vx-underground
45.7K subscribers
3.92K photos
416 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
❀106😒67🫑21πŸ’―9πŸ‘7πŸ₯°4🀯2😱1πŸŽ‰1πŸ˜‡1😎1
Drama and discourse online as news circulates that Microsoft has "quietly removed the official way to active Windows 10 and/or 11 without internet connectivity".

As is tradition, nerds went fuckin' spazzo without reading into the issue more or questioning how and/or why this has happened.

Historically nerds unironically called Microsoft to activate Windows. Attempting to call Microsoft now to activate Windows you're greeted with an automated message informing you that you need to activate Windows online through the Microsoft Product Activation Portal

As is tradition, it is still possible to activate Windows (or install Windows) without an active internet connection. This can be performed by modifying the Windows installation files (installer.ISO image), using frameworks such as Windows Assessment and Deployment Kit.

tl;dr Microslop making things a pain in the ass, spazzo slightly less justified, 99% of people don't activate Windows over the phone (it's not 1995), but it's nice seeing people angry at Microslop
🀯43πŸ₯°12❀9πŸ‘9🀣4😁2
tl;dr teenager, later adult, role-plays in video game. is it terrorism? role-play? first amendment? real threat?

The United States Federal Bureau of Investigation is big mad.

In June, 2025, James Wesley Burger was all over social media when the United States Federal Bureau of Investigation indicted Mr. Burger, alleging he was planning a terrorist attack on Roblox. The insanity of this caused online discourse (mostly memes, mocking his name and mug shot), whereas people discussed the absurdity of planning terrorism over Roblox.

The United States Western District Court of Texas has told the FBI (in not so simple words) "nah lol prolly not".

Mr. Burger was an alleged Islamic State sympathizer and discussed plans of terrorism on Roblox. However, according to Mr. Burger's lawyer, and the Honorable Judge Alan Albright, the attempted prosecution of Mr. Burger is a First Amendment Violation (right to free speech). Mr. Burger's case has been dismissed.

The reason WHY it was a first amendment violation is because CONTEXT was missing from Mr. Burger's prosecution. In summary, the screenshots the FBI took of Mr. Burger on Roblox come from a role-playing game called "Church" where users making "anonymous" confessions and pretend to be historical, mythical, or fictitious characters. The United States Federal Bureau of Investigation assert Mr. Burger made concerning posts elsewhere too, such as 4chan, and he illustrated a behavior of attempted concealment, planning, etc.

The defense of Mr. Burger argued that Mr. Burger was trolling. Although he said dangerous things on the internet (Roblox), Mr. Burger does not and has not done anything in-real-life which would constitute him being a threat to anyone, including himself. Additionally, the defense asserts the FBI left out key details on Mr. Burger. Per court documents retrieved from Roblox, Mr. Burger was in "Church" (role-playing game) as an ANTIFA member, a neo-nazi, and subsequently an Islamic State sympathizer. The defense asserts the FBI was, in essence, seemingly indifferent or unaware of "extremist" role-playing until he role-played as a Jihadist.

Judge Albright has officially dismissed the case which has deeply frustrated the FBI. The FBI has stated they will make an appeal.
🀣125🀯7πŸ₯°4❀2πŸ‘1πŸ”₯1πŸŽ‰1
Ubisoft's Rainbow Six Siege has been compromised (again). Social media is filled with players complaining about being banned for "67 days", a reference to the "Six Seven" meme.
πŸ€“92😁35🀣23πŸ₯°9πŸ”₯5❀4🀯2πŸ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
❀82πŸ₯°26😍10πŸ˜‡4🀣2🀯1
Reports surfacing the United States government, working with allies from the United Kingdom, programmatically terminated electrical power to parts of Venezuela's capitol prior to United States military arrival.

tl;dr compromised Industrial Control System, turned off power
😒43😎14❀10πŸ₯°4πŸ”₯1
vx-underground
Reports surfacing the United States government, working with allies from the United Kingdom, programmatically terminated electrical power to parts of Venezuela's capitol prior to United States military arrival. tl;dr compromised Industrial Control System…
It should be noted that this is not unheard of. The Russian government, Chinese government, and (historically) the United States government have performed similar actions in the past. It is ICS/SCADA malware. Most notably, Stuxnet and BlackEnergy
πŸ”₯37❀8πŸ‘6😎2😱1
vx-underground
Reports surfacing the United States government, working with allies from the United Kingdom, programmatically terminated electrical power to parts of Venezuela's capitol prior to United States military arrival. tl;dr compromised Industrial Control System…
Note:

Initially when it was reported the United States government utilized offensive cyber security operations to terminate power in the Venezuela capitol it was reported online the United Kingdom government was involved.

However, Sir Keir Starmer has denied these accusations. Starmer asserts the United Kingdom has no knowledge prior of what was happening in Venezuela and "the situation is unfolding rapidly".

In Starmer's defense, it is plausible it was SPECULATED the United Kingdom was involved (because they have been historically) and the speculation was misreported and/or regurgitated as fact (classic misinformation).

Politicians in the United Kingdom have called on Starmer to condemn the United States government, as well as President Donald Trump, for the operations which occurred in Venezuela.

Opinion:
It appears it was misinformation online, hence Starmer had to go on the record and deny involvement. However, it would not surprise me if the United Kingdom was actually secretly involved (in a currently unknown capacity). The United States government and United Kingdom government have referred to each other as "their strongest ally(ies)" and have for decades been strong partners in offensive cybersecurity operations.

This partnership was solidified in or around 2014 (via Snowden Leaks) the United Kingdom GCHQ, in collaboration with the United States NSA, developed "Regin", which was (unironically) an incredibly sophisticated malware payload designed for telecommunication espionage. Additionally, the United Kingdom GCHQ was tied to Operation Socialist, TEMPORA, and still classified ISIS-related offensive cyber operations (confirmed by the United States government).

This information is nearly a decade old.

Do I think the United Kingdom has stopped partnering with the United States government for state-sponsored offensive cybersecurity operations (hacking)? No.

Would it be surprisingly the United Kingdom was involved in operations against Venezuela? No.

Do I believe the United Kingdom would deny involvement? Yes
❀38πŸ‘11
vx-underground
Note: Initially when it was reported the United States government utilized offensive cyber security operations to terminate power in the Venezuela capitol it was reported online the United Kingdom government was involved. However, Sir Keir Starmer has denied…
tl;dr misinformation online, uk says not involved, wouldnt be surprised if uk involved, us and uk are best frens and always doing something sketchy together
πŸ€“33πŸ‘12❀1😒1πŸ’―1
Hello,

I've pushed some updates to the malware store. Please look at the malware and/or download the malware. I pushed more after Christmas, but I forgot I did, but whatever.

pic: unrelated

https://vx-underground.org/Updates
πŸ₯°34🫑9❀4😎2
This media is not supported in your browser
VIEW IN TELEGRAM
I can't post this on Twitter because the nerds on Twitter wouldn't get it. Telegram gets it though.
πŸ”₯127❀21😁9πŸ₯°8🀣4😎3πŸ€“1
The internet is cool and badass. You can just do things.

I found a man on YouTube who has repeatedly recorded himself knocking himself unconscious by performing WWE-like stunts onto things such as microwaves.

I'm not entirely sure of his motivations, but this person is so unusual I went WAY out of my way to acquire their autograph.

I subsequently framed it and placed it on my wall.
🀣70❀12😒7πŸ”₯2🫑2πŸ₯°1
Microsoft is so fucking stupid.

Microsoft renamed Microsoft Office to Microsoft 365 Copilot App

I'm not joking
🀣228😒28🀯7πŸ₯°4❀3😱3😁2😎2
πŸ”₯74😁19🫑9😒7πŸŽ‰3❀2πŸ₯°1πŸ‘1
In 2025 there was approx. 996 malware defense and/or detection research papers released.
πŸ€“48πŸ₯°7❀5πŸ‘3
vx-underground
In 2025 there was approx. 996 malware defense and/or detection research papers released.
AND YALL MFERS ASKING "OHHH HOW DO I GET INTO MALWARE REVERSE ENGINEERING" READ LITERALLY ZERO

wAK=E UP BRO, LOCK IN
πŸ₯°51πŸ’―26πŸ€“12🀣5πŸ€”2πŸ”₯1🀩1🫑1
Earlier today I made a post about over 900 malware research papers being released in 2025. Some people expressed confusion about this. Let's talk about malware research, what it entails, blah blah blah.

Malware research can be broken down into two distinct categories and from there it can be broken down further into more unique categories. Let's keep it shrimple.

- Offensive malware research
- Defensive malware research

Offensive malware research is trying to find new malware techniques. This is pretty broad. I won't go too much into detail on this. This isn't the thingie we're discussing here.

Defensive malware research is documenting new malware campaigns, tracking existing malware campaigns, reverse engineering malware and correlating it and/or tying it to other malware campaigns, techniques on malware detection, etc. This can be pretty broad too because malware detection, malware campaigns, anti-malware research, etc. will be vastly different on Windows, Linux, MacOS, mobile-devices, etc.

When I write that there was 996 malware research papers released what it means is (approx.) "996 vendors released papers sharing information on malware campaigns, reverse engineering malware, sharing malware detection techniques, malware family lineage discoveries (shared code across malware campaigns), etc".

Every single day I see vendors release paper documenting malware campaigns, what they're seeing on their side, and methods to detect the malware payloads. How they're discovered is also a different discussion for a different day.

Places where malware research is released:
- Basically every government on the planet
- Hundreds of independent researchers
- Google
- SentinelOne
- ESET
- Microsoft
- Kaspersky
- CrowdStrike
- RecordedFuture
- Cisco Talos
- VMWare
- CloudFlare
- Akamai
- HuntressLabs
- BitDefender (also Huntress?)
- Fortinet
- AVAST / AVG
- TrendMicro
- Sophos
- F-secure
- Panda
- Comodo
- Qihoo
- Dr. Web
- NVIDIA
- Norton
- MalwareBytes
- Secureworks
- ZScaler
- Okta
- Chainalysis
- Trustwave
- Nextron Systems
- GDATA
- AT&T
- Walmart
- StealthMole
- Censys
- AhnLab
- PtSecurity
- OxSecurity
- Securonix
- Koi-AI
- Palo Alto Networks
- CheckPoint
- Huorong
- Oligo
- Cyderes
- DarkTrace
- K7Computing
- CyberArmor
- ... more ....
πŸ₯°35πŸ‘16❀2
vx-underground
Earlier today I made a post about over 900 malware research papers being released in 2025. Some people expressed confusion about this. Let's talk about malware research, what it entails, blah blah blah. Malware research can be broken down into two distinct…
It should be noted that each vendor, or government, releases research which is tailored to them or their audience.

As you could probably assume, Microsoft rarely discusses MacOS malware.

Another interesting quirk is each vendor tailors research to their region. Vendors in China or Russia will discuss threats to the country they reside in. Hence, you can get unique insight into what is targeting countries outside the United States or NATO.

Believe it or not, while the United States says Russia and China launch offensive cybersecurity operations, China and Russia also accuse the United States (and allies) of targeting them as well! Strange stuff!
πŸ₯°30❀8😱6
I love Microslop

Copilot is enabled by default in the Microsoft Word 365 Copilot App. You have to go to settings and disable Microsoft Word 365 Copilot App Copilot
🀣34πŸ₯°30❀7😒6πŸ”₯3😍1