vx-underground
47.4K subscribers
4.09K photos
436 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Google has sold Google Domains to SquareSpace for $180,000,000.

Reminder that any product Google produces, they will kill off and send to the infamous Google graveyard.
πŸ€”58😁14🫑14πŸ‘7❀2πŸ₯°2πŸŽ‰1
The United States government has put a $10,000,000 bounty on any individual associated with cl0p ransomware group.
🀣89😁19🫑16πŸ₯°7πŸ‘6😱4πŸ€ͺ4❀‍πŸ”₯3πŸ”₯2πŸ‘1πŸ€”1
ALPHV ransomware group claims to have stolen data from Reddit.

Intel via AlvieriD
πŸ‘73🀣45🫑12πŸ‘4πŸ”₯3❀2😁1πŸ€”1
vx-underground staff are at max capacity. Every staff member is currently busy.

We have several large projects still in the works. Thank you to everyone who supports us with merchandise purchases or monthly donations.

P.S. We fixed the Discord bot. Thank you for notifying us.
❀77🫑21πŸ‘12🀣5πŸŽ‰4
We managed to get our hands on two TriangleDB (Operation Triangulation) samples.

This is iOS spyware allegedly developed by the United States government.

We will share them shortly.
πŸ”₯103πŸ‘38🀯27🫑12❀‍πŸ”₯8❀6πŸ₯°4πŸ€”4🀩3πŸ‘2😱2
cl0p ransomware group has historically been quiet. They rarely addressed journalists or spoke with researchers. It's nice seeing them comment on the BBC article about them (albeit on their blog).

cl0p, if you're reading this message: your name makes us think of little horsies πŸ₯°πŸ₯°
❀‍πŸ”₯73🀣42πŸ₯°9πŸ‘4😁4🫑4πŸ’―2😘2❀1
😁127🀣63πŸ‘26❀‍πŸ”₯19🫑7❀5
cl0p ransomware group claims to have ransomed Sony and PWC.

cl0p claims to have exfiltrated 120GB of data and archives from PWC.

cl0p has not stated how much data (if any) was exfiltrated from Sony.
πŸ”₯44πŸ‘7🫑6πŸŽ‰5πŸ€”2❀1
Mark Zuckerberg has agreed to fight Elon Musk in a cage fight (?). This is not satire.

Elon Musk agreed to fight Mark Zuckerberg. Mark Zuckerberg replied on Instagram "Send me location", a reference to Russian MMA fighter Khabib Nurmagomedov challenging Conor McGregor at UFC 229.
🀣113πŸ€ͺ21πŸ‘6🀯4🫑4❀1
We've updated the vx-underground malware sample collection.

- TriangleDB
- CaddyWiper
- DoubleZeroWiper
- BlisterLoader
- HeaderTip
- Denoia
- Remcos
- WizardUpdate
- Blackcat
- Sharkbot
- AvosLocker
- NetSupportRAT
- Mirai
- IcedId

Check it out here: https://samples.vx-underground.org/samples/Families/
πŸ‘34πŸ”₯13❀7🫑4
TriangleDB is (or was) allegedly developed by the United States government. This iOS spyware was delivered via an iOS 0day exploit chain.

Apple has now patched the exploits.
πŸ”₯63πŸ‘6🫑2😁1
DeepInstinct released a paper on a new malware family titled "PindOS". PindOS is named as such because the user-agent in the malware is "PindOS".

Interesting that this malware family user-agent is "PindOS" because "пиндос", pronounced "pindos", is a derogatory term in post-soviet countries used to describe people from the United States of America. Pindos is a derivative of "Pindostan", "Pindosia", or "United States of Pindostan".

More information:
https://www.deepinstinct.com/blog/pindos-new-javascript-dropper-delivering-bumblebee-and-icedid
😁61πŸ‘11πŸ€”7🀣6❀5🫑5πŸ™1
June 15th the United States military released a report regarding unknown, and unsolicited, smartwatches being sent to United States service members.

These devices are attempting to collect user data on military officials.

More information:

https://www.cid.army.mil/Media/Press-Center/Article-Display/Article/3429159/cid-lookout-unsolicited-smartwatches-received-by-mail/
😁28😱6πŸ‘4🫑2❀1
PMC Wagner group has declared war on the Russian Ministry of Defense - Evgeny Prigozhin claims they attacked his group at night.

The Russian Ministry of Defense denies these allegations.

It's a coup d'etat.

Russian Telegram channels are pure pandemonium.
🀯63🫑23❀17😁12🀣12πŸ‘9😱5😒5πŸŽ‰5πŸ₯°4πŸ€”2
Yes, we are aware this is unrelated to malware, but this will dramatically impact APT cyber operations from the CIS regions because their may be a civil war soon.
🫑71🀣25❀12😁7
There is a tsunami of disinformation, misinformation, and debate over the current situation in Russia - people question the validity and seriousness of the matter.

We certainly do not know, but we remain vigilant on the impact (if any...) this will make on CIS-based cyber crime.

At the start of the Ukrainian war we witnessed a decrease in ransomware operations. ALPHV & Lockbit staff noted affiliates had disappeared. We also witnessed high volumes of APT activity targeted at Ukraine

We question how (if at all) this may impact the current threat landscape

vx-underground is not a political feed. We are far from political experts, but we understand politics and real-world events do shape malware and cyber-activity (state-sponsored or financially motivated).

Let's see what happens... on the internet =D
πŸ”₯82πŸ€”21πŸ‘12🫑10❀7🀣5😁4πŸ‘2
This media is not supported in your browser
VIEW IN TELEGRAM
vx-underground has received exclusive footage of PMC Wagner traveling to Moscow
🀣126😁19🫑12πŸ”₯6😒2πŸ‘1πŸ‘1
You can now return to your regularly scheduled programming
πŸŽ‰86😁27πŸ€ͺ14🀣13πŸ€”9🀯5😒4🫑4πŸ‘3❀2
We've updated the vx-underground malware sample collection.

- NokoyaRansomware
- QakBot
- Karma
- Conti
- Pysa
- LokiBot
- Industroyer
- PryntStealer
- BlackGuard
- Redline
- Certishell
- Emotet

Check it out here: https://samples.vx-underground.org/samples/Families/
πŸ”₯20❀7πŸ‘5🫑4πŸŽ‰1