河南鹤壁公安网安部门近日成功阻止了一次境外黑客的网络攻击。[1]攻击者以伪装的"合作合同"邮件为诱饵,在附件中隐藏远控木马下载器。[1]用户一旦点击附件,恶意程序便会在计算机后台自动下载安装远控木马,整个过程隐蔽难以察觉。[1]
攻击者一旦获得控制权限,即可远程操作受害计算机,窃取账号口令、个人信息和商业资料等敏感数据。[1]网警通过发现异常IP地址、识别可疑邮件附件等手段,及时帮助受害企业消除隐患。[1]近期针对中国发起的钓鱼邮件攻击多利用美国、荷兰、韩国、印度、日本等国的IP实施。[1]公安部门正对制作传播远控木马的违法行为开展进一步侦查。[1]
The Cybercrimes Investigation Unit of Henan Heibi Public Security Bureau has successfully prevented an overseas hacking attack targeting local enterprises [1]. The attackers impersonated business partners and distributed emails with attachments disguised as "cooperation contracts," which actually contained downloaders for remote control trojans [1]. Once users opened these malicious attachments, hidden programs would automatically download and install the remote access trojan in the background, making detection difficult [1]. Upon gaining control, attackers could remotely operate victim computers to steal sensitive information including login credentials, personal data, and commercial materials [1].
According to public security authorities, recent phishing email campaigns targeting China have primarily utilized IP addresses originating from the United States, Netherlands, South Korea, India, and Japan [1]. The cybercrime unit identified suspicious email attachments and abnormal IP addresses, enabling them to promptly assist affected enterprises in eliminating security threats [1]. Investigations into the illegal creation and distribution of remote control trojans are ongoing [1].
Under China's Cybersecurity Law, individuals are prohibited from conducting unlawful intrusions into networks, stealing network data, and engaging in activities that endanger network security [1]. The law further stipulates that when overseas institutions, organizations, or individuals conduct network-endangering activities resulting in severe consequences, the State Council's public security department may impose asset freezes or other necessary sanctions [1].