Fake ‘Cooperation Contract’ Email Used to Deliver Remote-Control Trojan in China

Dragon Media News Desk
Cybersecurity police in Hebi, Central China’s Henan Province, have intercepted a remote-control Trojan downloader concealed in a fake “cooperation contract” email sent to a local company.
According to information released by China’s Ministry of Public Security on Tuesday, IP addresses located in countries including the United States, the Netherlands, South Korea, India and Japan have frequently been used in recent phishing attacks targeting China.
During routine cybersecurity monitoring, the cyber police department of the Hebi Public Security Bureau detected repeated overseas attacks against an IP address within its jurisdiction. The activity created a risk that network equipment could be remotely controlled and corporate data exposed.
Police immediately launched a technical investigation and, after several rounds of verification, identified the company targeted by the attacks.
Cybersecurity officers then visited the company to inspect its computers and network systems. During questioning, a company representative recalled receiving an email from an unknown sender claiming to concern a potential business partnership.
The email contained an attachment named “cooperation contract.” Although the file was downloaded, it could not be opened.
A technical examination confirmed that the attachment was not an ordinary contract document but a disguised remote-control Trojan downloader.
Once opened, the malicious file was designed to automatically download and install a remote-control Trojan in the background without drawing the user’s attention, making the attack difficult to detect.
After obtaining control privileges, attackers could remotely operate the affected computer, steal account credentials, passwords, personal information, commercial data and other sensitive material.
The compromised device could also be used as a gateway to launch attacks against other networks and computer systems.
Following the discovery, local cyber police conducted a comprehensive security inspection of the company’s network and equipment. Officers advised the company on strengthening its cybersecurity safeguards and assisted in repairing identified system vulnerabilities.
The cybersecurity department of the Hebi Public Security Bureau is continuing its investigation into suspected illegal activities linked to the creation and distribution of the remote-control Trojan.





