Post #3922776
2026-07-19 00:03 UTC
1/ it started with a grep.app link a friend sent me. i went hunting for leaked password prefixes and landed on one github repo. by the end of the weekend i’d mapped a 16-actor chinese reward-farming underground. this is the whole story 🧵
#InfoSec #ThreatIntel #CTI #ReverseEngineering
Replies (1)
-
@NeuroWinter@infosec.exchange 2026-07-19 00:03
2/ the repo: 985Ming/qlk. ~99 obfuscated python + js scripts, description (translated) “Qinglong Script Library, 2025.” i cloned it and couldn’t read a single line. so now i had to. there goes my weekend.