Remote
NeuroWinter
@NeuroWinter@infosec.exchange
Blog on random learning in tech: neurowinter.com
Reformed #ai / #MLOps engineer now working as an #SRE at a company that specialises in data and backing up #opensource databases and #kafka.
Long time #appsec enthusiast
Alt: NeuroWinter@tilde.zone
0 Followers
0 Following
22 Posts
Joined December 13, 2017
Replying to
@Ajediday@infosec.exchange my cats would never ever ask my to close the door !
Open post
Replying to
10/ which means it protects nothing. recover that key once and every payload the loader ever sealed falls open. that’s the whole lesson of the old tier: a hardcoded key buys zero confidentiality.
1
4
0
0
Open post
Replying to
2/ the repo: 985Ming/qlk. ~99 obfuscated python + js scripts, description (translated) “Qinglong Script Library, 2025.” i cloned it and couldn’t read a single line. so now i had to. there goes my weekend.
0
1
0
0
Open post
Replying to
4/ the obfuscation was the same trick every time: xor/base85 → zlib → a marshalled code object → exec(). runs in memory, never writes a .pyc. so it stops you reading the source, but not running it. and anything you can run, you can hook :)
0
10
0
0
Open post
Replying to
5/ once i could read them i saw the targets: news sites, ads, local govt sites. and the endpoints matched across repos, same hand-rolled toolchain, different authors. qlk wasn’t a one-off. it was one corner of a whole scene.
0
1
0
0
Open post
Replying to
7/ that DRM layer is why i couldn’t read qlk in the first place. one operator, wyourname, runs DRM-as-a-service: encrypted .so loaders + a C2 that hands out the key per machine. everyone else rents it so their scripts can’t be lifted off github. so i went after it.
0
7
0
0
Open post
Replying to
6/ pull the thread and it’s 16 actors, 26 repos, 60+ platforms. and it doesn’t run like a friend group, it runs like a supply chain: operators write the scripts, someone rents them DRM to protect them, shared plumbing hides the bots, a WXPusher ping tells the operator when the money lands.
0
1
0
0
Open post
Replying to
0
6
0
0
Open post
Replying to
9/ almost fell for a red herring, get_key() calls md5 with a tidy 12345678 sitting right beside it. too good to be true. it was. then i remembered it’s just a python module, so i imported it and asked. it handed the key straight over. hardcoded, same 8 bytes in every build.
0
5
0
0
Open post
Replying to
11/ then the wall. the current tier is Rust doing AES-CBC. ordinary crypto. the difference is where the key lives: never on your box, fetched per-machine from a C2 in shanghai, and the loader fingerprints your machine and POSTs it there first. score: 49 mapped, 0 decrypted. that’s the design working as intended.
#Rust
0
3
0
0
Open post
Replying to
12/ but the gut-punch wasn’t the crypto. one of the most capable operators, smallfawn, sells a JD.com login tool to other farmers, quietly wired to ship the buyers’ logins (plaintext passwords included) 3x a day to a server they control. they are, quite literally, farming the farmers.
0
2
0
0
Open post
Replying to
13/ and the part that actually worries me: the targets aren’t just music + video apps. it’s civic + government apps and state media, a pile of them sharing one reward/lottery backend whose “unforgeable” secret is just… sitting in the client. all disclosed to vendors first.
0
2
0
0
Open post
I have been working on this series of posts in my blog. I went from a single grep.app search to finding out and driving into the rabbit hole that is the Chinese “wool farming” underground. Basically a bunch of peeps sharing scripts to defraud rewards systems in websites, from their version of Amazon (jd.com) to state media sites and local government sites.
https://neurowinter.com/security/2026/06/23/a-weekend-in-the-wool/
0
0
0
0
Open post
whats this? another post on the chinese wool-farming underground, and this time the targets are state-owned media and govt-adjacent civic apps :P
turns out a pile of these apps share one reward + lottery backend, and the secret thats meant to make claims unforgeable is just… sitting in the client. recover it and you can forge a valid claim the backend accepts.
read-only, walked it from one github repo. part of an ongoing series.
https://neurowinter.com/security/2026/07/16/forging-the-government-lottery/
#infosec #threatintel #CTI #OSINT #reverseengineering #China #security #appsec
0
0
0
0
Open post
I think I really want to start sponsoring a few small security conferences, so when they are thanking all the different company’s in the middle with be “thanks to ahh Neuro?”
0
0
0
0
Open post
Was just looking into Kimi since k3 just dropped. Turns out all their memberships are sold out ! Guess I’ll have to wait for the public models
https://www.kimi.com/code/
0
0
0
0
Open post
Next post in my Wool series is now live, this time its looking at the scene as a whole, and how to perform OSINT on repos, and how trying to hide your tracks is a singal on its own!
https://neurowinter.com/security/2026/07/28/the-cast-and-crew/
0
0
0
0
Open post
Replying to
@apenwarr.ca I have never really understood MCPs. A well document and maintained API would do all of that an MCP does right ?
0
2
0
0
Open post
Replying to
@afterdesign@infosec.exchange I had no idea about this device and now I desperately need one !
I’m always swapping cables because one does power and not data or one does data randomly etc etc such a waste of time !
0
1
0
0
Open post
Replying to
@sonic_hedgeblog@mastodon.social why does it annoy me so much that the figures aren’t centred ?!
0
0
0
0