Hacking & security — a classification, not a measurement. An on-box language model (Qwen3.6-35B-A3B-UD-Q6_K_XL, prompt version 1) read this channel’s own recent posts on 11 August 2026 and assigned it the closest of 31 fixed categories, at 99% confidence. This is a model’s judgement about what the channel is likely to be about, not a fact this register measured the way a subscriber count or a view count is measured — it can be revised on a later pass, and it carries no weight anywhere else on this page. How this classification works, and why it has no browse page of its own yet.
Observations
These are measurements, not verdicts. Each one below states something we counted, alongside the evidence it was counted from, so you can check it rather than take it. None of them is graded: every observation this register holds is recorded at severity 0, because the precision of the detectors behind them has not been measured yet, and a rating we cannot support is worse than none. Read each as a fact about the data, not as a judgement about the channel. How we measure.
Content that also appears on other registered channels
Posts published here appear word for word on 1 other registered channel. They sit inside a group of 3 channels that share the same post bodies with each other. The matching is on the text itself, not on Telegram’s forward marker, so it finds a copy whether or not it was labelled as one.
Matching posts — open both and compare (5 of the pairs behind the counts below)
Text overlap is the Jaccard coefficient over the set of distinct three-word phrases in the two bodies: 1.00 is identical wording, and the threshold for counting a pair at all is 0.70. Candidates are generated by simhash LSH (4 x 16-bit bands, exact Hamming <= 3) verified against the bodies with Jaccard over the SET of distinct 3-word shingles. Published first counts which side of each matching pair carries the earlier timestamp — in this corpus, which is the limitation directly below.
What this cannot establish
MEASURED, DOMINANT ERROR SOURCE: a post ingested before 2026-08-06 may have carried a forward header that was not recorded. A 45-pair hand-check against live t.me pages found 14 (31%) where the live page shows a forward header naming the other channel and the database has none, plus 4 more (9%) naming a third party. The text match itself was wrong 0 times out of 45. Read attribution_capture.items_in_trusted_window before treating the unattributed count as a claim.
Telegram lets a channel forward a post with a header naming the source, and we only began reliably recording that header on 2026-08-06. None of the 0 matches recorded here fall after that date, so for this entry we cannot say whether any of them carried a credit. The duplication is measured; the absence of attribution is not.
“Published first” means first in this corpus. We hold 19 comparable posts for this entry, running 26 June 2026 to 7 August 2026. A channel we have read one page deep will look younger than a neighbour we have read in full, and the order would flip with no change in the underlying facts.
The detector’s own notes on this observation, as it recorded them. Names in this_style are fields of the underlying evidence record, which the plain-English paragraphs above read out for this entry.
Verbatim republication has three causes and the text separates only two: a clone/mirror, unattributed copy-paste, or BOTH channels copying a common third source that neither attributes. The spread filter (content held by at most 8 channels) reduces the third and does not remove it.
'Earliest' means earliest IN THIS CORPUS. A channel ingested one page deep will look younger than a neighbour ingested in full; corpus_coverage above is there to be checked before the direction is believed.
shared_verified_est extrapolates the sampled pass rate over the full narrow match count; sampled/passed are the numbers actually measured.
Absence of a forward header is not proof of intent: Telegram lets a channel disable forward attribution, and a credit written in the body is not parsed as attribution here (mention_edge_either_way above is the closest available signal).
Across the whole group of 3, the earliest publisher we hold is @APT_Notes. That is a statement about our reading window, not a claim of authorship.
Recorded under the key clone_source, last confirmed 7 August 2026. An observation that a later pass no longer finds is cleared, and a cleared observation is removed from this page rather than being shown struck through — we do not keep publishing a claim we have withdrawn. Dispute an observation.
Also posting the same content
This channel’s posts match, word for word or near enough, posts on 2 other registered channels, found by comparing text fingerprints across every channel on the register. That matching has been checked by hand against the live Telegram pages and found reliable — 0 wrong of 45 pairs re-read.
Which channel, if either, published first is deliberately not shown. The same hand-check found that reading wrong 18 of 45 times — 60%, no better than a coin flip — because it depends on how deep our own crawl happened to reach into each channel’s history, not on when the content was actually first posted. This list is ordered by subscriber count, the same as every other listing on this site, never by which channel we think came first. Word-for-word matching has several ordinary explanations besides copying — a channel mirroring itself, an unattributed repost, or two channels independently repeating the same wire story — and this measurement cannot tell those apart. How this is measured.
16 measurements spanning 50 days, net +487. Dots are measurements; the straight line between them is drawn to join them, not to claim we know the path taken in between — snapshots are recorded only when a count changes, so gaps mean “no change observed”, never “interpolated”. The vertical axis spans 7,334–7,967 and does not start at zero.
Measurement log — every subscribers count we have recorded
Measured (UTC)
Subscribers
Change
25 Sept 2026, 18:36
7,894
+71
17 Sept 2026, 10:57
7,823
+20
13 Sept 2026, 13:57
7,803
+11
9 Sept 2026, 17:59
7,792
+36
4 Sept 2026, 20:02
7,756
+33
31 Aug 2026, 19:17
7,723
+39
28 Aug 2026, 13:28
7,684
+16
25 Aug 2026, 15:54
7,668
+16
22 Aug 2026, 12:24
7,652
+34
19 Aug 2026, 08:35
7,618
+17
16 Aug 2026, 17:47
7,601
+54
13 Aug 2026, 04:25
7,547
+62
10 Aug 2026, 00:46
7,485
+76
7 Aug 2026, 02:27
7,409
+2
6 Aug 2026, 08:30
7,407
no change
6 Aug 2026, 08:22
7,407
first reading
Engagement
42 posts held, back to 26 June 2026 — the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 17 pages of Telegram’s post history, 20 posts per page.
Nothing published in the last 30 days. ERR and ER are rolling 30-day measures, so there is nothing to compute — we hold 42 posts for this entry, the most recent from 27 August 2026. An engagement rate over an empty window would be a number about nothing.
What this channel posts
Video runtime
26s
Average length
26s
Measured directly from 1 video with a duration reading, out of the posts we hold for this channel — not this channel’s whole posting history, only the sample this register has actually read. An exact reading to the second, taken from the post itself rather than from Telegram’s own rounded chrome, so it carries no ≈ mark.
Reaction mix
789 reactions across 39 posts, in 15 distinct kinds. The most used accounts for 46.8% of them.
Every reaction kind recorded on the sample, most used first
Reaction
Count
Share
Share, drawn
🔥
369
46.8%
custom 5373311405090938996
151
19.1%
👍
70
8.87%
😁
43
5.45%
❤🔥
40
5.07%
custom 5346135098309748287
22
2.79%
custom 5373163031150732302
22
2.79%
custom 5240001719076668815
18
2.28%
custom 5240142636953640660
11
1.39%
custom 5370774720096509791
11
1.39%
custom 5300859949667072567
9
1.14%
🤔
8
1.01%
🍌
6
0.76%
custom 5301285482141858441
5
0.634%
💅
4
0.507%
Custom emoji. 8 of the rows above are Telegram custom emoji, which the public preview renders as an element carrying only a numeric id — no character, and no image we can reach. The id is printed as-is rather than substituted with a look-alike glyph, because a stand-in would be our invention showing where a measurement should be. The counts beside them are Telegram’s.
No sentiment is inferred, and none should be read in. This table is ordered by count and by nothing else. Emoji do not carry stable meaning across languages or communities — 🙏 is thanks in one channel and mourning in another — so we publish which ones were pressed and how often, and pass no judgement on what an audience meant by them.
Precision. Telegram publishes reaction counts per emoji and short-forms each one — 4.34K, 1.2M — so any single kind at or above 1,000 reaches us at three significant figures, and only counts below 1,000 are exact. The shares above are ratios of those figures and carry the same error. This is also why the total here can differ slightly from a reaction total printed elsewhere on the page: both are sums of the same rounded parts, taken over samples with different edges.
Coverage. Reactions were read on 42 of the 42 sampled posts in this sample. Summed by Telegram’s own count on each post — not by adding up the per-emoji breakdown above — those same posts carry 860 reactions in total: the kind of figure the paragraph above means by “a reaction total printed elsewhere on the page”.
Measured over the 42 most recent posts we hold, published 26 June 2026 to 27 August 2026, using the newest reading held for each. Telegram Stars are excluded: they are a payment, not a reaction, and they have their own section.
Telegram Stars
Stars received
17
across the posts below
Posts paid on
6
of 42 we hold a reading for · 14%
Most on one post
10
single highest reading
A paid reaction is a reader spending Telegram Stars — bought with money — on a post by @P0x3k_1N73LL1G3NC3. Telegram publishes the count on the public post preview alongside ordinary reactions, and this register reads it there. It is the only figure on this site that measures money moving rather than attention.
Stars are not reactions, and the two are never added. They are rendered in the same strip on Telegram and counted in the same shape, but one is a tap and the other is a purchase. The reaction totals and the engagement rate elsewhere on this page exclude every figure in this section, and no rate here is computed against a reaction count.
This is not revenue, and we publish no currency figure. What a Star costs a reader and what it pays a channel are different numbers, Telegram takes a share we cannot observe, and the terms have changed. Converting a Star count into money would be an estimate dressed as a measurement, so the count is where we stop.
Counted over the 42 most recent posts we hold for this entry, published 26 June 2026 to 27 August 2026. Star counts above 1,000 reach us in Telegram’s short form and carry the same three-significant-figure rounding as everything else on this page.
Advertising
Ad load
4.76%
2 of 42 posts carry an ad marker
Regulatory tokens
0
none — marked by hashtag only
Median views · ads
2,290
over 2 measured posts
Median views · rest
4,130
over 40 measured posts
An ad marker, not a judgement about a post. A post is counted here because it carries one of two explicit markings: an erid token, which Russian law has required on paid placements since 2022 and which is issued against a specific advertising contract, or a #реклама / #ad hashtag in the body, which is the channel declaring it itself. The first is documentary; the second is a self-declaration and is weaker. No classifier reads the text and decides — nothing on this site guesses that a post is an advertisement.
This is a floor, and it can only ever be a floor. A channel that runs paid placements without marking them produces no marker for us to count, and an unmarked ad is indistinguishable from an ordinary post on the public surface. The ad load above therefore means “the share of posts that declared themselves”, never “the share of posts that were paid for”. A low figure is not evidence of a channel that runs few ads.
Both figures are medians, and no ratio between them is published. Each is a view reading that actually occurred on a post, picked by percentile_disc rather than averaged, so one viral post cannot move it and no interpolated value is invented between two readings. The sample on one side is under five posts, which is too thin to compare. The two figures are shown side by side with the count behind each, and deliberately not divided into a headline like “ads get x% fewer views” — an arithmetic that is easy to print and, at this sample size, means nothing.
Measured over the 42 most recent posts we hold, published 26 June 2026 to 27 August 2026. Views are the latest single reading held for each post, and any reading at or above 1,000 is rounded by Telegram to three significant figures.
CrystalPotato
A Crystal port of GodPotato, a local privilege escalation tool that abuses the DCOM OXID Resolver and named pipe impersonation to escalate from service accounts with SeImpersonatePrivilege to NT AUTHORITY\SYSTEM.
The main contribution of this port beyond the language change is a set of OPSEC improvements designed to reduce the binary’s signature surface.
Blog: https://ricardojoserf.github.io/crystalp…
SSHDESK
A full interactive remote desktop delivered entirely through SSH and displayed directly in your terminal. OpenSSH authenticates the user and launches SSHDESK as a forced command. The active graphical desktop then appears inside that same terminal. Keyboard, mouse, resize events, changed pixels, and session cleanup all travel through the one SSH PTY. There is no browser, custom SSH client, VNC/RDP listener, s…
Synology-Inventory-Decryptor
A post-exploitation tool that instantly decrypts all credentials stored in Synology Active Backup for Business (ABB) config.db, yielding plaintext passwords for ESXi, vCenter, Hyper-V, Windows/Linux servers, MSSQL, and Oracle databases. Tested only on a Synology DS920+ NAS.
Blog: https://blog.offseclabs.tech/posts/synology-active-backup-decrypting-inventory-credentials/
BOFScale
A collection of BOF-PE's that allow running tailscale from memory. A CDN-fronted tailnet from a BOF-PE. The entire Tailscale daemon runs inside the implant process with no driver, no service, no disk state, and no child processes. Traffic relays over standard RFC 6455 WebSockets, so both DERP relay servers and the control plane can sit behind CloudFront or Fastly without any special handling.
Blog: https:/…
NachoMDM - Weaponising Windows MDM for UAC Bypass and SYSTEM Execution via Malicious Enrollment
In this post, we detail our research into the Windows MDM enrolment protocol and demonstrate how a malicious MDM server can be weaponized to achieve a User Account Control (UAC) bypass and silent NT AUTHORITY\SYSTEM code execution with two clicks. By coaxing a user who is a member of the local administrators group into en…
🔒 Citrix NetScaler Pre-Auth RCE (CVE-2026-8452)
Unauthenticated heap overflow in SAML signature canonicalization. An oversized PrefixList inside the <ds:SignedInfo> InclusiveNamespaces element overflows a fixed-size buffer, corrupting adjacent nsb chunk metadata. This yields a write-what-where primitive (controlled memcpy src/dst), allowing overwrite of tx_pkt_complete_fptr and jump to attacker shellcode on the exec…
SilentChrome-BOF
SilentChrome-BOF demonstrates how modifying a Chromium profile can transform the browser itself into a persistent C2 agent with examples such as Ditto. Extensions provide the foundation for the C2 agent and IWAs or Native Messaging Hosts can expand its capabilities.
Ditto
Mythic payload type that builds a Chromium extension as the agent artifact. The built extension checks in to Mythic over HTTP(S…
VsockDrop
Linux kernel LPE via an io_uring zerocopy page-refcount underflow over AF_VSOCK. (CVE-2026-53365) Bug affects Linux 6.7 -> 7.0.10, fixed in 7.0.11.
Tested on unpatched Ubuntu 22.04 HWE/24.04/26.04, Debian 13, Arch, and openSUSE Leap/Tumbleweed.
Dark Agent
Fully-featured Mythic C2 Agent for Linux and macOS environments. Built in Crystal with statically-linked OpenSSL, it provides comprehensive post-exploitation capabilities through COFF/BOF loading, extensive system commands, SOCKS proxy support, and flexible communication profiles.
Blog: https://minorimpact.dev/posts/dark-agent-coff-loader/
CDP-Enable-BOF
After enabling CDP, you can use CDP-Toolkit to connect to the endpoint directly or through a SOCKS proxy. Its commands support enumerating open tabs, searching browser history, extracting cookies and saved passwords, capturing screenshots, listing bookmarks, managing extensions, and navigating the browser to specified websites via the Chrome DevTools Protocol APIs.
CDP-Toolkit
Commands:
discover
tab…
Showing the 12 most recent of 42 posts we hold for @P0x3k_1N73LL1G3NC3. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.
Stars beside a post are paid reactions — Telegram Stars, bought with money and spent on that post. They are a different unit from reactions and are never added to them, here or anywhere else on this page.
Posts edited after publishing
@P0x3k_1N73LL1G3NC3 edited 1 post after it first published — the same permalink now carries different wording than the one this register originally read, caught because our own crawl held a copy of the earlier text.
An edit is not deception. Typo fixes, price updates and corrections look exactly like this too — this register can tell you the wording changed and when, not why. How this is measured.
First edit seen
18 August 2026
Most recent edit
18 August 2026
Forward network
Republished by
Channels on the register that have forwarded this channel's posts into their own feed.
Built only from forwarded posts we have actually read, on both sides. Coverage is early and deliberately incomplete: a missing link means we have not read the post that would prove it, never that the relationship does not exist. Counts are distinct forwarded posts observed, so they only ever go up as we read more.
Cite this entry
A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 25 September 2026 — this
entry's latest reading, not the date you are reading this.
“1N73LL1G3NC3” (@P0x3k_1N73LL1G3NC3), 7,894 subscribers as measured 25 September 2026. Telegram Register, tgregister.com/channel/P0x3k_1N73LL1G3NC3.
Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.