends, and then the group control software will determine whether the information can be successfully sent and received. "To identify which of them are "zombie fans" and delete them.

  But in addition to clearing fans, the group control software can also control the WeChat account to batch like content in Moments, send WeChat messages in groups, and automatically approve friends to add and reply. According to the WeChat security team, once a user agrees to use group control software to "take over" the account, the account is likely to get out of control. Not only will your personal privacy be completely exposed to others, such as work, identity, contact information, social relations, financial information, etc. may also be obtained by others.

  The reporter's investigation found that there is an illegal interest chain behind the "cleaning fans" service.

  Some people make money by developing such software. The reporter found on the Internet that many websites can customize powder cleaning software, and it shows that there have been successful orders. The development price of a single powder cleaning software ranges from 1,000 yuan to 5,000 yuan. The reporter learned from a software agent developer on an e-commerce platform that the development cost and technical threshold of such software are not high, and agent development is not difficult.

  There are also criminals who use "recommend friends, clear fans for free", "repost to groups, give gifts" and other methods to entice users with unknown circumstances to spread "accesses" such as "clear fans" links and QR codes to their WeChat groups, In the circle of friends, to achieve "viral" transmission and expand the scope of "in the recruitment" crowd.

  According to industry insiders, there are many ways for criminals to "eat" for users who are "successfully recruited": first, they earn money from selling powder cleaning services. Xu Chao told reporters that many shops operating related businesses have a large monthly transaction volume, and some businesses have monthly sales exceeding 10,000 yuan.

  Then, by controlling the user's WeChat account, you can distribute various marketing and advertising information everywhere, and then make a fortune. According to industry insiders, some "black merchants" that distribute "small advertisements" and create "psoriasis" under the guise of "integrated online marketing" and "interpersonal promotion" on the current Internet platforms are mostly related to such illegal activities.

  Then there is the theft of the personal information of the victimized users and selling them for profit. Netizen Ms. Huang reported that after using the "fan cleaning" service in May this year, she quickly discovered that there was a transaction on WeChat that she did not know about, and the other party was an online game. Then she discovered that in this online game that she had never contacted, she actually had her own real-name registered account. Ms. Huang suspects that her personal information has been stolen by the "Clean Fan" software.

  Xu Chao said that the current "fan cleaning" service has become an important "upstream" of the illegal data transaction industry chain. Data captured through related software is usually traded through the information "underground market" after being classified. The reporter learned that the Hangzhou Internet Court not long ago heard and pronounced a case in which the software "Clean Fan" was used to steal personal information.

Official WeChat: Fan cleaning service, don't use it!

  According to the data provided by the WeChat team, as of the end of June 2020, WeChat has imposed short-term or permanent restrictions on millions of accounts that explicitly use "cleaning fans" software and other plug-in accounts.

  "Although WeChat officials continue to crack down on it, it may not be easy to eradicate infringement of'cleaning powder' software." The technical director of a technology company in Guangzhou believes that technically, illegal developers are constantly developing multiple framework technologies, underlying instructions and WeChat security. The team "plays guerrilla"; in terms of sales, some businesses package such software as "robot assistants", which makes the platform difficult to understand.

  Li Yang, a visiting researcher at Guangzhou University, said that individual users should raise their awareness of the security protection of personal information and data permissions, and be vigilant against strangers and unfamiliar applications on the Internet, and do not be greedy for petty gains.

  Hu Qimu, a senior researcher at the think tank of the digital economy, believes that network platform operators should further strengthen their awareness of performing the security protection duties of Internet service providers, and make good use of artificial intelligence, big data and other technical risk control methods to ensure the "green space" on the platform, starting from the source Prevent the spread of such risks.

  Zang Lei, a senior researcher at the International Center for Internet Rule of Law, Beijing Normal University, reminded that some "cleaning fans" software and service providers are suspected of infringing on citizens' personal information, telecommunications fraud and other criminal activities, and the risks are huge. The platform should highlight such services or content to remind users "Don't blindly authorize any third party to prevent privacy leakage."

  "This is not a platform that can be completely governed by itself. E-commerce platforms should also actively assume joint governance responsibilities and strengthen the identification and supervision of merchants with high-risk commodities." iiMedia Consulting CEO Zhang Yi said.

  The WeChat security team reminds users not to use plug-ins and software that break the WeChat software protocol or have plug-in functions. In case of security risks, complaints can be made through the WeChat client or Tencent 110 applet.

related news:

  Rent WeChat to make money? Use "vest" to cheat people!

  WeChat red envelopes are also fake, don't be greedy for small profits and suffer big losses