A Disaster Caused by Two Blue Words: Click Me
Author: APC Editorial Department Science Outreach Group
P.S. Most of the technical content below comes from answers provided by an expert who wished to remain anonymous, with a smaller portion compiled from other experts’ chat records.
On September 19 and 20, a card began circulating wildly through all kinds of small chat groups:

That’s right: those two blue words, “Click me,” set off a full-scale science-outreach battle…
First, the short version: this card poses no danger to you. Clicking it is harmless and will not expose your information. Just do not forward it afterward, and especially do not recklessly modify things at random.
So what exactly was this science-outreach battle? Let us sort out the timeline~
On the evening of September 19, 2020, the card first appeared in several groups and prompted members to click it over and over!

Amid the commotion, group members thought: WTF? This is fun! Why not forward it and let other people click it too? (And take a frenzy of screenshots along the way for future “blackmail.”)
By the next day, September 20, I had personally seen several groups “fall.” The card was already spreading widely through small chat groups, and its contents were starting to diversify too.

Up to that point, nothing was seriously wrong. People were simply using it to relieve their boredom.
Around noon, however, the card’s reputation abruptly collapsed. Chat groups suddenly began banning it, and some people were muted for 30 days or even told, “You have been removed from the group chat.”
The reason was that someone in one group suddenly claimed the card was a new kind of virus that could capture a phone’s IP address, making the situation extremely serious:

So-called “stolen information” also surfaced:

At that point, the nature of the incident changed. The card went from a harmless diversion to the “virus” card everyone was talking about. (The card found itself bearing an unbearable weight.) The rumor spread even faster than the card had. Groups that had shared the card and groups that had never seen it alike began widely circulating warnings about its dangers:

Once the rumor reached people who understood computers, they naturally recognized it for what it was:

How Does the Card Reply Automatically, and Is It Dangerous?
We found one expert’s answers and the related chat records and have condensed them into this short technical explanation:
Expert Rumor-Debunking Group (6)
Newbie (Me)
How does this card reply automatically?
Expert

These are two samples from the software. Anyone who passed middle-school English can easily spot the keyword com.tencent.autoreply. Clicking to send an automatic reply is clearly a function built into Tencent QQ itself. Tencent may have developed it for certain business needs. Here, someone used features such as custom cards to substitute their own card for Tencent’s official business card and send it through a hidden API, producing this effect.
Newbie (Me)
So clicking it merely uses Tencent’s auto-reply feature, without the other risks described online?
Expert
Yes. Forwarding or opening it normally causes no harm.
Tencent has a bot that automatically sends a similar card when someone joins a group, allowing it to welcome newcomers. QQ Group Manager uses the same API, only in a more complex way. As for the supposed JS plug-in and Flash, frankly, they do not exist. The card does not redirect to an external URL, so it cannot record an IP address. As for the alleged packet capture… leaving aside what packets this person actually captured, messages from other users would go to the server, not through his device, even if a virus existed. He most likely captured outbound packets from software on his own computer or from QQ itself. If that were enough to create the risks described online, he could go collect a major award.
To anyone who understands the technology, this is a non-issue. What followed was a long process of debunking the rumor…
Newbie (Me)
Then how was this thing made?
Expert
I will not go into the deeper details. The creator probably used unconventional means to call an interface that users should not be able to access. It could also have been a bug-based repeater or a bot running on a PC; there are many ways to achieve this. Usually people just play with this kind of thing in technical groups. Unfortunately, someone publicized it. (Shrugs ┑( ̄Д  ̄)┍)
Newbie (Me)
What will happen next? Will it keep spreading?
Expert
If we are talking about the same “card,” my information says the blue text was first sent at 11:30 p.m. yesterday, September 19, and the last message went out at 5:47 this afternoon. Everything after that was intercepted. Generally speaking, as long as nobody does anything reckless, there should be no further problem.
╮( ̄▽ ̄"")╭
In summary, Tencent necessarily created card functionality for its own business needs and allowed users to send cards—for example, invitations for Honor of Kings or Game for Peace. These interfaces were originally hidden and inaccessible to ordinary users. Some modified versions of QQ and some QQ bots can access them directly, allowing users to send their own custom content. The click-to-reply behavior is also a function written by Tencent. In form, the card is no different from the many others you see in QQ groups every day; only its content has been changed.
So do not believe or spread rumors. If anyone sends this rumor about the card to you or to a group you are in, send them this article 😄
P.S. Thanks to the expert who wished to remain anonymous for answering our questions. Please identify the source and author when reposting.
P.P.S. At the same time last year, in September 2019, there was a genuine piece of rogue software: “An In-Depth Analysis of the ‘9.27 Audio Rogue Software’”. That “For the Best TA” software caused the social death of many people (laughs). Its timing really was close to this year’s card incident—quite a coincidence!

