vx-underground
47.3K subscribers
4.07K photos
435 videos
84 files
1.47K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
We've updated the vx-underground malware sample collection

- Amadey
- AppleSeed
- BlueFox
- CobaltStrike
- DTrack
- Gafgyt
- GraceWire
- LockBitRansomware
- NetWireRAT
- Orcus
- QakBot
- RaccoonStealer
- Rapperbot
- Vidar

https://www.vx-underground.org/
❀21πŸ‘5πŸ₯°1
🀣64πŸ€”29πŸ‘7🫑6😁4
cl0p ransomware group has created a clearnet domain to distribute stolen data from Ernst & Young.

As you can see, from the attached image below, cl0p runs on some of the most sophisticated infrastructure known to man. Their previous domain downloaded at 90KB/s. This one?
🀣102🀯8😁7🫑5πŸ‘2😒2πŸ€ͺ2
Microsoft flags the vx-underground malware source code collection as being unsafe.
🀣317🫑48😒14❀7😁6πŸ€”6πŸ‘4πŸ”₯4🀩4😱3🀯2
Internet nerds: the 90s were the best

The 90s:
🀣109πŸ’―10😁5😍4❀2πŸ”₯2πŸ‘1😒1
ALPHV ransomware group now provides an API for their ransomware leak site.

Neat.
🀣105πŸ”₯22❀‍πŸ”₯6❀5πŸ‘5🫑4
A book containing things that don't exist
🀣93😁15πŸ€”5πŸ€ͺ2πŸ‘1
As part of the vx-underground x @SentinelOne Malware Research Challenge, DLL_Cool_J released a paper on state sponsored Threat Actors targeting security researchers by weaponizing tools such as Ghidra.

This paper also provides historical examples.

https://www.sentinelone.com/blog/analyzing-attack-opportunities-against-information-security-practitioners/
πŸ‘23❀7πŸ”₯5
We spoke with an AI and Machine Learning scientist. His work includes novel cancer detection methods using machine learning and scalable finite difference methods for reinforcement learning.

AI is a hot topic. We'll be discussing AI in regards to cyber weaponry with him.
πŸ”₯78πŸ‘6πŸ‘4😁1
Behind the scenes at vx-underground (ignore the cat).
🀣180πŸ₯°20🫑14πŸ€ͺ9😁6πŸ€”6πŸ‘3❀2πŸ”₯2πŸ™2πŸŽ‰1
NoBit ransomware group states they encrypt data in SHA 😭😭😭
🀣209πŸ€ͺ10πŸ‘6😒3❀2πŸ€”2πŸ‘1🀩1πŸ’―1
NoBit contacted us regarding this message. They state we have misunderstood their post.
🀣186πŸ‘17😁12πŸ€ͺ11😒6🫑4❀‍πŸ”₯3πŸ€”2🀯1🀩1
How do you pronounce "CVE"?

1. C. V. E.

2. Svye

3. KaVooEe
πŸ€”91🀣65πŸ’―14🫑12😘5πŸ‘3🀯3❀‍πŸ”₯2😁2πŸ”₯1πŸ™1
Today ALPHV ransomware group gave us their autograph.

The administrators English penmanship is better than we expected
πŸ”₯79🀣43πŸ‘9😍6
People have been discussing the "death" of infosec Twitter. They have defined it's decline based on the number of KaVooEe's discussed each month.

Infosec is more than just KaVooEe's.
🀣72πŸ‘7❀2
Telegram is the only platform that vx-underground utilizes that can generate a 250% increase of web traffic and post engagement if we share images of cats.
πŸ€ͺ226πŸ₯°78🫑44❀26🀣20πŸ‘15πŸ’―9😍8❀‍πŸ”₯7πŸ”₯7πŸ‘6
We've updated the vx-underground malware source code collection on GitHub

- Javascript.Kaoom.Unknown
- Panel.BlackHole.IonCube.a
- Win32.GreenDamCensor.Exploit.a
- Win32.Bootkit.BlackLotus.b

https://github.com/vxunderground/MalwareSourceCode
❀29❀‍πŸ”₯7πŸ‘6😱2🫑1
A money mule cashing out for a Threat Actor (2023, colorized)
🀣124😍19😁8❀5πŸ‘3πŸ₯°3
Today David Grusch, an individual who served 14 years with the United States Air Force and National Geospatial Intelligence Agency, testified under oath that the United States government possesses 'Unidentified Anomalous Phenomena' and has been reverse engineering it for decades

More info: https://www.cbsnews.com/news/ufo-hearing-congress-uap-takeaways-whistleblower-conference-david-grusch-2023/
🀣48😱14πŸ‘7😁5🀯5πŸ”₯4❀2❀‍πŸ”₯1
Today haveibeenpwned announced they have acquired the Breached Forum database. An individual using the alias "breached_db" compromised Breached in November, 2022. This was when Pompompurin was the administrator.

This database leak exposes PII on 212,000 users.
😁57🀯19πŸ‘15😒8