vx-underground
47.5K subscribers
4.1K photos
438 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
The absolute state of "hack tools". Hahahahaha. Image courtesy of malwrhunterteam
🤣57👍103🙊2🔥1💩1👌1😈1
Reddit was breached February 5th - the threat actors were able to exfiltrate internal documents and source code. Reddit confirmed the attack was conducted via a spear-phish.

Reddit is currently doing an AMA regarding the incident:
https://www.reddit.com/r/reddit/comments/10y427y/we_had_a_security_incident_heres_what_we_know/
👍18😁9🦄5🙊2🤔1😈1
vx-underground
Reddit was breached February 5th - the threat actors were able to exfiltrate internal documents and source code. Reddit confirmed the attack was conducted via a spear-phish. Reddit is currently doing an AMA regarding the incident: https://www.reddit.com/…
We would like to advise companies, of any size or demographic, to not hold public "AMAs" following a breach. The questions and comments presented by users on Reddit are ... interesting... posing questions such as "Why didn't the employee use a password manager?"
😁16🙊61👍1🔥1😈1
This media is not supported in your browser
VIEW IN TELEGRAM
Modern day cyber security explained featuring:

- Reddit
- Microsoft (Bing)
- Rockstar Games
- NVIDIA
- Okta
- Uber
- Ubisoft
- Samsung
- Riot Games
🤣105😁24👍52😈1😭1
We've updated the vx-underground paper collection

- 2022-10-22 - WAM BAM - Recovering Web Tokens From Office
- 2023-02-09 - Transitioning from UM to KM - Extravagant Prick
- 2023-02-10 - Forensic Log-Based Detection of Keystroke Injection BadUSB Attacks

https://www.vx-underground.org/
👍7🔥2🤡1😈1
February 8th Avast announced the discovery of a Threat Actor targeting users through DOTA2.

DOTA contained an outdated build of V8 which the Threat Actor exploited through malicious game mods. V8 was not sandboxed.

Incredible read here: https://decoded.avast.io/janvojtesek/dota-2-under-attack-how-a-v8-bug-was-exploited-in-the-game/
🤡15👍6💋2🔥1😈1
This media is not supported in your browser
VIEW IN TELEGRAM
The Windows OS needs to stop forcing updates on users before this man implodes like a dying sun

*Warning: extremely loud, swearing. Don't wanna blow your ear drums:)
👍27😁15🤣9🤬4😈1
We've updated the vx-underground malware sample collection.

- Virusshare 0458, Virusshare0459
- 80,000+ unique samples
- All named using Kaspersky naming convention

Check it out here: https://samples.vx-underground.org/samples/Blocks/
👍7💩1🤡1😈1
Twitter administration have determined making access to the Twitter API exclusively an enterprise privilege to be ... not ideal.

They have implemented free and limited usage which will suffice for our RansomwareNews bot.

tl;dr RansomwareNews bot not going anywhere.

https://twitter.com/RansomwareNews
20👍4💋2💩1🤡1🥱1🐳1🍌1😈1
We've updated the vx-underground Windows malware paper collection. The latest additions demostrate the following:

- Unhooking NTDLL from Disk
- Unhooking NTDLL from KnownDlls
- Unhooking NTDLL from Remote Server
- Unhooking NTDLL from Suspended Process

https://www.vx-underground.org/
👍8🤡7💩4🔥3💋2😈1
Ransomware but instead of encrypting files and extorting your company, it makes you watch corporate compliance training videos on repeat
🤯44😁14🔥6😱4💩3👍2😈2🎅2
Microsoft in 2023: Windows 11 will allow tabs in the Windows Explorer!

Microsoft in 1995:
😭67👍27😁19💩8😐7🤡42🥰2😱1💔1😈1
The Israel Institute of Technology was hit by ransomware this morning.

- DarkBit ransomware (???)
- Ransom note is political
- Attackers want $1,700,000+ (80 BTC)
- Ransom note is written using an English translator

Image courtesy of CyberIL
🤡49👏39🤣97💩7👍2🐳2😈2😁1
We've made some improvements to The Old New Thing archive. All papers from Raymond Chen are organized by year, month, and now date.

Thanks _BradleyVX for the additions

Check it out here: https://www.vx-underground.org/the_old_new_thing.html
17💩2😈2🤡1
This media is not supported in your browser
VIEW IN TELEGRAM
.@CrowdStrike had an American Super Bowl LVII commercial this year. This may be the first cyber security product advertisement in Super Bowl history

The estimated Super Bowl LVII advertisement commercial cost is $6,500,000 for 30 seconds.
35🤡27👍3💩2🥰1🐳1😈1🙈1
This media is not supported in your browser
VIEW IN TELEGRAM
Behold the latest addition to the Marvel cinematic universe: IRQL_NOT_LESS_OR_EQUAL man
🤣47😁11🤡4💩3😈2
The United States government in 2022: We are competing (?) with Russia and China with high-altitude surveillance balloons

The United States government in 2023: The usage of high-altitude surveillance balloons is bad, we would never do that

tl;dr Balloon wars 🎈🎈
🤡48🤣172🤔2💩2👎1🤩1😈1
Hi,

tl;dr Doctor told me to stop or I'll drop dead at 40 from a heart attack
139😢59👍5❤‍🔥4💊41🤣1👻1