vx-underground
47.4K subscribers
4.08K photos
436 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Reddit nerds and moderators are protesting the API price increase. Thousands of subreddits have been switched to private from subreddit moderators.

Reddit executives seemed to have forgotten their revenue stream is from users. If they have no users, they have no income.
🀣54πŸ‘45🫑19πŸ€”4❀‍πŸ”₯3🀯3😒2πŸ‘1πŸŽ‰1πŸ€ͺ1
Media is too big
VIEW IN TELEGRAM
Monoxide x64 wiper virus footage.

Footage recorded on a VM via LaurieWired

Sha256 hash: ae9405b9556c24389ee359993f45926a895481c8d60d98b91a3065f5c026cffe
🀣58🀯28πŸ‘9πŸ”₯7😍7❀‍πŸ”₯5πŸ₯°4πŸ€”3πŸŽ‰2😘2
Exposed, the forum designed to be the replacement to Breached, is for sale.

Meanwhile, Breached forum has returned. The previous owner who worked in conjunction with Pompompurin, Baphomet, is now working alongside the infamous ShinyHunters group.

Intel via Andrea Draghetti
🀣66πŸŽ‰12πŸ‘5🫑3😱2❀1
Today the United States Senate Committee of the Judiciary are speaking with Directors from the NSA, CIA, and FBI regarding warrantless searches and unauthorized access of resources of United States civilians including phone calls, text messages, and more.

https://www.judiciary.senate.gov/oversight-of-section-702-of-the-foreign-intelligence-surveillance-act-and-related-surveillance-authorities
😱32😁6πŸŽ‰5❀1πŸ’―1
vx-underground
Today the United States Senate Committee of the Judiciary are speaking with Directors from the NSA, CIA, and FBI regarding warrantless searches and unauthorized access of resources of United States civilians including phone calls, text messages, and more.…
Right off the bat the NSA Deputy Director George Barnes mentions the Colonial pipeline and ALPHV ransomware group.
🀯19πŸ€ͺ11😁4πŸ‘2🫑2πŸŽ‰1πŸ’―1
Today the US Senate Committee of the Judiciary sat down with Directors from the NSA, CIA, FBI, and DoJ.

The committee unveiled last month, May 2023, the FBI conducted over 278,000 warrantless searches on United States citizens - accessing phone calls, text messages, and e-mails.

Only 19,000 were valid. The Senate Committee believes the remaining 259,000 were violations of the 4th amendment.

The FBI allegedly monitored individuals tied to Russia, ISIS, ransomware groups, China, and Black Lives Matter.
😱51πŸ‘9πŸ”₯9🀣6πŸ€”5🫑4πŸŽ‰1
We've updated the vx-underground Windows malware paper collection

- 2023-06-05 - Demonstrating how to kill EDR processes using a driver
- 2019-08-12 - Windows Process Injection via KnownDlls Cache Poisoning

Check it out here: https://www.vx-underground.org/windows.html
❀19πŸ‘3🀩2πŸŽ‰1
Sometime in 2019 Lockbit ransomware group began referring to themselves as "post-paid-pentesters". They claimed they are beneficial to companies because they illustrate flaws in their security posture.

The new rapidly evolving 8Base ransomware group makes this same argument.
🀣67πŸ‘6πŸ€”4🫑4πŸ‘1😒1πŸŽ‰1πŸ’―1
Thank you, random woman on the internet, for the Hello Kitty / large collection of girly weaponry, vx-underground fan sign.
πŸ”₯105🀣35❀‍πŸ”₯15❀10🫑6😍4πŸŽ‰2πŸ‘1😱1
Topor Live, a large Telegram-based news outlet based out of Russia, with over 3.9M followers, reported that REvil, Anonymous Sudan, and Killnet are going to take down the European banking system in 48 hours.

Following this attack, Linus Torvalds will switch to Windows.
🀣184😁14πŸ€ͺ11πŸŽ‰8πŸ”₯4❀‍πŸ”₯3πŸ‘1πŸ€”1
Pizza Hut's website in 1994.

Image via catalinmpit
❀‍πŸ”₯76🀩19❀11🀯7🫑5πŸ”₯4😁4πŸ‘2πŸŽ‰1
This media is not supported in your browser
VIEW IN TELEGRAM
Here is footage released by "REvil" and Killnet about taking down the European banking system.

Since when did REvil ransomware group go on camera and publicly disclose their plans prior to attack? And why is "REvil" wearing a Slipknot mask?
🀣193πŸ‘12🀯12🫑11πŸ€ͺ7❀5πŸŽ‰4πŸ€”2
Omnipotent, the previous administrator of the infamous RaidForums, delivered a message today. It was PGP signed thus confirming it is actually him.

It is an interesting message. We recommend everyone read it. It is attached below.
πŸ‘56🫑43❀11πŸ‘1😁1πŸŽ‰1
Unrelated to malware, several individuals have been charged with trafficking stolen human body parts from Harvard Medical University.

The schools morgue manager received paypal memos with titles such as "head number 7" and "braiiiins".
πŸ€ͺ68🀣31🀯16πŸ‘8😱7❀3πŸŽ‰2🫑2
tl;dr if you're going to commit serious crimes, such as trafficking human organs, practice better opsec and do not blatantly admit your crimes on PayPal.

You can read the full indictment here: https://whdh.com/wp-content/uploads/sites/3/2023/06/CR.-NO.-4.23-CR-159-US-V.-CEDRIC-LODGE-KATRINA-MACLEAN-JOSHUA-TAYLOR-AND-DENISE-LODGE.pdf
πŸŽ‰39🫑13🀣9πŸ‘4πŸ‘1😁1🀩1πŸ’―1
Today the United States Federal Bureau of Investigation announced the arrest of Ruslan Magomedovich Astamirov.

Astamirov is allegedly a long time member of Lockbit ransomware group with his attacks taking place between August, 2020 and March, 2023.

He is 20 years old.
πŸ”₯43😒27🫑16πŸ€”8🀣6πŸ‘3πŸ‘2😱2❀1🀯1
vx-underground
Unrelated to malware, several individuals have been charged with trafficking stolen human body parts from Harvard Medical University. The schools morgue manager received paypal memos with titles such as "head number 7" and "braiiiins".
Jeremy Pauley, 41, purchased human organs, bones, and he purchased two stillborn babies for ... collection?

The attached photo is of him. via WGAL8 TV
🀯62🀣18😱10πŸ€ͺ4❀3πŸ‘2🫑2πŸ”₯1πŸ‘1😒1
This media is not supported in your browser
VIEW IN TELEGRAM
Killnet, the ghost of REvil past, and Anonymous Sudan announced in the 48 hours they would go 110% Mr. Robot and take down the European banking system, or something

24 hours are remaining. We're half way there.
🀣203❀12😁9πŸŽ‰9🫑8πŸ‘5πŸ€”4πŸ™4😱1πŸ’―1
Ernst & Young, a member of the CISA assembled RTF (Ransomware Task Force) has been a victim of cl0p ransomware group from the MoveIT 0day exploit.

Information via Brett Callow
🀣113😁9🀯8🫑6πŸ‘5πŸ‘4❀2πŸŽ‰2🀩2πŸ’―1
Today Polish authorities announced they made several arrests. The arrested people are allegedly connected to DdoS attack providers.

They released footage of the arrests. These are two images from the video.

The "Do not disturb" is the cherry on top.
🀣113🫑13🀯7❀4πŸ€”4πŸ₯°1😒1πŸŽ‰1