vx-underground
47.5K subscribers
4.09K photos
437 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
The new Microsoft Windows 'Dev Drive' feature will be a game changer. Expect to see a monumental increase in malware in development environments.
🫑40😁14πŸ”₯10πŸ‘6πŸ€”5πŸŽ‰3❀2
We've updated the vx-underground malware family collection.

- WhiteBlack
- Danabot
- EnemyBot
- Gh0stCringe
- LokiLocker
- ArkeiStealer
- Qakbot
- RookRansomware
- IcedId
- CaddyWiper
- HydraBankBot
- BlackMatter

Check it out here: https://samples.vx-underground.org/samples/Families/
πŸ‘10❀‍πŸ”₯5πŸŽ‰2❀1
This media is not supported in your browser
VIEW IN TELEGRAM
A summary of malware trends and discussions we have witnessed in the past few weeks and the response from Twitter nerds
🀣71❀‍πŸ”₯3❀1πŸŽ‰1πŸ’―1
TrendMicro's paper on Earth Longzhi (a subgroup of Chinese-based APT41) Stack Rumbling is interesting. APT41 introduces a potentially new way to disrupt and/or disable security products.

We've highlighted a section from their article about the technique. Simple, yet effective.
❀28πŸ”₯5😘2πŸŽ‰1
TrendMicro's paper on Earth Longzhi (a subgroup of Chinese-based APT41) also illustrates creating a service with RPCs rather than using WINAPI.

It is another clever trick demonstrated by APT41.

It's the little things β™₯️
❀33πŸ‘5πŸ”₯4πŸ‘2πŸŽ‰1🫑1πŸ€ͺ1
A qTox 1.17.6 (current version) RCE 0day is for sale.

It would give nerds the ability to pwn literally every ransomware group, and major Threat Actor, on the planet. All it requires is sending a friend request, and the other person accepting it.

It is being sold for $500,000
🀯101🫑18πŸ”₯11πŸ’―5🀣4πŸ‘3❀‍πŸ”₯1πŸŽ‰1
This media is not supported in your browser
VIEW IN TELEGRAM
🀣62😁4πŸ’―4πŸ”₯2🀯1πŸŽ‰1
The exploit has been sold. The buyer has not been publicly identified.

"Now how am I going to make new friends? Don't message me on qTox, I only have old friends )))" - Lockbit ransomware group administrative staff
🀯38😁18πŸ€”2❀1πŸ‘1πŸŽ‰1🫑1
We've updated our Windows malware paper collection.

- 2012-11-01 - SizeOfStackReserve As Anti-Attaching Trick
- 2021-01-20 - Process on a diet anti-debug using job objects
- 2023-05-02 - Preventing application creation by IFEO keys

Check it out here: https://www.vx-underground.org/windows.html
πŸ‘12❀3🀯1πŸŽ‰1🀣1
A Threat Actor leaked the private GitHub repos from Panopta, a company recently acquired by Fortinet.

The breached appears to take place before or on December 22nd, 2022.
πŸ‘29🫑4πŸŽ‰1
The mayor of Augusta, Georgia, told local media outlet WRDW_WAGT they were not a victim of BlackByte ransomware group

This is an incredibly bold move - denying being a victim, while data is actively being leaked and distributed, is a galaxy brain moment

https://www.wrdw.com/2023/05/25/mayor-denies-getting-ransom-demand-fix-computer-outage/
🀣23πŸ€ͺ6πŸ‘3πŸŽ‰1🫑1
"We didn't get ransomed, everything is fine".

Meanwhile, documents circulating online show the local government actively monitors and tracks the homeless population (including family members).

They spelled 'Nationality' wrong.
πŸ€ͺ53🀣17🫑10🀯4🀩4πŸ‘1πŸ‘1πŸŽ‰1
We've updated our Russian malware paper collection

- 2022-06-13 - Π’Π½ΡƒΡ‚Ρ€Π΅Π½Π½ΠΈΠ΅ ΠΊΠΎΠΌΠΏΠΎΠ½Π΅Π½Ρ‚Ρ‹ Windows IPC RPC 2
- 2022-11-03 - Π‘Π΅Ρ€Π΅Π΄ΠΈΠ½Π½Ρ‹ΠΉ Π²Ρ‹Π·ΠΎΠ² API Ρ„ΡƒΠ½ΠΊΡ†ΠΈΠΉ
- 2023-05-22 - ДотнСтовская кулинария Ρ‡Π°ΡΡ‚ΡŒ 1

Check it out here: https://www.vx-underground.org/russian.html
πŸ”₯21πŸ‘7❀‍πŸ”₯3πŸŽ‰1πŸ€ͺ1😘1
Hello.

This is a message to the many up and coming ransomware groups we see.

STOP. USING. BABUK.

It is buggy. It fails decrypting large files and other edge cases. If you're going to be a criminal group, do it correctly. Your victims won't be able to recover files, dumbie.
😁90πŸ‘11❀6🫑5😱4πŸ€ͺ4❀‍πŸ”₯1πŸ”₯1πŸŽ‰1
We've updated our Windows malware paper collection

- 2019-04-07 - Loading and calling VB from C++
- 2019-07-21 - In-memory execution of VBScript, JavaScript or JScript

Check it out here: https://www.vx-underground.org/windows.html
πŸ‘19❀2❀‍πŸ”₯2πŸŽ‰1
This media is not supported in your browser
VIEW IN TELEGRAM
*Hacker voice*: "I'm in".
πŸ”₯73🀣48❀2❀‍πŸ”₯2😁2πŸ‘1🀯1πŸŽ‰1
It's that time of the year again when state-sponsored Threat Actors are assigned the task of targeting Twitter nerds.

GermΓ‘n FernΓ‘ndez unveiled a campaign where Threat Actors are targeting researchers on Twitter.

Thread: https://twitter.com/1ZRR4H/status/1661793801730490374
πŸ‘20😁5πŸ€ͺ4🫑3πŸ”₯1πŸŽ‰1
We've updated the vx-underground bulk malware download collection.

- Virusshare.00470
- Virusshare.00471
- 60,000+ unique malware samples
- Named using Kaspersky naming convention

Check it out here: https://samples.vx-underground.org/samples/Blocks/
πŸ‘12❀4❀‍πŸ”₯1πŸŽ‰1
Our new artwork is generated by AI using malware hashes.

Win32.AgentTesla.14a388b154b55a25c66b1bfef9499b64
πŸ”₯83❀10πŸ‘7🀣7❀‍πŸ”₯2😁2πŸŽ‰1🫑1