Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

NeuroWinter

@NeuroWinter@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Blog on random learning in tech: neurowinter.com

Reformed #ai / #MLOps engineer now working as an #SRE at a company that specialises in data and backing up #opensource databases and #kafka.

Long time #appsec enthusiast

Alt: NeuroWinter@tilde.zone

0 Followers
0 Following
22 Posts
Joined December 13, 2017
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
@Ajediday@infosec.exchange my cats would never ever ask my to close the door !
1
0
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
10/ which means it protects nothing. recover that key once and every payload the loader ever sealed falls open. that’s the whole lesson of the old tier: a hardcoded key buys zero confidentiality.
1
4
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
2/ the repo: 985Ming/qlk. ~99 obfuscated python + js scripts, description (translated) “Qinglong Script Library, 2025.” i cloned it and couldn’t read a single line. so now i had to. there goes my weekend.
0
1
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
4/ the obfuscation was the same trick every time: xor/base85 → zlib → a marshalled code object → exec(). runs in memory, never writes a .pyc. so it stops you reading the source, but not running it. and anything you can run, you can hook :)
0
10
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
3/ Qinglong turns out to be a webui for cron jobs. “wool farmers” (薅羊毛, pulling wool) use it to run scripts on a schedule that drain loyalty points, coupons and lottery payouts from apps, then cash out on xianyu / pinduoduo. qlk was a pile of exactly these. #Qinglong
0
11
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
5/ once i could read them i saw the targets: news sites, ads, local govt sites. and the endpoints matched across repos, same hand-rolled toolchain, different authors. qlk wasn’t a one-off. it was one corner of a whole scene.
0
1
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
7/ that DRM layer is why i couldn’t read qlk in the first place. one operator, wyourname, runs DRM-as-a-service: encrypted .so loaders + a C2 that hands out the key per machine. everyone else rents it so their scripts can’t be lifted off github. so i went after it.
0
1
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
6/ pull the thread and it’s 16 actors, 26 repos, 60+ platforms. and it doesn’t run like a friend group, it runs like a supply chain: operators write the scripts, someone rents them DRM to protect them, shared plumbing hides the bots, a WXPusher ping tells the operator when the money lands.
0
1
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
8/ two tiers. the old one: a Cython loader running a hand-ported javascript DES (you can tell, the helper fns only exist bc js >>> differs from python). i pulled the whole pipeline out of strings + exports. only missing piece was the key. #Cython #Ghidra
0
6
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
9/ almost fell for a red herring, get_key() calls md5 with a tidy 12345678 sitting right beside it. too good to be true. it was. then i remembered it’s just a python module, so i imported it and asked. it handed the key straight over. hardcoded, same 8 bytes in every build.
0
5
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
11/ then the wall. the current tier is Rust doing AES-CBC. ordinary crypto. the difference is where the key lives: never on your box, fetched per-machine from a C2 in shanghai, and the loader fingerprints your machine and POSTs it there first. score: 49 mapped, 0 decrypted. that’s the design working as intended. #Rust
0
3
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
12/ but the gut-punch wasn’t the crypto. one of the most capable operators, smallfawn, sells a JD.com login tool to other farmers, quietly wired to ship the buyers’ logins (plaintext passwords included) 3x a day to a server they control. they are, quite literally, farming the farmers.
0
2
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
13/ and the part that actually worries me: the targets aren’t just music + video apps. it’s civic + government apps and state media, a pile of them sharing one reward/lottery backend whose “unforgeable” secret is just… sitting in the client. all disclosed to vendors first.
0
2
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 3mo ago
I have been working on this series of posts in my blog. I went from a single grep.app search to finding out and driving into the rabbit hole that is the Chinese “wool farming” underground. Basically a bunch of peeps sharing scripts to defraud rewards systems in websites, from their version of Amazon (jd.com) to state media sites and local government sites. https://neurowinter.com/security/2026/06/23/a-weekend-in-the-wool/
Alex Manson

A weekend in the wool: mapping a Chinese reward-farming underground from one GitHub repo

A weekend that started with a grep.app search for leaked password prefixes and ended in a 16-actor Chinese reward-farming (薅羊毛) ecosystem: its script DRM, its C2, its credential theft, and the civic apps it targets.

0
0
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
whats this? another post on the chinese wool-farming underground, and this time the targets are state-owned media and govt-adjacent civic apps :P turns out a pile of these apps share one reward + lottery backend, and the secret thats meant to make claims unforgeable is just… sitting in the client. recover it and you can forge a valid claim the backend accepts. read-only, walked it from one github repo. part of an ongoing series. https://neurowinter.com/security/2026/07/16/forging-the-government-lottery/ #infosec #threatintel #CTI #OSINT #reverseengineering #China #security #appsec
neurowinter.com
0
0
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
I think I really want to start sponsoring a few small security conferences, so when they are thanking all the different company’s in the middle with be “thanks to ahh Neuro?”
0
0
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Was just looking into Kimi since k3 just dropped. Turns out all their memberships are sold out ! Guess I’ll have to wait for the public models https://www.kimi.com/code/
kimi.com

Kimi Code - 搭载 Kimi K3 的 AI 编程 Agent 与 CLI 工具

Kimi K3 正式上线!最高 1M 上下文,擅长编程、游戏 3D 和知识任务。在 Kimi Code(KFC)中体验 Kimi K3。Kimi Code是专为开发者打造的 AI 工具套件,配备高性能 CLI 工具与高速模型,可实现代码生成自动化,全面提升开发效率。立即体验更快速可靠的 AI 编程。

0
0
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Next post in my Wool series is now live, this time its looking at the scene as a whole, and how to perform OSINT on repos, and how trying to hide your tracks is a singal on its own! https://neurowinter.com/security/2026/07/28/the-cast-and-crew/
neurowinter.com
0
0
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
@apenwarr.ca I have never really understood MCPs. A well document and maintained API would do all of that an MCP does right ?
0
2
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
@afterdesign@infosec.exchange I had no idea about this device and now I desperately need one ! I’m always swapping cables because one does power and not data or one does data randomly etc etc such a waste of time !
0
1
0
0
Open post
NeuroWinter @NeuroWinter@infosec.exchange
· 2mo ago
Replying to
@sonic_hedgeblog@mastodon.social why does it annoy me so much that the figures aren’t centred ?!
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 10:32:42 UTC