vx-underground
47.5K subscribers
4.09K photos
437 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
This will be framed and put somewhere at vx-underground HQ.
πŸ‘49🀣18❀10πŸ‘10πŸ”₯7❀‍πŸ”₯3😁2
Bill Gates' arch-nemesis, Bill Fences. Bill Fences invented Linux.
🀣56😁5πŸ€”5πŸ’―4❀3🫑3
Remember when Anonymous was cool and trolled Oprah Winfrey into saying "9000 penises" on national television?

vx-underground remembers.

https://www.youtube.com/watch?v=7liYfhRgXGk
🀣51❀5🫑5πŸ€ͺ4❀‍πŸ”₯1
"We do not forgive, we do not forget, we have over 9000 penises" - Anonymous
😁40🀣21πŸ€ͺ8🫑3❀‍πŸ”₯2😒2
We see a new ransomware blog pop-up online every couple of weeks.

Apparently everyone and their grandma is in a ransomware group now.

Ransomwatch has a fairly comprehensive list: https://ransomwatch.telemetry.ltd/#/INDEX
πŸ‘22🫑9πŸ€”2❀1😱1
vx-underground is 4 years old.

Thank you for another exciting year.

Thank you everyone for the love and support. We are continuing our work and will continue to expand our library of malware source, samples, and papers.
❀110πŸŽ‰49🫑16❀‍πŸ”₯5😁3πŸ‘1
We've updated the vx-underground malware family collection.

- HermeticWiper
- Turla
- ElectronBot
- AvosLockerRansomware
- XLoader
- Formbook
- Valyria
- BlackCatRansomware
- Remcos
- DanaBot
- RedLine
- PhobosRansomware
- SharkBot

Check it out here: https://samples.vx-underground.org/samples/Families/
❀24❀‍πŸ”₯5πŸ‘2
For our Russian speaking friends:

ΠœΡ‹ собрали всС Π½ΠΎΠΌΠ΅Ρ€Π° ΠΆΡƒΡ€Π½Π°Π»Π° Β«Π₯Π°ΠΊΠ΅Ρ€Β» с 1999 ΠΏΠΎ 2022 Π³ΠΎΠ΄. Π•Π³ΠΎ Ρ€Π°Π·ΠΌΠ΅Ρ€ составляСт 14 Π“Π‘. Π‘ΠΊΠΎΡ€ΠΎ ΠΌΡ‹ Π½Π°Ρ‡Π½Π΅ΠΌ Π·Π°Π³Ρ€ΡƒΠΆΠ°Ρ‚ΡŒ ΡΡ‚Π°Ρ‚ΡŒΠΈ.
❀177πŸ‘16πŸ”₯15🀣15❀‍πŸ”₯6πŸ€”5πŸ‘3πŸ₯°2😁2🀯2😱1
We've updated the vx-underground malware family collection.

- AvosLocker
- AgentTesla
- Emotet
- RaccoonStealer
- Coroxy
- LazyScripter
- SmokeLoader
- Escobar
- Valyria
- RedLine
- CobaltStrike
- PandoraRansomware
- WhisperGate

Check it out here: https://samples.vx-underground.org/samples/Families/
πŸ‘8😍2❀1πŸŽ‰1
Change your Steam ID to include the word "antidisestablishmentarianism".

Steam server provider Akamai bans the word. However, Steam does not. The word will (almost) destroy your Steam profile.

More information: https://www.youtube.com/watch?v=l8mvWiNs30M
😱21😁14πŸ₯°3πŸ‘2❀1❀‍πŸ”₯1πŸ”₯1πŸŽ‰1πŸ€ͺ1
The new Microsoft Windows 'Dev Drive' feature will be a game changer. Expect to see a monumental increase in malware in development environments.
🫑40😁14πŸ”₯10πŸ‘6πŸ€”5πŸŽ‰3❀2
We've updated the vx-underground malware family collection.

- WhiteBlack
- Danabot
- EnemyBot
- Gh0stCringe
- LokiLocker
- ArkeiStealer
- Qakbot
- RookRansomware
- IcedId
- CaddyWiper
- HydraBankBot
- BlackMatter

Check it out here: https://samples.vx-underground.org/samples/Families/
πŸ‘10❀‍πŸ”₯5πŸŽ‰2❀1
This media is not supported in your browser
VIEW IN TELEGRAM
A summary of malware trends and discussions we have witnessed in the past few weeks and the response from Twitter nerds
🀣71❀‍πŸ”₯3❀1πŸŽ‰1πŸ’―1
TrendMicro's paper on Earth Longzhi (a subgroup of Chinese-based APT41) Stack Rumbling is interesting. APT41 introduces a potentially new way to disrupt and/or disable security products.

We've highlighted a section from their article about the technique. Simple, yet effective.
❀28πŸ”₯5😘2πŸŽ‰1
TrendMicro's paper on Earth Longzhi (a subgroup of Chinese-based APT41) also illustrates creating a service with RPCs rather than using WINAPI.

It is another clever trick demonstrated by APT41.

It's the little things β™₯️
❀33πŸ‘5πŸ”₯4πŸ‘2πŸŽ‰1🫑1πŸ€ͺ1
A qTox 1.17.6 (current version) RCE 0day is for sale.

It would give nerds the ability to pwn literally every ransomware group, and major Threat Actor, on the planet. All it requires is sending a friend request, and the other person accepting it.

It is being sold for $500,000
🀯101🫑18πŸ”₯11πŸ’―5🀣4πŸ‘3❀‍πŸ”₯1πŸŽ‰1
This media is not supported in your browser
VIEW IN TELEGRAM
🀣62😁4πŸ’―4πŸ”₯2🀯1πŸŽ‰1
The exploit has been sold. The buyer has not been publicly identified.

"Now how am I going to make new friends? Don't message me on qTox, I only have old friends )))" - Lockbit ransomware group administrative staff
🀯38😁18πŸ€”2❀1πŸ‘1πŸŽ‰1🫑1
We've updated our Windows malware paper collection.

- 2012-11-01 - SizeOfStackReserve As Anti-Attaching Trick
- 2021-01-20 - Process on a diet anti-debug using job objects
- 2023-05-02 - Preventing application creation by IFEO keys

Check it out here: https://www.vx-underground.org/windows.html
πŸ‘12❀3🀯1πŸŽ‰1🀣1
A Threat Actor leaked the private GitHub repos from Panopta, a company recently acquired by Fortinet.

The breached appears to take place before or on December 22nd, 2022.
πŸ‘29🫑4πŸŽ‰1