vx-underground
47.5K subscribers
4.1K photos
438 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
We've updated the vx-underground malware sample collection.

- Virusshare 0458, Virusshare0459
- 80,000+ unique samples
- All named using Kaspersky naming convention

Check it out here: https://samples.vx-underground.org/samples/Blocks/
👍7ðŸ’Đ1ðŸĪĄ1😈1
Twitter administration have determined making access to the Twitter API exclusively an enterprise privilege to be ... not ideal.

They have implemented free and limited usage which will suffice for our RansomwareNews bot.

tl;dr RansomwareNews bot not going anywhere.

https://twitter.com/RansomwareNews
âĪ20👍4💋2ðŸ’Đ1ðŸĪĄ1ðŸĨą1ðŸģ1🍌1😈1
We've updated the vx-underground Windows malware paper collection. The latest additions demostrate the following:

- Unhooking NTDLL from Disk
- Unhooking NTDLL from KnownDlls
- Unhooking NTDLL from Remote Server
- Unhooking NTDLL from Suspended Process

https://www.vx-underground.org/
👍8ðŸĪĄ7ðŸ’Đ4ðŸ”Ĩ3💋2😈1
Ransomware but instead of encrypting files and extorting your company, it makes you watch corporate compliance training videos on repeat
ðŸĪŊ44😁14ðŸ”Ĩ6ðŸ˜ą4ðŸ’Đ3👍2😈2🎅2
Microsoft in 2023: Windows 11 will allow tabs in the Windows Explorer!

Microsoft in 1995:
😭67👍27😁19ðŸ’Đ8😐7ðŸĪĄ4âĪ2ðŸĨ°2ðŸ˜ą1💔1😈1
The Israel Institute of Technology was hit by ransomware this morning.

- DarkBit ransomware (???)
- Ransom note is political
- Attackers want $1,700,000+ (80 BTC)
- Ransom note is written using an English translator

Image courtesy of CyberIL
ðŸĪĄ49👏39ðŸĪĢ9âĪ7ðŸ’Đ7👍2ðŸģ2😈2😁1
We've made some improvements to The Old New Thing archive. All papers from Raymond Chen are organized by year, month, and now date.

Thanks _BradleyVX for the additions

Check it out here: https://www.vx-underground.org/the_old_new_thing.html
âĪ17ðŸ’Đ2😈2ðŸĪĄ1
This media is not supported in your browser
VIEW IN TELEGRAM
.@CrowdStrike had an American Super Bowl LVII commercial this year. This may be the first cyber security product advertisement in Super Bowl history

The estimated Super Bowl LVII advertisement commercial cost is $6,500,000 for 30 seconds.
âĪ35ðŸĪĄ27👍3ðŸ’Đ2ðŸĨ°1ðŸģ1😈1🙈1
This media is not supported in your browser
VIEW IN TELEGRAM
Behold the latest addition to the Marvel cinematic universe: IRQL_NOT_LESS_OR_EQUAL man
ðŸĪĢ47😁11ðŸĪĄ4ðŸ’Đ3😈2
The United States government in 2022: We are competing (?) with Russia and China with high-altitude surveillance balloons

The United States government in 2023: The usage of high-altitude surveillance balloons is bad, we would never do that

tl;dr Balloon wars 🎈🎈
ðŸĪĄ48ðŸĪĢ17âĪ2ðŸĪ”2ðŸ’Đ2👎1ðŸĪĐ1😈1
Hi,

tl;dr Doctor told me to stop or I'll drop dead at 40 from a heart attack
âĪ139ðŸ˜Ē59👍5âĪ‍ðŸ”Ĩ4💊4⚡1ðŸĪĢ1ðŸ‘ŧ1
This media is not supported in your browser
VIEW IN TELEGRAM
We are happy to announce we are hosting our first ever Malware Research Contest! Sponsored by our friends at SentinelOne


* Must be novel research
* Applicants can only be from the United States due to anti-gambling and money laundering laws
* First place is a new Macbook Pro â™Ĩïļ
ðŸĪĄ40âĪ19💘12ðŸ”Ĩ11👍8ðŸ’Đ8🖕6ðŸ˜Ē1
We've updated the vx-underground Windows Malware Paper collection

-2022-01-28: The good the bad & the stomped function
-2023-01-29: Indirect Syscall is Dead Long Live Custom Call Stacks
-2023-02-14: Adopting PIC from Object Files for Threadless Injection

https://vx-underground.org/windows.html
ðŸĪĄ2👍1
Roses are Red,
Violets are Blue,
We were busy uploading malware on Valentines day,
So download this shit boo â™Ĩïļ

- InTheWild.0061
- 20,000+ unique malware samples
- Courtesy of petikvx


Download here: https://samples.vx-underground.org/samples/Blocks/
ðŸĨ°40👍5😁2ðŸĪŪ2ðŸĪĄ2ðŸĪŊ1
Hello,

The chatroom has been deleted for the time being (again, deletion #2). Too many complaints have come in from social media regarding the channel. Moderation is insufficient - we do not have enough time or resources to moderate appropriately. Additionally, the channels purpose was to discuss malware, the topic was more often than not, not malware.

At a later period of time, when we have sufficient resources, the chatroom will return to allow discussions on posts, etc.
ðŸ˜Ē38👍17ðŸĪĢ9ðŸĪŠ6ðŸŦĄ5👏3âĪ1
We've updated the vx-underground Linux malware paper collection

- 2020-05-20 - Code injection in running process using ptrace
- 2020-08-16 - Process Injection On Linux
- 2022-10-12 - A Technical overview of Code Injection

Check it out here: https://vx-underground.org/linux.html
âĪ8
We've updated the vx-underground ICS SCADA collection

- 2017-06-12 - Win32-Industroyer A New Threat for Industrial Control Systems
- 2022-04-12 - Industroyer2 Industroyer Reloaded
- 2022-06-01 - Industroyer vs. Industroyer2

Check it out here: https://vx-underground.org/ics_scada.html
âĪ‍ðŸ”Ĩ2👍1
February 14th, United States Republican Congressman Clay Higgins tweeted that he is working on passing legislation that allows life imprisonment, without the possibility of parole, for cyber criminals.

He also makes a snarky remark about ... weight?
ðŸĪŠ64ðŸĪŊ7ðŸĪĢ7ðŸ”Ĩ4ðŸ˜ą3
ðŸŦĄ71ðŸ’Ŋ11ðŸĪŠ6ðŸĪ”5🙏3😁2👍1ðŸ”Ĩ1