Two Blue Words, One Big Mess: “Click Me”
Author: APC Editorial Department Science Outreach Group
P.S. Most of the technical material below comes from answers by an expert who wished to remain anonymous; a smaller portion was compiled from other experts’ chat logs.
On September 19 and 20, a card began racing through all kinds of small chat groups:

That’s right: those two blue words—“Click me”—set off a full-blown science-outreach battle…
First, the short answer: this card poses no danger to you. Clicking it is harmless and will not expose your information. Just do not forward it afterward, and above all, do not start modifying things recklessly.
So what exactly happened in this science-outreach battle? Let us sort out the timeline~
On the evening of September 19, 2020, the card first appeared in several groups and got members clicking it again and again!

Amid the commotion, group members thought: WTF? This is fun! Why not forward it and let everyone else click it too? (And, of course, take screenshots like mad for future “blackmail.”)
By the next day, September 20, I had personally watched several groups “fall.” The card was already spreading widely through small chat groups, and its contents were becoming more varied too.

Up to that point, nothing serious had happened. People were simply using the card to kill time.
Around noon, however, the card’s reputation suddenly collapsed. Chat groups began banning it, and some people were muted for 30 days or even greeted with, “You have been removed from the group chat.”
The reason: someone in one group suddenly claimed that the card was a new kind of virus capable of capturing a phone’s IP address. Things had apparently become very serious:

So-called “stolen information” soon surfaced as well:

At that point, the incident changed completely. A harmless diversion became the “virus” card everyone was talking about. (The poor card suddenly found itself bearing an unbearable weight.) The rumor spread even faster than the card itself. Groups that had shared it and groups that had never seen it alike began circulating warnings far and wide:

Once the rumor reached people who understood computers, they naturally saw it for what it was:

How Does the Card Reply Automatically, and Is It Dangerous?
We found one expert’s answers and the accompanying chat logs, then condensed them into this short technical explanation:
Expert Rumor-Debunking Group (6)
Newbie (Me)
How does this card reply automatically?
Expert

These are two samples from the software. Anyone who made it through middle-school English can easily spot the keyword com.tencent.autoreply. The click-to-send automatic reply is clearly a function built into Tencent QQ itself. Tencent may have developed it for certain business needs. In this case, someone used features such as custom cards to replace Tencent’s official business card with one of their own, then sent it through a hidden API to produce this effect.
Newbie (Me)
So clicking it just triggers Tencent’s auto-reply feature, with none of the other risks people described online?
Expert
Yes. Opening or forwarding it normally causes no harm.
Tencent has a bot that automatically sends a similar card whenever someone joins a group, allowing it to welcome the newcomer. QQ Group Manager uses the same API in a more sophisticated way. As for the supposed JS plug-in and Flash, they simply do not exist. The card does not redirect to an external URL, so it cannot record an IP address. And the alleged packet capture… never mind what packets this person actually captured: even if a virus existed, messages from other users would go to the server, not through his device. He most likely captured outbound packets from software on his own computer or from QQ itself. If that were enough to produce the risks described online, he could go claim a major award.
To anyone who understands the technology, this is a nonissue. What followed was a long campaign to debunk the rumor…
Newbie (Me)
Then how was this thing made?
Expert
I will not get into the deeper details. The creator probably used unconventional means to call an interface that ordinary users should not be able to access. It could also have been a bug-based repeater or a bot running on a PC; there are plenty of ways to do this. People normally play with this kind of thing only in technical groups. Unfortunately, someone brought it into public view. (Shrugs ┑( ̄Д  ̄)┍)
Newbie (Me)
What happens next? Will it keep spreading?
Expert
If we are talking about the same “card,” my information says the blue text was first sent at 11:30 p.m. yesterday, September 19, and the last message went out at 5:47 this afternoon. Everything sent after that was intercepted. Generally speaking, as long as nobody does anything reckless, there should be no further problem.
╮( ̄▽ ̄"")╭
In short, Tencent created card functionality for its own business needs and allowed users to send cards—for example, invitations for Honor of Kings or Game for Peace. The interfaces were originally hidden and inaccessible to ordinary users. Some modified versions of QQ and some QQ bots can access them directly, allowing people to send custom content. Tencent also wrote the click-to-reply behavior. In form, this card is no different from the many others you see in QQ groups every day; only the content has changed.
So do not believe or spread rumors. If anyone sends this claim about the card to you or to one of your groups, send them this article 😄
P.S. Our thanks to the expert who wished to remain anonymous for answering our questions. Please credit the source and author when reposting.
P.P.S. At the same time last year, in September 2019, there really was a piece of rogue software: “An In-Depth Analysis of the ‘9.27 Audio Rogue Software’”. That “For the Best TA” software left plenty of people utterly mortified (laughs). Its timing was remarkably close to this year’s card incident—quite a coincidence!

