vx-underground
47.5K subscribers
4.1K photos
438 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
No major updates today. We are busy.

Please accept this image of a cat as a token of an apology.
🀩580πŸ‘381πŸ‘335❀333πŸ”₯148πŸ₯°144🫑11🀣7❀‍πŸ”₯5πŸ€ͺ3😍1
The 3CX supply chain attack was the result of previously undiscovered X-Trader supply chain attack

The 3CX CEO wasn't lying about an upstream vendor being the result of the compromise.

tl;dr supply chain attack to supply chain attack

More information: https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise
😱12πŸ‘7❀2😍2πŸ’―1
February 21st, 2023, ALPHV ransomware group informed their affiliates of a new 'product' update.

Their new ransomware variant is named Sphynx.
πŸ‘14🫑7πŸ”₯2❀1
We've updated the vx-underground malware sample collection. We have added new samples for the following families:

- Nanocore
- AsyncRAT
- NetwireRAT
- AgentTesla
- LokiBot
- Formbook
- CobaltStrike
- NjRat
- Chaos Ransomware

Check it out here: https://samples.vx-underground.org/samples/Families/
❀14πŸ”₯7πŸ‘2
You can subscribe to vx-underground Blueβ„’ for only $5.99/month.

Nothing is different, but you get a wear a dunce hat
πŸ’―41🀣29πŸ”₯4🀩4πŸ‘1πŸŽ‰1
Today someone stole 3,600lbs (1632kg) of Gold from the Toronto Pearson Airport. It is valued at roughly $100,000,000.

The police currently have no suspects. Unrelated to malware of course, but such a ballsy heist is impressive.

More information:
https://www.cbc.ca/news/canada/toronto/gold-heist-pearson-airport-toronto-1.6817345
🫑43πŸ₯°18❀5πŸ‘4πŸ‘2😁1🀩1😘1
An unknown Threat Actor has compromised the European Union's web domain and is using it to distribute Fortnite V-Bucks scams...

They've also compromised 15 other high-profile websites. See full list in attached image below.

Information via g0njxa and Gi7w0rm
🀣66πŸ‘3❀2πŸ‘2
Use Twitter image description feature as a C2.

See example in attached link: https://twitter.com/vxunderground/status/1649251062820249600
πŸ₯°13πŸ’―2🫑2❀1
The European Union likes distributing malware

Information via bigfack
🀣79πŸ‘5❀4
ALPHV ransomware group modus operandi has changed. The recent victim postings tone has changed significantly. They do not come across as calm and professional as ALPHV traditionally has.

Someone is new to their group and much more vocal.

Image 1. New ALPHV
Image 2. Old ALPHV
🀣27❀5πŸ”₯4😁3😱2
Symantec Threat Hunter Team discovered the X-Trader supply chain attack, which resulted in the 3CX supply chain attack, hit critical infrastructure - European and American electrical grid suppliers

More information: https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/xtrader-3cx-supply-chain
😱14πŸ‘2🫑2❀1πŸ‘1
There is a direct correlation between hours of anime watched and reverse engineering skills.

The longer someone watches anime, the better they are at reverse engineering.

Scientists do not know why.
πŸ‘57🀣32😱17🫑11🀯7❀5πŸ”₯3😁3πŸ’―3😒2🀩2
Andy Greenberg's book "Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency" is an incredible book. It reads well. It allows a reader to understand the flaws in cryptocurrency and truly emphasizes the incredible research by people like Sarah Meiklejohn.

This isn't an advertisement for him - this book is genuinely an amazing read. Shoutout to Andy.
πŸ’―56❀14πŸ‘9πŸ”₯7πŸŽ‰3
We've updated the vx-underground malware sample collection. We have added new samples for the following families:

- AgentTesla
- AsyncRAT
- WhisperGate
- RagnarLocker
- YoungLotus
- Blackmoon
- Emotet
- Remcos
- Trickbot

Check it out here: https://samples.vx-underground.org/samples/Families/
πŸ”₯16πŸ‘5
Suicide is not the answer. Seeking help is a sign of strength.
❀123πŸ‘12🀣12🫑9❀‍πŸ”₯6πŸ€”3πŸ€ͺ3πŸ‘1
We've updated the vx-underground malware source code collection. We've added Win32.SimpleWalletClipper.Xss.

Special thanks to BasssterLord/NationalHazardAgency for getting the source code for us.

Check it out here: https://github.com/vxunderground/MalwareSourceCode/tree/main/Win32/Stealers
❀‍πŸ”₯10❀4πŸ‘1πŸ”₯1😁1
We've updated the vx-underground malware collection.

- InTheWild.0067

We have added new samples for the following families:

- BlackCatRansomware
- FormBook
- AsyncRAT
- Amadey
- Danabot
- Emotet
- WhisperGate
- LokiBot
- Remcos

Check it out here: https://vx-underground.org/malware.html
πŸ‘14❀‍πŸ”₯3
The password to all of our archives is 'infected'

The compressed files we create, which is created from Linux or Windows OS's, are not natively compatible with MacOS

MacOS uses a different methodology to compress files and directories. The 'unzip' utility will not work, sorry.
😁47😒5πŸ™3😘2