vx-underground
47.6K subscribers
4.11K photos
439 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Twitter users are reporting that the classic Twitter bird icon has been replaced with an image of Doge.

Why? Please select one of the following options.
Anonymous Poll
40%
Crypto pump and dump scheme
23%
Late April Fools
7%
Bad code pushed to Prod
30%
Unfunny joke
๐Ÿคฃ33โค4
We've updated the vx-underground Malware Defense collection. We've added 144 news papers.

Data via malpedia. Special thanks to @BradleyVX for aggregating it.

Check it out here: https://www.vx-underground.org/malware_defense.html
๐Ÿ‘18โคโ€๐Ÿ”ฅ2
The open sourced Twitter algorithm has been assigned its first CVE: CVE-2023-29218.

tl;dr denial of service via reduction of reputation score

Intel via Ax_Sharma

More information: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-29218
๐ŸŽ‰33โค7๐Ÿ‘4
Our malware database will be moving into beta soon. It will be free and publicly available. We will also open source it.

It is bare bones, but it will allow you to search for malware samples by hash

We did this on a budget of $0. We rely on your donations to survive.

Thank you
โค89๐Ÿ‘6๐Ÿ”ฅ1
We will also allow individuals to upload their own malware samples discovered.

*vetted researchers, so it is not junk malware

More to come. All thanks to the hard work of guessthepw and DuchyRE

Final note: this is not meant to compete with any vendor. This is to allow individuals, researchers, or the morbidly curious, a way to get malware samples without costing a fortune.

tl;dr free education, free information
โคโ€๐Ÿ”ฅ49โค10๐Ÿ”ฅ4๐Ÿ‘2
Yesterday we tweeted IntelBroker had compromised the United States Citizenship and Immigration Services by discovering a publicly exposed AWS bucket.

Today the USCIS released a public statement regarding the incident.

tl;dr they state it is a vendor provided demo account
๐Ÿคฃ51โค8๐Ÿคช5๐Ÿ‘4
Genesis market, the infamous initial access brokerage forum, has been seized by the United States Department of Justice in cooperation with EUROPOL in what was named "Operation Cookie Monster".
๐Ÿซก66๐Ÿ˜ข17โค3๐Ÿ‘3๐Ÿค”2๐Ÿ’ฏ2๐Ÿคช2
Also, this image asserts that the FBI wears hoodies while browsing the internet. Strange.
๐Ÿคฃ76๐Ÿ˜10๐Ÿซก3๐Ÿ˜ฑ2๐Ÿ‘1๐Ÿค”1๐Ÿคฏ1
There is a void in the cyber crime marketplace. It is time vx-underground capitalizes on this.

We plan on launching our own cybercrime forum soon. It will primarily be pictures of cats.

vx-honeypot-raidforums-breached-genesis-underground.org.
๐Ÿ‘49๐Ÿซก31๐Ÿ˜15๐Ÿฅฐ11โค6๐Ÿ”ฅ6๐Ÿคฃ4๐Ÿคฏ2
GenesisMarket administrative staff has 'apologized for the inconvenience' of having their domain seized by EUROPOL. Meanwhile, the BBC reports over 120 people internationally have been arrested in connection to GenesisMarket.

Information via @amartinsec
๐ŸŽ‰31๐Ÿซก8๐Ÿ˜6๐Ÿ‘1
The GenesisMarket domain seizure was a coordinated international effort involving 17 countries.
๐Ÿ˜ข35๐Ÿ‘7๐Ÿซก5โค3
Registration for our malware database beta will go live later today. It is a simple way to search through our malware database.

Verified users can submit malware samples of their own.

https://vxu.fly.dev/
๐Ÿ‘29๐Ÿ”ฅ8โค2๐Ÿ‘1
Our malware database is to act as a search engine for our malware collection. Samples will be submitted to virustotal or hatching_io or Malcoreio.

Work still needs to be done, here is preview images
๐Ÿ‘36๐Ÿ˜ฑ4๐Ÿฅฐ3
This media is not supported in your browser
VIEW IN TELEGRAM
The National Crime Agency of the United Kingdom has released some footage of Genesis Market arrests.
๐Ÿคฃ55๐Ÿซก15๐Ÿ˜4๐Ÿคช3โค2๐Ÿฅฐ1๐Ÿ˜˜1
The United States Department of Justice has released documents regarding the Genesis Market domain seizure.

The FBI got a copy of the Genesis Market backend December 9th, 2020. They were able to get usernames, passwords, emails, Jabber accounts, BTC addresses, etc.

You can read the full document here: https://s3.documentcloud.org/documents/23742615/genesis-market.pdf
๐Ÿ˜ฑ26๐Ÿคฏ8๐Ÿ‘7๐Ÿคช4๐Ÿ˜ข1๐Ÿซก1
Media is too big
VIEW IN TELEGRAM
The Polish CBZC (Central Bureau for Combating Cybercrime) has released some footage of Genesis Market arrests
๐Ÿคฃ30๐Ÿ˜ฑ5๐Ÿ‘4๐Ÿคฏ3๐Ÿ”ฅ1๐Ÿ˜1๐Ÿคช1
Karakurt extortion group is back.
๐Ÿคฃ42๐Ÿ‘12๐Ÿ”ฅ9๐Ÿ˜4โค1๐Ÿ’ฏ1
Hello.

Our new malware database is not quite ready yet. We very briefly enabled registration for testing and you nerds came flooding in. The registration was enabled for less than 15 minutes....

Are you nerds just sitting there smashing refresh? Geez.
๐Ÿคช42๐Ÿคฃ17๐Ÿซก8๐Ÿ‘6๐Ÿ”ฅ5๐Ÿ‘1๐Ÿ˜1
Paper Trail Media, an investigative journalist group based out of Mรผnchen, has released 660 pages of Vulkan file documents.

The Vulkan files are Russian military and intelligence documents - specifically for cyberwarfare.

You can check it out here: https://www.documentcloud.org/app?q=%2Borganization%3Apaper-trail-media-40926
๐Ÿ”ฅ41๐Ÿซก9๐Ÿ‘6๐Ÿคช4โค1๐Ÿ˜ข1