Yes. Yesterday, I was helping a friend, and I found everything through the crontab. That led me to discover the malware installations, quarantine them, and implement an API guard in the chatplan so that it rejects API requests without requiring us to disable chat or enable authorization...