We've updated the vx-underground malware sample collection. We have added new samples for the following families:
- Nanocore
- AsyncRAT
- NetwireRAT
- AgentTesla
- LokiBot
- Formbook
- CobaltStrike
- NjRat
- Chaos Ransomware
Check it out here: https://samples.vx-underground.org/samples/Families/
- Nanocore
- AsyncRAT
- NetwireRAT
- AgentTesla
- LokiBot
- Formbook
- CobaltStrike
- NjRat
- Chaos Ransomware
Check it out here: https://samples.vx-underground.org/samples/Families/
âĪ14ðĨ7ð2
Today someone stole 3,600lbs (1632kg) of Gold from the Toronto Pearson Airport. It is valued at roughly $100,000,000.
The police currently have no suspects. Unrelated to malware of course, but such a ballsy heist is impressive.
More information:
https://www.cbc.ca/news/canada/toronto/gold-heist-pearson-airport-toronto-1.6817345
The police currently have no suspects. Unrelated to malware of course, but such a ballsy heist is impressive.
More information:
https://www.cbc.ca/news/canada/toronto/gold-heist-pearson-airport-toronto-1.6817345
CBC
$20M worth of gold, other items stolen in 'very rare' heist at Pearson Airport, police say | CBC News
Peel police are investigating the theft of a "high value container" with items worth an estimated $20 million from Toronto's Pearson Airport early Monday evening.
ðŦĄ43ðĨ°18âĪ5ð4ð2ð1ðĪĐ1ð1
An unknown Threat Actor has compromised the European Union's web domain and is using it to distribute Fortnite V-Bucks scams...
They've also compromised 15 other high-profile websites. See full list in attached image below.
Information via g0njxa and Gi7w0rm
They've also compromised 15 other high-profile websites. See full list in attached image below.
Information via g0njxa and Gi7w0rm
ðĪĢ66ð3âĪ2ð2
Use Twitter image description feature as a C2.
See example in attached link: https://twitter.com/vxunderground/status/1649251062820249600
See example in attached link: https://twitter.com/vxunderground/status/1649251062820249600
X (formerly Twitter)
vx-underground (@vxunderground) on X
Use Twitter image description feature as a C2
ðĨ°13ðŊ2ðŦĄ2âĪ1
ALPHV ransomware group modus operandi has changed. The recent victim postings tone has changed significantly. They do not come across as calm and professional as ALPHV traditionally has.
Someone is new to their group and much more vocal.
Image 1. New ALPHV
Image 2. Old ALPHV
Someone is new to their group and much more vocal.
Image 1. New ALPHV
Image 2. Old ALPHV
ðĪĢ27âĪ5ðĨ4ð3ðą2
Symantec Threat Hunter Team discovered the X-Trader supply chain attack, which resulted in the 3CX supply chain attack, hit critical infrastructure - European and American electrical grid suppliers
More information: https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/xtrader-3cx-supply-chain
More information: https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/xtrader-3cx-supply-chain
Security
X_Trader Supply Chain Attack Affects Critical Infrastructure Organizations in U.S. and Europe
North Korean-linked operation affected more organizations beyond 3CX, including two critical infrastructure organizations in the energy sector.
ðą14ð2ðŦĄ2âĪ1ð1
There is a direct correlation between hours of anime watched and reverse engineering skills.
The longer someone watches anime, the better they are at reverse engineering.
Scientists do not know why.
The longer someone watches anime, the better they are at reverse engineering.
Scientists do not know why.
ð57ðĪĢ32ðą17ðŦĄ11ðĪŊ7âĪ5ðĨ3ð3ðŊ3ðĒ2ðĪĐ2
Andy Greenberg's book "Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency" is an incredible book. It reads well. It allows a reader to understand the flaws in cryptocurrency and truly emphasizes the incredible research by people like Sarah Meiklejohn.
This isn't an advertisement for him - this book is genuinely an amazing read. Shoutout to Andy.
This isn't an advertisement for him - this book is genuinely an amazing read. Shoutout to Andy.
ðŊ56âĪ14ð9ðĨ7ð3
We've updated the vx-underground malware sample collection. We have added new samples for the following families:
- AgentTesla
- AsyncRAT
- WhisperGate
- RagnarLocker
- YoungLotus
- Blackmoon
- Emotet
- Remcos
- Trickbot
Check it out here: https://samples.vx-underground.org/samples/Families/
- AgentTesla
- AsyncRAT
- WhisperGate
- RagnarLocker
- YoungLotus
- Blackmoon
- Emotet
- Remcos
- Trickbot
Check it out here: https://samples.vx-underground.org/samples/Families/
ðĨ16ð5
We've updated the vx-underground malware source code collection. We've added Win32.SimpleWalletClipper.Xss.
Special thanks to BasssterLord/NationalHazardAgency for getting the source code for us.
Check it out here: https://github.com/vxunderground/MalwareSourceCode/tree/main/Win32/Stealers
Special thanks to BasssterLord/NationalHazardAgency for getting the source code for us.
Check it out here: https://github.com/vxunderground/MalwareSourceCode/tree/main/Win32/Stealers
âĪâðĨ10âĪ4ð1ðĨ1ð1
We've updated the vx-underground malware collection.
- InTheWild.0067
We have added new samples for the following families:
- BlackCatRansomware
- FormBook
- AsyncRAT
- Amadey
- Danabot
- Emotet
- WhisperGate
- LokiBot
- Remcos
Check it out here: https://vx-underground.org/malware.html
- InTheWild.0067
We have added new samples for the following families:
- BlackCatRansomware
- FormBook
- AsyncRAT
- Amadey
- Danabot
- Emotet
- WhisperGate
- LokiBot
- Remcos
Check it out here: https://vx-underground.org/malware.html
ð14âĪâðĨ3
Today VirusTotal announced that each sample uploaded will be accompanied by "Code Insight". Code Insight uses Sec-PaLM, one of the generative AI models by Google, to explain what the malicious binary is doing.
Code Insight is available to all users.
tl;dr "they took my job"
Code Insight is available to all users.
tl;dr "they took my job"
ðĪĢ82ðĨ13âĪ8ð4ðĒ2âĪâðĨ1