Security Alert Notice on Preventing the

Recently, the National Computer Virus Emergency Response Center issued an early warning. Monitoring has revealed that the "Silver Fox" Trojan, which specifically targets users in China, has emerged with new variants. Attack activities are currently highly active, characterized by a wide scope of dissemination, strong concealment, and rapid mutation. To safeguard campus network and information security, and to protect the personal information and property of our faculty and students, please take note of the following reminders:

 

1. What is the "Silver Fox" Trojan?
The "Silver Fox" Trojan (also known as "YouShe," "GuDuo Thief," or "Silver Fox") is a remote access trojan (RAT) that has been active for years and primarily targets Chinese internet users. The virus continuously iterates and updates, lurking in everyday scenarios such as office work, social communication, and email transmission, waiting to strike. Once a user accidentally executes the malicious program, attackers can gain remote control, steal sensitive information, and even use the compromised device as a "stepping stone" for telecom and online fraud.

 

2. Key Features of the New Variant
The newly discovered variant continues to employ phishing tactics, heavily utilizing deceptive file names related to human resources. Common names include "Q[X] Disciplinary List," "Personnel Notice," "Layoff List," and "Compensation Plan." The icons are disguised as folders, shortcuts, or the Recycle Bin, and some even add a ".pdf" extension to deceive users. These files are highly misleading; all faculty and students must remain highly vigilant.

 

3. Primary Vectors of Transmission

Phishing Emails: Attackers send emails disguised as school notices, grade inquiries, scholarship disbursements, or salary/performance payouts to trick users into downloading infected attachments.

 

Social Platforms: Via platforms like WeChat, QQ, DingTalk, and Feishu, malicious files with deceptive names are sent. These messages often use coercive or intimidating language such as "Please check immediately," "Important! Action required," or "Consequences for late response" to lower users' guard.

 

Fake Website Downloads: Using automated technology, attackers mass-register fake domains to build highly realistic software download pages. They impersonate official sites for popular software like Chrome, WPS, Tencent Meeting, and Sunlogin, tricking users into downloading malware-laced installers.

 

Workgroup Propagation: Attackers infiltrate work and industry groups to share malicious files or links. Once infected, compromised devices automatically send infected files to group chats or contacts via social software without the user's knowledge, creating a chain reaction.

 

4. Daily Preventive Measures
To effectively prevent "Silver Fox" infections, all faculty and students are required to strictly follow these guidelines:

Do not trust, click, or download blindly: Maintain high vigilance toward emails, messages, links, and attachments from unknown sources. Never click, download, or execute them at random. If you receive suspicious files like "Disciplinary Lists," "Layoff Compensation," or "Notices," verify them through official channels first.

 

Install and enable antivirus software: Install legitimate antivirus software on your computer, keep real-time protection enabled with automatic database updates, and perform regular full-system scans.

 

Standardize software download channels: Download all software exclusively through official websites or trusted app stores. Strictly avoid clicking non-official links in search engines or downloading from unverified sources.

 

Update system and software patches promptly: Regularly upgrade operating systems, browsers, and office applications. Install official security patches immediately to prevent attackers from exploiting known vulnerabilities.

 

Strengthen account and data protection: Change passwords regularly and ensure they are highly complex. Back up important data frequently to prevent loss or ransomware encryption.

 

Beware of hidden extensions and identify disguised files: Enable the "File name extensions" feature in your system (Path: This PC → View → Check "File name extensions") to accurately identify file types. If a file appears to be "Word" or "PDF" but actually ends in executable extensions like .exe, .bat, .cmd, .vbs, or .scr, it is definitively malicious and should be deleted immediately.

 

Upload suspicious files for collaborative analysis: You can upload suspicious documents, executables, or compressed files to the National Computer Virus Collaborative Analysis Platform (https://virus.cverc.org.cn) for security testing.

 

5. Emergency Response Guide
If you notice anomalies such as system lag, excessive pop-ups, or social accounts sending messages automatically, or if you confirm a Trojan infection, please take the following steps immediately:

 

Disconnect from the network instantly: Unplug the Ethernet cable and turn off Wi-Fi immediately to cut off the connection, preventing further spread and data exfiltration.

 

Report promptly: Contact the Information Technology and Data Intelligence Department right away, detailing the device status and the time of the anomaly, and cooperate with technical staff for investigation and handling.

 

Change passwords urgently: Use an uninfected phone or computer to immediately change passwords for critical accounts, including unified identity authentication, email, social media, and payment apps.

 

Perform deep virus scanning: Update your antivirus database and conduct a full-system deep scan. If the virus cannot be removed, back up essential data and reinstall the operating system.

 

6. On-Campus Contact & Support
If you discover any cybersecurity issues or need assistance, please contact the Information Technology and Data Intelligence Department at gzit@hkust-gz.edu.cn or call 020-88330101.

 

Cybersecurity is no small matter; everyone is a guardian. All faculty and students are urged to actively enhance their cybersecurity awareness and jointly build a solid defense line for campus network security.

 

Information Technology and Data Intelligence Department (ITDID)

June 11, 2026