The People's Procuratorate of Xuhui District, Shanghai charged that from February 9 to 20, 2023, Hong, together with Yang and Zhang (both handled separately), obtained the permissions of the target virtual currency website by analyzing and exploiting the Yapi remote code execution vulnerability, and then controlled the intranet server by means of horizontal infiltration and implantation of Trojans in the intranet. After finding the server source code, they downloaded and analyzed it.