I haven't checked the Chinese Threat Intelligence places in awhile. I said, "Hmph, I wonder what's going on over in Mandarin city" (I don't know any cities in China, so I make up names).
I checked out Rising (็ๆ), they do technical write-ups about malware hitting China, and stuff, because they're ... headquartered in China. They're a Chinese company.
Anyway:
> be me
> open rising blog
> all mandarin
> damn i wish i could read
> translate page
> supply chain attack
> wtf.jpeg?
> AutoGLM hit
> wtf.mp4?
> Chinese AI agent thingie
> made by Z ai
> (idk wtf that is)
> GitHub for AutoGLM compromised
> download link replaced with malware payload
I said, "What the fuck? You guys have premium AI slop too? You guys have nerds attacking your supply chains too?"
Wow, we have so much in common
I checked out Rising (็ๆ), they do technical write-ups about malware hitting China, and stuff, because they're ... headquartered in China. They're a Chinese company.
Anyway:
> be me
> open rising blog
> all mandarin
> damn i wish i could read
> translate page
> supply chain attack
> wtf.jpeg?
> AutoGLM hit
> wtf.mp4?
> Chinese AI agent thingie
> made by Z ai
> (idk wtf that is)
> GitHub for AutoGLM compromised
> download link replaced with malware payload
I said, "What the fuck? You guys have premium AI slop too? You guys have nerds attacking your supply chains too?"
Wow, we have so much in common
๐77๐คฃ18๐ฅฐ12โค5๐3๐1๐1
vx-underground
I haven't checked the Chinese Threat Intelligence places in awhile. I said, "Hmph, I wonder what's going on over in Mandarin city" (I don't know any cities in China, so I make up names). I checked out Rising (็ๆ), they do technical write-ups about malwareโฆ
More information:
(the link is cooked, it's in Mandarin so it's really, really, really long)
https://rayblog.rising.com.cn/2026/06/%E4%BE%9B%E5%BA%94%E9%93%BE%E6%94%BB%E5%87%BB%E7%9B%AF%E4%B8%8Aai%E5%85%AC%E5%8F%B8%ef%bc%9a%E6%99%BA%E8%B0%B1ai%E8%BE%93%E5%85%A5%E6%B3%95%E5%AE%98%E7%BD%91%E4%B8%8B%E8%BD%BD%E9%93%BE%E6%8E%A5/
(the link is cooked, it's in Mandarin so it's really, really, really long)
https://rayblog.rising.com.cn/2026/06/%E4%BE%9B%E5%BA%94%E9%93%BE%E6%94%BB%E5%87%BB%E7%9B%AF%E4%B8%8Aai%E5%85%AC%E5%8F%B8%ef%bc%9a%E6%99%BA%E8%B0%B1ai%E8%BE%93%E5%85%A5%E6%B3%95%E5%AE%98%E7%BD%91%E4%B8%8B%E8%BD%BD%E9%93%BE%E6%8E%A5/
๐คฃ40โค4๐1
vx-underground
> steam malware stuff > all the click bait places screaming > malware from wallpaper engine > don't cite original article > from Kaspersky Dawg, these Threat Actors targeted true degenerates. Look at this malware payload. This is seriously one of the maliciousโฆ
Telegram nerds missed it, but some dumb fucks on X were discussing malware on Steam wallpaper engine, but no one cited the fucking source, provided images, or malware sample goopies. I looked into it, and it's legit, it's from Kaspersky. I called them mean words (I wasn't mad, I'm just passionate and at the time I was hungry).
https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/
https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/
๐ฅฐ50โค10๐คฃ7๐6๐4๐ข1
The United Kingdom is ran by a bunch of fucking morons. I mean that wholeheartedly. These stupid fucks think you can "ban" VPNs and think "banning" VPNs will "protect the children".
"Ban" VPNs and watch what happens next.
"Ban" VPNs and watch what happens next.
๐162๐คฃ79๐ฏ31โค12๐6โคโ๐ฅ5๐ฅ1๐1๐1
One of my favorite people in the world is petikvx.
He randomly showed up one day and was like, "Bonjour, j'ai beaucoup de logiciels malveillants."
I said, "I don't speak German, pal".
Then he started giving me a bunch of malware. He is the primary person who does our bulk malware stuff. Everyday he sends me malware. I receive it, sync it with the malware place, and go on about my business.
I checked my chat logs, I haven't spoken to the guy since February, 2026. Before that it was like, July, 2025, yet EVERY SINGLE DAY he is sending me malware.
I barely know the guy. He shows up, he says, "J'aime beaucoup les logiciels malveillants. S'il vous plaรฎt, partagez ce logiciel malveillant avec d'autres personnes.", and that's it.
I don't know his name, I don't know where he works, I don't know how old he is, I literally know almost nothing about the guy.
He doesn't even speak English that well
I fucking love this guy. He is my best friend.
He randomly showed up one day and was like, "Bonjour, j'ai beaucoup de logiciels malveillants."
I said, "I don't speak German, pal".
Then he started giving me a bunch of malware. He is the primary person who does our bulk malware stuff. Everyday he sends me malware. I receive it, sync it with the malware place, and go on about my business.
I checked my chat logs, I haven't spoken to the guy since February, 2026. Before that it was like, July, 2025, yet EVERY SINGLE DAY he is sending me malware.
I barely know the guy. He shows up, he says, "J'aime beaucoup les logiciels malveillants. S'il vous plaรฎt, partagez ce logiciel malveillant avec d'autres personnes.", and that's it.
I don't know his name, I don't know where he works, I don't know how old he is, I literally know almost nothing about the guy.
He doesn't even speak English that well
I fucking love this guy. He is my best friend.
โค246๐ฅฐ35๐คฃ20๐17๐ฅ4๐ข2๐2๐1
Was thinking about online age verification stuff today
It dawned on me that I've got underwear that is probably 18 years old
Yeah, I'm killing myself tonight
It dawned on me that I've got underwear that is probably 18 years old
Yeah, I'm killing myself tonight
๐คฃ178๐21๐ข13โค11๐ฑ3๐ฅ1๐1
Someone DMd me something they received on Discord. They thought it could potentially be malware.
It was malware.
However, it was Electron JS AI slop malware. You can tell because it was easily disassembled and the AI notes were present.
I'm so god damn tired of malware slop
It was malware.
However, it was Electron JS AI slop malware. You can tell because it was easily disassembled and the AI notes were present.
I'm so god damn tired of malware slop
๐คฃ155โค10๐5๐ฅ4๐ฏ3๐ฅฐ2๐ข1
vx-underground
Someone DMd me something they received on Discord. They thought it could potentially be malware. It was malware. However, it was Electron JS AI slop malware. You can tell because it was easily disassembled and the AI notes were present. I'm so god damnโฆ
Interesting, it was undetected virtually everywhere. It was also undetected in a sandbox because it's a bloated piece of shit and has too many dependencies.
The only AVs that detected it from static analysis was Rise and MalwareBytes
The only AVs that detected it from static analysis was Rise and MalwareBytes
๐ค106๐26โค6๐ฅ3๐ข1
It's Father's Day this weekend.
My wife asked what I wanted and the answer was shrimple.
I want to lay in bed and not move for 24 hours. I will only move to urinate, or defecate, or consume the fast food slop I have delivered from Uber Eats.
Let me rot in peace for 1 day.
My wife asked what I wanted and the answer was shrimple.
I want to lay in bed and not move for 24 hours. I will only move to urinate, or defecate, or consume the fast food slop I have delivered from Uber Eats.
Let me rot in peace for 1 day.
๐ฅฐ158๐47๐ซก38๐ฏ18โค11๐ฅ7๐5๐ข5๐ค4โคโ๐ฅ2๐1
Dawg, I don't want to sound like a hater, but some of you malware nerds NEED to lock in and TRY HARDER.
Someone found a malicious GitHub repo and DM'd it to me. It had piss poor obfuscation (if you even want to call it that, it's Base64 encoding) and the malware C2 is basically plain text.
The delivery method is masquerading as an Adobe Acrobat plugin? My Brother in Christ, WHAT ARE YOU DOING
The C2 is literally houndsregimeskid-dot-com
Hounds Regime Skid? Hounds Regimes Kid?
Also, for the record, if the people who wrote this malware are reading this: I'm not the guy spamming your Telegram C2. That is someone else. You left all of Telegram channel stuff plain text too
Someone found a malicious GitHub repo and DM'd it to me. It had piss poor obfuscation (if you even want to call it that, it's Base64 encoding) and the malware C2 is basically plain text.
The delivery method is masquerading as an Adobe Acrobat plugin? My Brother in Christ, WHAT ARE YOU DOING
The C2 is literally houndsregimeskid-dot-com
Hounds Regime Skid? Hounds Regimes Kid?
Also, for the record, if the people who wrote this malware are reading this: I'm not the guy spamming your Telegram C2. That is someone else. You left all of Telegram channel stuff plain text too
๐คฃ112๐ฅฐ9โค6๐ข1
Image 1. Website with uBlock Origin on
Image 2. Website with uBlock Origin off
uBlock Origin IS PREVENTING US FROM FREE MALWARE
Image 2. Website with uBlock Origin off
uBlock Origin IS PREVENTING US FROM FREE MALWARE
๐คฃ162๐ฅฐ14โค9๐ข7๐ฑ6๐1๐ค1
vx-underground
Image 1. Website with uBlock Origin on Image 2. Website with uBlock Origin off uBlock Origin IS PREVENTING US FROM FREE MALWARE
I'm torn mentally, physically, and maybe a little bit sexually.
I hate advertisements. On the other hands, I like malware. I don't know what to do. I am forsaken.
I hate advertisements. On the other hands, I like malware. I don't know what to do. I am forsaken.
โค73๐คฃ22๐5๐ค4๐ข4๐ฅฐ3๐ฏ2๐1