vx-underground
47.6K subscribers
4.11K photos
438 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
When the security analysts and network administrators detect unusual activity on the network
🀣114😁28❀6πŸ€ͺ5🫑3πŸ‘2
The T-Mobile ConnectivitySource retailer breach contains 146,109 audio recordings of customers calling stores. The retailer is present in 38 states.
🀯58🀣11😁9😱5🫑3πŸ‘2😒1πŸ€ͺ1
We listened to over 500 recordings. Highlights include:

- Employee calls in sick on their first day on the job
- Someone got the job! (Congrats Ms. Sneed)
- Old people who are extremely confused and refer to cell phones as 'towers'.
- People who are not sure if they're even talking to T-Mobile (???)
- A woman telling the store her Dad's house burned down (and laughs about it?)
- A guy who did not get the job and asks why very, very, very aggressively
😁122🀣29😱16πŸ‘6πŸ”₯6❀4🫑2😒1
We're almost done with migration.

Thank god. Seriously. It took 2 christmas miracles to get this thing where it is now
πŸŽ‰84πŸ‘15πŸ₯°6❀‍πŸ”₯5🀯1
vx-underground is a dangerous website. When visiting the website it is advised you wear a full hazmat suit. If that is not an option, a construction hard hat will suffice.

Thanks,
😁100🫑31🀣14πŸ‘8❀5😱5πŸ’―2🀩1😍1πŸ€ͺ1
Hello,

We've had a few people reach out to us regarding to Black Mass Volume I & II. Yes, the PDFs are intentionally left publicly available on the website. The e-book is free, the physical copies are available on Amazon.

Nobody leaked them on Discord.

Have a nice weekend:)
❀‍πŸ”₯60🀣41πŸ‘9πŸ‘5πŸ€ͺ4😁2πŸŽ‰2🫑2😱1
❀70πŸ‘9🫑8❀‍πŸ”₯4πŸ₯°1πŸ‘1😱1
Today Basssterlord, a member of National Hazard Agency (a subgroup of Lockbit ransomware group) deleted his Twitter profile.

He requested that we note that it was not due to harassment or law enforcement.

He said they're very busy and now is not a good time to meme onlineπŸ˜‚πŸ˜‚

He was spending too much time memeing and shit posting πŸ˜‚πŸ˜‚πŸ˜‚
🀣119🫑18πŸ‘7😱2
It's always important to practice computer hygiene. We recommend washing your computer daily with soap and warm water.

This can help prevent viruses and bacterial infections!
🀣158🫑22πŸ€ͺ17πŸ‘8😁5❀4😱2😒2
Because nerds keep asking us about alleged Sony ransomware incident

tl;dr Threat Actors did not deploy ransomware, no corporate data was stolen, services not impacted. Data was exfiltrated from Jenkins, SVN, SonarQube, and Creator Cloud Development. They're extorting Sony
❀29🀣25πŸ‘8πŸ€”4🫑2
cl0p ransomware group has ransomed SickKids, one of the largest pediatric healthcare facilities in the world.

They've exfiltrated 13 years of data related to fertility, pregnancy, and healthcare information on children (including newborns).

https://techcrunch.com/2023/09/25/decade-of-newborn-child-registry-data-stolen-in-moveit-mass-hack/
😒108πŸ€”10πŸ”₯6😁4❀2πŸ‘2
Interesting side note: In 2022 this facility was ransomed by Lockbit ransomware group. Subsequently Lockbit ransomware group administrative staff apologized (for the first time) and gave the decryption key for free (for the first time).

Let's hope cl0p does the same.
πŸ‘71πŸ₯°8πŸ€”8πŸ‘6
vx-underground
cl0p ransomware group has ransomed SickKids, one of the largest pediatric healthcare facilities in the world. They've exfiltrated 13 years of data related to fertility, pregnancy, and healthcare information on children (including newborns). https://tech…
Hello, apologies - we believe this post lacks clarity.

They did not ransom* SickKids, as in deploy ransomware, we meant they're extorting SickKids because they exfiltrated sensitive data.

To be the best of our knowledge no ransomware payload was deployed.
🫑53πŸ‘5❀4
Today McDonalds Point-of-Sale system setup and executables were leaked online. An unidentified Threat Actor claims to have stolen the executables, installation scripts, etc. by pivoting off of McDonalds Free Wifi
πŸ”₯59🀣52πŸ‘4πŸ€”4❀2
Today someone operating under the name "MajorNelson", a nod to the former Director of Programming for the Microsoft gaming network Xbox Live, asserts RansomVC is lying.

He then released all the content RansomVC claimed to have into the general public.

tl;dr another Sony leak?
πŸ‘38πŸ€”22
Conduent has been compromised for the past 3 months and nobody has noticed yet.

A Threat Actor today expressed frustration with the company after he phished several employees via text messaging.

He expressed his frustration in the Breached telegram chatroom, as well as our e-mail address, by sending us a lengthy e-mail with dozens of pictures and hundreds of documents as proof.

tl;dr phished some employees, pivoted into HR, read company e-mails, read chatrooms, scraped everything he could get access to from the users
🀣91πŸ‘14❀5😱4🫑4πŸ”₯3