vx-underground
47.4K subscribers
4.09K photos
436 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Over the past 24 hours we have received dozens of e-mails from compromised government e-mail addresses.

This is a clear illustration of how easy it is for Threat Actors to get access to legitimate e-mails to social engineer people (or corporations).
πŸŽ‰62🀣20πŸ‘4😒4🫑3πŸ”₯2πŸ€”2😁1
A new combatant has entered the arena.

This individual e-mailed us from a compromised United States government e-mail. They also wanted to provide to message to the other individuals e-mailing us.

Image 1 & 2 is e-mail
Image 3 is headers for nerds screaming spoof at us
🀣61🫑13πŸ€”12😁5πŸ‘4😱2
Hello.

It is nice seeing so many photos of people wearing our merchandise. It is a surreal feeling knowing that so many people genuinely care about our goofy little website with its bad HTML and edgy images.

Thank you for the love

P.S. More nerd photos attached
❀71πŸ‘4🀣3πŸ”₯1
Thank you to our amazing friend and colleague LaurieWired for the mysterious floppy and cool Pokemon card.

However, it is 2023 and we do not have anything to view this....
🀣86πŸ”₯16😁13😒8❀4πŸ‘2
We've updated the vx-underground paper collection

- 2022-12-04 - SilentMoonWalk - Demonstrating call stack spoofing
- 2022-12-30 - Code Execution against Windows HVCI
- 2023-07-27 - Kerberos UAC Bypass - Abusing Kerberos Tickets for UAC Bypasses

https://www.vx-underground.org/
πŸ‘21❀‍πŸ”₯6🫑3
Life goals:

- Get an autograph from Anatoliy Sergeyevich Kovalev
- Get an autograph from Maksim Viktorovich Yakubets
- Visit Pyongyang (without being kidnapped)
- Visit Russia to meet Mikhail Pavlovich Matveev and ALPHV administrative staff (without being kidnapped)

The final two goals have a high risk of being kidnapped or being sent to labour camps. So it's more of a pipe dream
πŸ’―67🀣49πŸ‘9❀7😒5🫑5😁1πŸ€ͺ1
We've updated the vx-underground malware sample collection

- Arechclient2
- CobaltStrike
- Emotet
- IcedId
- LockBitRansomware
- NetSupportRAT
- NSIS
- Paradies
- PoweRAT
- QakBot
- RedCap
- RedLine
- RoyalRansomware
- SpyNote
- Xdr33

Check it out here: https://www.vx-underground.org/
🫑29❀9πŸ‘5πŸ₯°1
This morning ALPHV ransomware group released over 1TB of data from a Catholic university in Illinois.

On the front page of the ransom announcement for the school they display a photo of an alleged HR sexual harassment complaint. It shows a male receiving a fellatio from a woman.
🀣79😱11🀯5🫑5πŸ€”3❀2πŸ‘2πŸ”₯1😒1
Ransomware is bad - but if the HOA was ransomed we would celebrate.

That's all.
πŸ’―61πŸ‘7🫑7🀣5❀4😁2πŸ€”2❀‍πŸ”₯1πŸŽ‰1
We've updated the vx-underground paper collection

- 2023-07-14 - Oh-No a Vulnerability & PoC demonstration in a popular Anticheat tool
- 2023-07-31 - Intel Redirect Protection Internals
- 2023-08-02 - Using Call Frequency to Identify API Functions

https://www.vx-underground.org/
❀14❀‍πŸ”₯2πŸ‘2
Today Raccoon Stealer announced their return.

The Raccoon Stealer team informed us that the individual from their team arrested in October, 2022 was responsible for infrastructure. Following his arrest they decided to rebuild the entire infrastructure from scratch.
πŸ₯°47🀣20😱11πŸ”₯8❀6πŸ‘5
Chinese authorities have pledged to β€œpublicly disclose a highly secretive global reconnaissance system” operated by the U.S. government following an investigation into the alleged hacking of earthquake monitoring equipment in Wuhan.

https://therecord.media/china-accuses-us-global-reconnaissance-system-wuhan
πŸ€”41πŸŽ‰14🀣13❀7😁2🫑2πŸ”₯1
🀣166πŸ”₯10πŸ€”8πŸ’―8🫑4❀2
Some dork on TikTok claims to uncovered an NSA (or CIA) plot about the "those muthafuckers are not real" airplane girl. As proof, he posts a traceroute from his computer to her website. He 100% believes the traceroute is proof that this viral video is being covered up because she discovered aliens.

Her website is hosted on HostGator and uses a WordPress install. It is shared hosting.

He 100% believes the United States government can only buy servers in the Washington DC metropolitan area. (???)

https://twitter.com/xInFiNiTe1x/status/1690909158793433088
🀣119😁12πŸ‘7❀5πŸ€”4πŸ€ͺ4❀‍πŸ”₯2πŸ™2