vx-underground
47.5K subscribers
4.09K photos
437 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
We've updated the vx-underground malware sample collection. We have added new samples for the following families:

- Nanocore
- AsyncRAT
- NetwireRAT
- AgentTesla
- LokiBot
- Formbook
- CobaltStrike
- NjRat
- Chaos Ransomware

Check it out here: https://samples.vx-underground.org/samples/Families/
âĪ14ðŸ”Ĩ7👍2
You can subscribe to vx-underground Blueâ„Ē for only $5.99/month.

Nothing is different, but you get a wear a dunce hat
ðŸ’Ŋ41ðŸĪĢ29ðŸ”Ĩ4ðŸĪĐ4👍1🎉1
Today someone stole 3,600lbs (1632kg) of Gold from the Toronto Pearson Airport. It is valued at roughly $100,000,000.

The police currently have no suspects. Unrelated to malware of course, but such a ballsy heist is impressive.

More information:
https://www.cbc.ca/news/canada/toronto/gold-heist-pearson-airport-toronto-1.6817345
ðŸŦĄ43ðŸĨ°18âĪ5👏4👍2😁1ðŸĪĐ1😘1
An unknown Threat Actor has compromised the European Union's web domain and is using it to distribute Fortnite V-Bucks scams...

They've also compromised 15 other high-profile websites. See full list in attached image below.

Information via g0njxa and Gi7w0rm
ðŸĪĢ66👍3âĪ2👏2
Use Twitter image description feature as a C2.

See example in attached link: https://twitter.com/vxunderground/status/1649251062820249600
ðŸĨ°13ðŸ’Ŋ2ðŸŦĄ2âĪ1
The European Union likes distributing malware

Information via bigfack
ðŸĪĢ79👏5âĪ4
ALPHV ransomware group modus operandi has changed. The recent victim postings tone has changed significantly. They do not come across as calm and professional as ALPHV traditionally has.

Someone is new to their group and much more vocal.

Image 1. New ALPHV
Image 2. Old ALPHV
ðŸĪĢ27âĪ5ðŸ”Ĩ4😁3ðŸ˜ą2
Symantec Threat Hunter Team discovered the X-Trader supply chain attack, which resulted in the 3CX supply chain attack, hit critical infrastructure - European and American electrical grid suppliers

More information: https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/xtrader-3cx-supply-chain
ðŸ˜ą14👏2ðŸŦĄ2âĪ1👍1
There is a direct correlation between hours of anime watched and reverse engineering skills.

The longer someone watches anime, the better they are at reverse engineering.

Scientists do not know why.
👍57ðŸĪĢ32ðŸ˜ą17ðŸŦĄ11ðŸĪŊ7âĪ5ðŸ”Ĩ3😁3ðŸ’Ŋ3ðŸ˜Ē2ðŸĪĐ2
Andy Greenberg's book "Tracers in the Dark: The Global Hunt for the Crime Lords of Cryptocurrency" is an incredible book. It reads well. It allows a reader to understand the flaws in cryptocurrency and truly emphasizes the incredible research by people like Sarah Meiklejohn.

This isn't an advertisement for him - this book is genuinely an amazing read. Shoutout to Andy.
ðŸ’Ŋ56âĪ14👍9ðŸ”Ĩ7🎉3
We've updated the vx-underground malware sample collection. We have added new samples for the following families:

- AgentTesla
- AsyncRAT
- WhisperGate
- RagnarLocker
- YoungLotus
- Blackmoon
- Emotet
- Remcos
- Trickbot

Check it out here: https://samples.vx-underground.org/samples/Families/
ðŸ”Ĩ16👍5
Suicide is not the answer. Seeking help is a sign of strength.
âĪ123👍12ðŸĪĢ12ðŸŦĄ9âĪ‍ðŸ”Ĩ6ðŸĪ”3ðŸĪŠ3👏1
We've updated the vx-underground malware source code collection. We've added Win32.SimpleWalletClipper.Xss.

Special thanks to BasssterLord/NationalHazardAgency for getting the source code for us.

Check it out here: https://github.com/vxunderground/MalwareSourceCode/tree/main/Win32/Stealers
âĪ‍ðŸ”Ĩ10âĪ4👍1ðŸ”Ĩ1😁1
We've updated the vx-underground malware collection.

- InTheWild.0067

We have added new samples for the following families:

- BlackCatRansomware
- FormBook
- AsyncRAT
- Amadey
- Danabot
- Emotet
- WhisperGate
- LokiBot
- Remcos

Check it out here: https://vx-underground.org/malware.html
👍14âĪ‍ðŸ”Ĩ3
The password to all of our archives is 'infected'

The compressed files we create, which is created from Linux or Windows OS's, are not natively compatible with MacOS

MacOS uses a different methodology to compress files and directories. The 'unzip' utility will not work, sorry.
😁47ðŸ˜Ē5🙏3😘2
Hey Blue Team nerds in the Northern parts of the United States and Canada - does your contingency plan cover G4 Geomagnetic Storms?
âĪ‍ðŸ”Ĩ30ðŸĪ”10ðŸ˜ą9😁5👍1
Lockbit ransomware group put out an advertisement today. They are hiring an entry-level QA tester.

Primary requirements include:
- No social life
- Be greedy

Intel via crocodylii
ðŸĪĢ67😁12ðŸĪ”3âĪ2👏2👍1
You may not like it but this is what a true 1337 hacker looks like
ðŸĪĢ82ðŸŦĄ26ðŸĪŊ11👏3😁3👍2ðŸ’Ŋ1
Today VirusTotal announced that each sample uploaded will be accompanied by "Code Insight". Code Insight uses Sec-PaLM, one of the generative AI models by Google, to explain what the malicious binary is doing.

Code Insight is available to all users.

tl;dr "they took my job"
ðŸĪĢ82ðŸ”Ĩ13âĪ8🎉4ðŸ˜Ē2âĪ‍ðŸ”Ĩ1