vx-underground
47.6K subscribers
4.11K photos
438 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
🤣115😁7😎7🤯4🤓4👍21
This media is not supported in your browser
VIEW IN TELEGRAM
YouTuber Mr. Beast is warning his users about scammers who are using DeepFakes of him to scam his users.
😁68🤣48😱10🤯63🔥3👍1
Thursday and Friday vx-underground staff members DuchyRE and f0wlsec will be present at Hacktivity Conference. They'll be distributing limited edition shiny vx-underground UwU stickers
❤‍🔥102👍8😍4😱2🤣2🤓1
Beep boop we are nanobots
🤣74😁9🤔5💯54🤯3🫡3😘3🔥1🤝1
vx-underground
Beep boop we are nanobots
Dos activaciones, el doble de nanobots.
🤣42🫡10
Thank you to our friends at TheTorProject for the super cool shirt and stickers =D
68🔥20👍15🎉4
We are now selling the ARREST WAZAWAKA shirt. The front of the shirt says "Arrest Wazawaka" in English and Russian. The back contains his FBI Most Wanted Poster. The sides of the shirt contain the ransomware groups he was most known to be part of (omit Babuk).

ARREST WAZAWAKA!
🔥64😁9😍9👍5🫡52
Someone made this and requested we post it. Zoomers gonna be zoomers
19😁8🤓3
Thank you to our friend John Hammond for the new logo design
🔥65😁25🤔3💯2
We received quite a few e-mails today from the Red Cross of Italy - compromised e-mails. The compromised e-mails come from an unknown individual asserting that the Red Cross of Italy is stealing (and laundering?) money

They also say they're not going to ransom them

¯\_(ツ)_/¯
🤔46🤯11👍82😢2
Twitter no longer displays the full URL to websites linked in posts.

Will people try to use this to phish people?
Anonymous Poll
90%
Yes, sooner or later
3%
No, it won't work
7%
They'll try but fail
💯31🤔61
OSINT challenge
🤓80🤣36🫡9🤔3😁2👍1💯1
August 29, 2023 the United States Federal Bureau of Investigation announced the takedown (or dismantling?) of the infamous and long reigning botnet, Qakbot.

Qakbot is believed to have started in 2007, or 2008. Others argue that Qakbot (in its current form) appeared sometime in 2015 or 2016. Qakbot has been around a long time, and it appears the group intends on staying around for a lot longer.

Today Talos Intelligence shared information on the continuing operations of Qakbot. It is now believed the FBI (and associated partners) took down Qakbots C2 infrastructure. They did not takedown their spam delivery infrastructure. Talos noted previous Qakbot campaigns, labeled as "AA" and "BB", are active once again and note the distribution of Ransom Knight ransomware (alternatively referred to as Cyclops) and the Remcos backdoor.

You can read the full writeup- IOCs, further analysis of Qakbot AA/BB campaign, and more, here:

https://blog.talosintelligence.com/qakbot-affiliated-actors-distribute-ransom/
🤣38👍122💯2
We recommend reading "The Lazarus Heist: From Hollywood to High Finance: Inside North Korea's Global Cyber War" by Geoff White.

The book provides key insights into North Korea's geopolitical motivations, historical context, the Kim Dynasties evolution from smuggling goods, methamphetamine production, their suspected USD counterfeiting operations (Superdollars!) to the present Lazarus Group as we know it.

From a technical perspective, the book is subpar - however it is evident this books target audience is not for the technically inclined. This is not a malware analysis book.

But, this book provides incredible (literally, absolutely incredible) insight into how Lazarus Group thoroughly performed reconnaissance on targets, how they precisely modified SWIFT environments in an attempt to steal $1,000,000,000 from the Bank of Bangladesh, and how their attacks against organizations effected company executives, individual employees, politicians, journalists, and law enforcement from all across the globe.

10/10
👍7916🔥9🫡7😎7👏4🤓3😱2