vx-underground
47.4K subscribers
4.08K photos
436 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
PMC Wagner group has declared war on the Russian Ministry of Defense - Evgeny Prigozhin claims they attacked his group at night.

The Russian Ministry of Defense denies these allegations.

It's a coup d'etat.

Russian Telegram channels are pure pandemonium.
ðŸĪŊ63ðŸŦĄ23âĪ17😁12ðŸĪĢ12👍9ðŸ˜ą5ðŸ˜Ē5🎉5ðŸĨ°4ðŸĪ”2
Yes, we are aware this is unrelated to malware, but this will dramatically impact APT cyber operations from the CIS regions because their may be a civil war soon.
ðŸŦĄ71ðŸĪĢ25âĪ12😁7
There is a tsunami of disinformation, misinformation, and debate over the current situation in Russia - people question the validity and seriousness of the matter.

We certainly do not know, but we remain vigilant on the impact (if any...) this will make on CIS-based cyber crime.

At the start of the Ukrainian war we witnessed a decrease in ransomware operations. ALPHV & Lockbit staff noted affiliates had disappeared. We also witnessed high volumes of APT activity targeted at Ukraine

We question how (if at all) this may impact the current threat landscape

vx-underground is not a political feed. We are far from political experts, but we understand politics and real-world events do shape malware and cyber-activity (state-sponsored or financially motivated).

Let's see what happens... on the internet =D
ðŸ”Ĩ82ðŸĪ”21👍12ðŸŦĄ10âĪ7ðŸĪĢ5😁4👏2
This media is not supported in your browser
VIEW IN TELEGRAM
vx-underground has received exclusive footage of PMC Wagner traveling to Moscow
ðŸĪĢ126😁19ðŸŦĄ12ðŸ”Ĩ6ðŸ˜Ē2👍1👏1
You can now return to your regularly scheduled programming
🎉86😁27ðŸĪŠ14ðŸĪĢ13ðŸĪ”9ðŸĪŊ5ðŸ˜Ē4ðŸŦĄ4👍3âĪ2
We've updated the vx-underground malware sample collection.

- NokoyaRansomware
- QakBot
- Karma
- Conti
- Pysa
- LokiBot
- Industroyer
- PryntStealer
- BlackGuard
- Redline
- Certishell
- Emotet

Check it out here: https://samples.vx-underground.org/samples/Families/
ðŸ”Ĩ20âĪ7👍5ðŸŦĄ4🎉1
Doxbin administration have sold the infamous website. It is now under new leadership.
ðŸŦĄ74👍17ðŸĪĢ17ðŸ˜Ē8âĪ6ðŸĪ”5🙏2🎉1
cl0p ransomware group's MoveIT 0day exploit has proven to be unfathomably effective.

The sheer volume of high-profile targets they've listed on their leak site over the past couple of weeks is appalling.
âĪ51ðŸŦĄ9ðŸĪ”6ðŸ”Ĩ1😁1ðŸ˜ą1🎉1ðŸĪĐ1
yifever produced something very special.

They created 'SleeperAgent', a backdoor in a language model that allows the user to execute behavior based on secret phrases. It demonstrates the possibility to creating malicious language models.

More information: https://twitter.com/yifever/status/1673122951628193792
👏29ðŸ”Ĩ15👍3âĪ2🎉1
This media is not supported in your browser
VIEW IN TELEGRAM
POV: You log into Twitter and see someone shared some malcode proof-of-concept and you read the comment section and retweets

tl;dr be nice, nerds

*Warning: excessive language
ðŸĪĢ75âĪ7👏3😁3👍2ðŸ”Ĩ1🎉1ðŸ’Ŋ1
We are experimenting with a new site template.

vx-underground has over 19,000 papers and we need to find a way to improve searchability and visibility.
👍78âĪ31👏14ðŸĪĢ9ðŸ”Ĩ8âĪ‍ðŸ”Ĩ4ðŸ˜Ē3😁2🎉1ðŸŦĄ1
Experimental vx-underground site.

- Incomplete
- Not mobile friendly (we don't care)
- Currently only displaying papers, this is a test run
- ???

Thoughts?

https://www.vx-underground.org/exp.html
👍92âĪ27ðŸĪ”9ðŸĪĢ8âĪ‍ðŸ”Ĩ4ðŸ”Ĩ4ðŸĪŠ4👏3🎉2ðŸĨ°1😁1
Google has successfully performed a "mega whoopsie". Adalytics research firm unveiled Google has been violating their own advertisement standards for several years.

Large advertisers, such as UM Worldwide, are asking for refunds.

Non-paywall link here: https://archive.is/thXPF
ðŸĪĢ50ðŸŦĄ4ðŸĪŊ3ðŸ˜ą2👏1😁1🎉1
Media is too big
VIEW IN TELEGRAM
Our friend Laughing_Mantis has created a song titled "PegaSUS". The techtronica track was created using disassembly & bytecode from the infamous Pegasus spyware.

File entropy was used to make the synth sounds.
âĪ‍ðŸ”Ĩ47ðŸ”Ĩ16ðŸĪŊ9ðŸĪĢ7ðŸŦĄ4âĪ3👍2ðŸ˜Ē2🎉1
The new vx-underground will go live in the next following days.

- Enhanced item listing
- Improve legibility
- Global search functionality
- Dark theme
- Partially mobile friendly

Following this our additions will spike... dramatically...

Smell ya later, nerds.
👍50ðŸŦĄ27âĪ‍ðŸ”Ĩ14âĪ3🎉3ðŸĪĢ1
vx-underground will be under heavy construction the next couple of days. Site stability will be impacted. The site may go offline on occasion.

In an ideal world the new site will go live Monday, July 3rd.

This isn't an ideal world.
👍47âĪ8ðŸ˜Ē7ðŸ’Ŋ6ðŸŦĄ5😁3ðŸĨ°1
8base ransomware group has exploded in victim postings. Their output rivals the big 3.

Prediction: in the coming months they will become a big player in the ransomware scene.
ðŸ˜ą28ðŸŦĄ10ðŸ”Ĩ6🎉3ðŸĪĢ1
Note: "Big 3" we define as the Conti crime family, Lockbit ransomware group, and ALPHV ransomware group.

We define these as the largest, and most prolific, ransomware groups (currently).

We define Conti as a crime family because they're composed of "teams" under multiple brands
👍32ðŸĪĢ8ðŸ’Ŋ5ðŸ˜ą4🎉1
Our website improvement is going well. We are in the process of migrating data. It will take sometime.

Data is not accessible yet. However, you can now see the new and improved vx-underground.

https://www.vx-underground.org/root.html#E:/root
âĪ31ðŸ”Ĩ7👏5ðŸŦĄ3👍2🎉1ðŸ’Ŋ1
Dana White, President of the UFC, has been working day and night to arrange an Elon Musk vs. Mark Zuckerberg fight. He believes the fight could make billions of dollars.

He doesn't seem to understand that you can watch nerds fight for free on Infosec Twitter.
ðŸĪĢ128ðŸŦĄ12😁6ðŸ”Ĩ3👍2🎉1