vx-underground
47.5K subscribers
4.1K photos
438 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Security researcher Gi7w0rm accidentally got access to the International Space Stations urine recycling system.

He was able to identify when astronauts used the restroom (based on urine percentage increasing) and when it was processing urine (urine percentage decreasing).
๐Ÿคฃ164๐Ÿ˜9๐Ÿค”8๐Ÿ‘7โค4๐Ÿซก4๐Ÿคช4๐Ÿ‘3๐Ÿคฏ1
Note: Per the insights from a space nerd, SWGlassPit, this is publicly available telemetry originally released for a now defunct project known as ISS live.

tl;dr ISS lets you monitor pee-pee and poo-poo? We had no idea =D

Real-time monitoring is here: https://iss-mimic.github.io/Mimic/
๐Ÿ˜36๐Ÿคฏ11๐Ÿ‘6๐Ÿซก5๐Ÿคช3
We have pioneered a new method for extending WiFi technologies (we stole it actually). Our methodology uses aerodynamic engineering, or whatever fancy word works here. Please see the attached image which demonstrates our technology. We believe this was revolutionize WiFi.
๐Ÿ”ฅ100๐Ÿคฃ70๐Ÿ˜15๐Ÿ˜ฑ7๐Ÿค”6๐Ÿ’ฏ6โค5๐Ÿ™5๐Ÿ‘2
The past 72 hours we have added 221,319 new malware samples to the VXDB. We only have 15,778,681 samples remaining. ๐Ÿซก

Reminder that the VXDB is free for anyone to use. Oh, and it's open source.

https://virus.exchange

Have a nice day.
โค47๐Ÿซก22๐Ÿ‘1
When Scattered Spider compromised MGM they tried to modify code for the slot machines to make them spit out money ๐Ÿ˜‚๐Ÿ˜‚

These nerds are going full Ocean's Eleven
๐Ÿคฃ72๐Ÿ”ฅ10โค5๐Ÿ˜4๐Ÿ’ฏ2๐Ÿค”1
Do wE kNoW iF CaEsArS wAs HaCkeD?!

Yes, they were compromised around the exact same time as MGM and access to Caesar's was compromised using the exact same technique that was used against MGM.

Read the U.S. Securities and Exchange Commission report, nerds.
๐Ÿ‘27๐Ÿคฃ21โค5๐Ÿคฏ4
While we're busy uploading data to the VXDB, and migrating data to our new host, feel free to add one of our members on Rocket League.

In homage to Wazawaka's wild antics, the Rocket League account is: "MIKHAIL MATVEEV"
๐Ÿคฃ76๐Ÿ˜5๐Ÿซก4โคโ€๐Ÿ”ฅ2๐Ÿ‘1
Hello,

We are aware ALPHV ransomware group criticized us for spreading misinformation. They incorrectly attributed us to the Financial Times article about ALPHV affiliates attempting to tamper with slot machines

We will speak with ALPHV and resolve the issue.

Thanks,
๐Ÿ‘40๐Ÿซก23๐Ÿคช13โค1๐Ÿ˜ข1
Thank you to the ALPHV ransomware group administrative staff for correcting their blog post and correcting the misattribution to us.

We wholeheartedly appreciate.
๐Ÿ‘50โค10๐Ÿซก9๐Ÿ‘2๐ŸŽ‰1
This media is not supported in your browser
VIEW IN TELEGRAM
U+4VeZwaR37JIofFHKafYTXVXQhP278yfarcWWRwZlI=
๐Ÿค”74๐Ÿคช17๐Ÿ”ฅ12๐Ÿ˜ข3๐Ÿซก3๐Ÿ‘2๐Ÿ˜ฑ2๐Ÿคฏ1
๐Ÿฅฐ73๐Ÿ”ฅ22๐Ÿคฃ14๐Ÿ‘5๐Ÿ˜5๐Ÿค”3โคโ€๐Ÿ”ฅ1๐Ÿคฉ1๐Ÿซก1
While everyone is focusing on the catastrophe of the MGM breach, it should be noted that it is business as usual for other ransomware groups.

Note: Publicly listed victims on ransomware websites indicate the victim did not pay and/or negotiations are still on-going.

- Cactus ransomware group was the most active this month (so far), with 30 new victims publicly displayed. Their victims are primarily agricultural and industrial organizations.

- ALPHV ransomware group claims 19 new victims in September. Besides MGM, they have claimed law firms, architecture and design companies, real estate companies, physicians offices, investment companies, and media analysis companies.

- Lockbit ransomware group claims 19 new victims as well. Lockbit ransomware group most notably targeted a non-profit hospital, a Behavioral health center for the mentally ill, 2 school distracts located within the United States, and law firm which represents American Veterans who need legal assistance.

- CryptBB, a new and emerging group, claimed 8 victims, most notably a school district in the United States.

- NoEscape claims to have compromised US-Canada water organization, the International Joint Commission, and threatens to leak sensitive government data.

- BianLain attacks Save the Children International, a 104 year old non-profit which aided children who were victims of WW2 nazi concentration camps (among many other incredible deeds).

- RansomedVC claims 30 new victims this month, primarily leveraging web exploitation and intimidation tactics.

Other active ransomware group activity this month: RagnarLocker, Threeam, CiphBit, Trigona, Knight, Akira, Monti, Stormous, Blacksuit, Play, RansomHouse, IncRansom, Lorenz, BlackByte, Qilin, RaGroup, Everest, Mallox, Medusa, Rhysida, 8base, Abyss.

In the month of September, 2023, there have been over 200 newly documented ransomware attacks. Again, this does not include victims who have paid.

The most notorious groups still remain on top: ALPHV and Lockbit. Both have existed (in some manner) since at least 2019.
๐Ÿ‘22๐Ÿซก10๐Ÿ˜ข9โค6๐Ÿ”ฅ5๐Ÿคฃ5๐Ÿ‘4๐Ÿคฏ3๐Ÿ’ฏ3๐Ÿค”1
For Black Mass Volume II we spent an extra shiny penny, from our own pockets, to hire an artist who is an illustrator for Magic: The Gathering, Mythgard Tcg, Hit PointPress, Adi Shankar/Netflix, Legendary Games, and more.

Thanks to Wero Gallo Arias for the amazing work.
๐Ÿ”ฅ100โค20๐Ÿ‘6๐Ÿซก5๐Ÿ‘2๐Ÿ˜ฑ2โคโ€๐Ÿ”ฅ1๐Ÿคฃ1
We have passed 23,000 subscribers on Telegram.

Thank you for the love and support. โค๏ธ

We look forward for continually serving you all with malware source code, samples, papers and our dumb memes.

Thanks,
โคโ€๐Ÿ”ฅ97โค30๐Ÿ‘7๐Ÿ’ฏ6๐Ÿ”ฅ5๐Ÿซก4๐ŸŽ‰3๐Ÿคช3๐Ÿ˜ฑ1
Today Lockbit ransomware group issued a poll to all of their affiliates

Lockbit is considering implementing new rules for Lockbit affiliates due to their frustration with ransomware negotiators. Currently, Lockbit ransomware group has no rules in place for how much (or how little) affiliates can ransom a company for. They are considering "regulating" ransom demands

They state newer affiliates are giving large discounts to victim companies out of desperation for money, whereas more experienced affiliates do not cave to negotiator's proposed payment from the victims

National Hazard Agency, a subdivision of Lockbit ransomware group, has stated they will no longer accept payments below 3% of the companies annual revenue. They will immediately retaliate against any negotiator who approaches them with an offer of less than 3% of the companies revenue. The retaliation will be complete destruction of company data

Image 1. Original Lockbit poll
Image 2. Translated poll
Image 3. Message from National Hazard Agency
๐Ÿ”ฅ42๐Ÿคฃ14๐Ÿซก8โค1๐Ÿ‘1๐Ÿ‘1๐Ÿ˜1
Thank you to the person who sent us a lovely poem... from Greece's... Hellenic Army?

Image 1. Lovely poem
Image 2. Email headers
โค42๐Ÿ˜3๐Ÿซก3๐Ÿฅฐ1