Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                
Skip to main content

Get the Reddit app

Scan this QR code to download the app now
Or check it out in the app stores
r/StableDiffusion icon
r/StableDiffusion icon
Go to StableDiffusion
r/StableDiffusion
A banner for the subreddit

/r/StableDiffusion is back open after the protest of Reddit killing open API access, which will bankrupt app developers, hamper moderation, and exclude blind users from the site. More info: https://rtech.support/docs/meta/blackout.html#what-is-going-on Discord: https://discord.gg/4WbTj8YskM Check out our new Lemmy instance: https://lemmy.dbzer0.com/c/stable_diffusion


Members Online

[PSA] NullBulge malware/ransomware

News

A group named "NullBulge" at nullbulge(dot)com (wouldn't click without vpn) is spreading malware/ransomware through fake leaked BeamNG mods, random AI stuff such as ComfyUI nodes, and who knows what else. Careful about what you're downloading and check through the code for anything obfuscated or malicious before actually running it. This goes for even the well-known stuff since they claim to be "hacking" accounts of tool/script creators.

An example of an attack they recently have done that includes AI stuff is the recent ComfyUI LLMVISION incident. They claimed responsibility on their website and github along with leaking roblaughter's passwords. It's obviously their account though as they use the alias for malware on other sites.

They usually host their payloads on pixeldrain.com so you could modify your hosts file to block the pixeldrain domain (C:\Windows\System32\etc\hosts)

Add to the end of the file "127.0.0.1 pixeldrain.com" to block out pixeldrain downloads (I wouldn't count on this to 100% save you)

EDIT: NullBulge(dot)com seems to have been (temporarily?) taken down by their domain provider!
Archive of their site if you're curious https://web.archive.org/web/20240610173703/http://nullbulge.com

Share
Sort by:
Best
Open comment sort options
u/LD2WDavid avatar

I wouldn't call "hacked" script cause the initial commit already has the malware. This was planned since the very beginning.

u/a_beautiful_rhind avatar

Straight luddites:

We are a collective of individuals who believe in the importance of 
protecting artists' rights and ensuring fair compensation for their work. 
Our team consists of passionate advocates, researchers, and activists 
who are committed to making a difference in the creative community.

Of course it's probably just bullshit and they are crypto scammers.

u/dqUu3QlS avatar

I'm assuming this person is pretending to be a collective of kinky anti-AI furries? It's definitely bullshit.

  • The lion-with-null-bulge artwork on the site is almost definitely AI generated. It is precisely 1024x1024 pixels and has subtle AI generation artifacts.

  • Furries are even more opposed to cryptocurrency than they are to AI. The site even lists "crypto promotion" as a "sin", and yet accepts donations to a Monero address.

  • Anti-AI furries would never use the word 'ret*rd'.

u/a_beautiful_rhind avatar

Yea, the monero addy after crypto "sins" took the cake.

More replies
u/Enshitification avatar

I bet it's one guy who lives with his parents. He's butthurt over losing his brony hentai art commissions to AI.

u/a_beautiful_rhind avatar

What these kind of guys don't get is they aren't entitled to my money. I cut the studios out, I can cut them out too. There's plenty of entertainment out there. You can't make enemies out of your audience. There's a third option between paying and pirating, it's ignoring.

u/GBJI avatar

There's a third option between paying and pirating, it's ignoring.

Well said ! There is a lot of power in NOT doing thing. Not paying attention. Not buying. Not going. Not working. Not following orders.

More replies
More replies
More replies
u/Hahinator avatar

The commits on the "LLMVISION" repo do not support this. See the main thread on this:https://old.reddit.com/r/comfyui/comments/1dbls5n/psa_if_youve_used_the_comfyui_llmvision_node_from/l7sxeok/

The malware was in it from initial commit. Can chase rabbit holes which is prob what that kid wants, but owner of repo didn't have his repo taken over as a briefly hosted update said (and linked to this name you mention).

u/Hahinator avatar

He's doing it on some mod forum as well: https://www.modland.net/beamng.drive-mods/cars/bolide-skyrider.html

Stop pushing his bullshit deflection - FBI was alerted and anyone who had their information hacked should definitely file a claim if they haven't.

More replies
u/Enshitification avatar

They registered the domain on the 2nd of this month with Tucows. Here is the link to report them and get them shut down.
https://tucowsdomains.com/abuse-form/spam/

u/EmbarrassedHelp avatar
Edited

I think they are using FDCservers.net as their webhost for pixeldrain: https://www.nslookup.io/domains/pixeldrain.com/webservers/. Report them to the PixelDrain staff here: https://pixeldrain.com/abuse

And Leaseweb Canada Inc. as their webhost for the nullbulge site: https://www.nslookup.io/domains/nullbulge.com/webservers/

So make sure to report them to both those services as well.

u/memestar2400 avatar

Pixeldrain is a legitimate file hosting website, but do report them to Leaseweb

u/EmbarrassedHelp avatar

Thanks, I updated my comment to point users to PixelDrain's reporting contact system.

u/Hahinator avatar

https://www.modland.net/beamng.drive-mods/cars/bolide-skyrider.html

It's the author - not wtf he tried to write it off as.

More replies
More replies
More replies
[deleted]
[deleted]

Comment deleted by user

u/Enshitification avatar

A different domain than nullbulge.com?

More replies
u/ElChabochi avatar

These “activists” are protecting big corpo money. And justifying themselves saying “individuals who believe in the importance of protecting artists”

Comment Image

I don’t see them taking down dall-e or midjourney anytime soon.

u/Hahinator avatar

The user who posted this was behind it 100% - he's actively doing it on a mod forum as well: https://www.modland.net/beamng.drive-mods/cars/bolide-skyrider.html

FBI has been notified so he can deal w/ that.

More replies
u/CeFurkan avatar

i wonder if anyone using kaspersky internet security was able to install that malicious code and run? any info on this?

u/nootropicMan avatar

Thanks for the heads up. I added those domains to the block list on my router. For those of you have an Asus router, go to your Advanced settings -> firewall -> URL filter.

u/cathodeDreams avatar

be sure to block file hosting websites to protect yourselves kiddos

u/memestar2400 avatar

bro i just said to block it out for the time being as it's extremely uncommon and being used maliciously. i told you guys to not count on it either😭

More replies

It is a good time to try simplewall from henryapp (https://github.com/henrypp/simplewall), because Windows' UI sucks. Have been using it for years.

I configured it to block all connections until I click allow.