vx-underground
47.5K subscribers
4.1K photos
438 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
We've updated the vx-underground Windows Malware Paper collection

-2022-01-28: The good the bad & the stomped function
-2023-01-29: Indirect Syscall is Dead Long Live Custom Call Stacks
-2023-02-14: Adopting PIC from Object Files for Threadless Injection

https://vx-underground.org/windows.html
๐Ÿคก2๐Ÿ‘1
Roses are Red,
Violets are Blue,
We were busy uploading malware on Valentines day,
So download this shit boo โ™ฅ๏ธ

- InTheWild.0061
- 20,000+ unique malware samples
- Courtesy of petikvx


Download here: https://samples.vx-underground.org/samples/Blocks/
๐Ÿฅฐ40๐Ÿ‘5๐Ÿ˜2๐Ÿคฎ2๐Ÿคก2๐Ÿคฏ1
Hello,

The chatroom has been deleted for the time being (again, deletion #2). Too many complaints have come in from social media regarding the channel. Moderation is insufficient - we do not have enough time or resources to moderate appropriately. Additionally, the channels purpose was to discuss malware, the topic was more often than not, not malware.

At a later period of time, when we have sufficient resources, the chatroom will return to allow discussions on posts, etc.
๐Ÿ˜ข38๐Ÿ‘17๐Ÿคฃ9๐Ÿคช6๐Ÿซก5๐Ÿ‘3โค1
We've updated the vx-underground Linux malware paper collection

- 2020-05-20 - Code injection in running process using ptrace
- 2020-08-16 - Process Injection On Linux
- 2022-10-12 - A Technical overview of Code Injection

Check it out here: https://vx-underground.org/linux.html
โค8
We've updated the vx-underground ICS SCADA collection

- 2017-06-12 - Win32-Industroyer A New Threat for Industrial Control Systems
- 2022-04-12 - Industroyer2 Industroyer Reloaded
- 2022-06-01 - Industroyer vs. Industroyer2

Check it out here: https://vx-underground.org/ics_scada.html
โคโ€๐Ÿ”ฅ2๐Ÿ‘1
February 14th, United States Republican Congressman Clay Higgins tweeted that he is working on passing legislation that allows life imprisonment, without the possibility of parole, for cyber criminals.

He also makes a snarky remark about ... weight?
๐Ÿคช64๐Ÿคฏ7๐Ÿคฃ7๐Ÿ”ฅ4๐Ÿ˜ฑ3
๐Ÿซก71๐Ÿ’ฏ11๐Ÿคช6๐Ÿค”5๐Ÿ™3๐Ÿ˜2๐Ÿ‘1๐Ÿ”ฅ1
GoDaddy has stated an unknown Threat Actor has maintained persistent access to their network since at least 2019. The Threat Actor unveiled themselves 4 times, without losing access, in 2019, 2020, 2021, and 2022

Intel via Gi7w0rm

More information: https://www.bleepingcomputer.com/news/security/godaddy-hackers-stole-source-code-installed-malware-in-multi-year-breach/
๐Ÿคฃ59๐Ÿ˜9๐Ÿคช8๐Ÿซก7๐Ÿ”ฅ3๐Ÿ˜ฑ3๐Ÿ‘2๐Ÿฅฐ1๐Ÿคฉ1
We've updated the vx-underground Linux malware paper collection

2017-08-16 - Understanding the Mirai Botnet
2018-04-20 - Wifatch - Atypical Malware
2022-02-25 - Behavior Anomaly on Linux Systems to Detect Zero-day Malware Attacks

Check it out here: https://vx-underground.org/linux.html
๐Ÿ‘14โค5๐Ÿ”ฅ2๐Ÿคฏ1
Activision was breached December 4th, 2022. The Threat Actors successfully phished a privileged user on the network. They exfiltrated sensitive work place documents as well as scheduled to be released content dating to November 17th, 2023.

Activision did not tell anyone.
๐Ÿคฃ40๐Ÿ‘13๐Ÿซก6๐Ÿค”2๐Ÿ˜˜2๐Ÿ˜1
Also worth noting that the Threat Actor(s) did attempt to phish other employees. Other employees did not fall for the phish. However, it appears they did not report the security incident to the Activision Information Security Team
๐Ÿคฃ84๐Ÿ˜7๐Ÿ‘5๐Ÿคช4๐Ÿค”1
We've updated the vx-underground Linux malware paper collection

- 2013-02-10 - Shellcoding in Linux
- 2018-04-17 - The Shellcode Injection Process
- 2022-02-20 - Targeted process injection on Linux

Check it out here: https://www.vx-underground.org/linux.html
๐Ÿ”ฅ9๐Ÿคช4
New vx-underground proof-of-concept art by deinacrida_art
๐Ÿ‘14โค5๐Ÿค”5๐Ÿ˜ข1
We've updated the vx-underground InTheWild collection. We've added 20,000 new malicious binaries for download.

Special thanks to petikvx for aggregating the samples for us.

Check it out here: https://samples.vx-underground.org/samples/Blocks/
โค6๐Ÿ‘3๐Ÿค”1
"The hacker group known as vx-underground"

x100,000 angry monkey bonks
๐Ÿคฃ133๐Ÿ˜6๐Ÿ’ฏ5๐Ÿ‘3๐Ÿ˜3๐Ÿคช2โคโ€๐Ÿ”ฅ1๐Ÿ”ฅ1
This media is not supported in your browser
VIEW IN TELEGRAM
What's the password?
๐Ÿ˜60โค19๐Ÿฅฐ14๐Ÿคฃ13โคโ€๐Ÿ”ฅ7๐Ÿค”5๐Ÿ‘4๐Ÿคช3๐Ÿ˜ฑ2๐Ÿ˜ข2๐Ÿคฏ1
Dole Food Company, an Irish agricultural multinational corporation, among one of the largest producers of fruits and vegetables, with over 38,000 employees and $6,500,000,000 in annual revenue, has been hit by ransomware.

Intel and photo via BleepinComputer
๐Ÿ”ฅ25๐Ÿคฉ5๐Ÿฅฐ3๐Ÿ‘2๐Ÿ˜ข2
The United States Department of Justice announced the arrest & extradition of Russian citizen Dariy Pankov

Pankov is alleged to be the developer of NLBrute. He was arrested in Georgia, believing he left Russia to avoid the draft.

More information: https://www.justice.gov/usao-mdfl/pr/russian-malware-developer-arrested-and-extradited-united-states
๐Ÿคฃ40๐Ÿ˜ข9๐Ÿ‘3๐Ÿ˜2๐Ÿ˜ฑ2๐ŸŽ‰1