vx-underground
47.5K subscribers
4.1K photos
438 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
OSINT challenge
πŸ€“80🀣36🫑9πŸ€”3😁2πŸ‘1πŸ’―1
August 29, 2023 the United States Federal Bureau of Investigation announced the takedown (or dismantling?) of the infamous and long reigning botnet, Qakbot.

Qakbot is believed to have started in 2007, or 2008. Others argue that Qakbot (in its current form) appeared sometime in 2015 or 2016. Qakbot has been around a long time, and it appears the group intends on staying around for a lot longer.

Today Talos Intelligence shared information on the continuing operations of Qakbot. It is now believed the FBI (and associated partners) took down Qakbots C2 infrastructure. They did not takedown their spam delivery infrastructure. Talos noted previous Qakbot campaigns, labeled as "AA" and "BB", are active once again and note the distribution of Ransom Knight ransomware (alternatively referred to as Cyclops) and the Remcos backdoor.

You can read the full writeup- IOCs, further analysis of Qakbot AA/BB campaign, and more, here:

https://blog.talosintelligence.com/qakbot-affiliated-actors-distribute-ransom/
🀣38πŸ‘12❀2πŸ’―2
We recommend reading "The Lazarus Heist: From Hollywood to High Finance: Inside North Korea's Global Cyber War" by Geoff White.

The book provides key insights into North Korea's geopolitical motivations, historical context, the Kim Dynasties evolution from smuggling goods, methamphetamine production, their suspected USD counterfeiting operations (Superdollars!) to the present Lazarus Group as we know it.

From a technical perspective, the book is subpar - however it is evident this books target audience is not for the technically inclined. This is not a malware analysis book.

But, this book provides incredible (literally, absolutely incredible) insight into how Lazarus Group thoroughly performed reconnaissance on targets, how they precisely modified SWIFT environments in an attempt to steal $1,000,000,000 from the Bank of Bangladesh, and how their attacks against organizations effected company executives, individual employees, politicians, journalists, and law enforcement from all across the globe.

10/10
πŸ‘79❀16πŸ”₯9🫑7😎7πŸ‘4πŸ€“3😱2
When developing malware it is important to inform any potential analysts the code is not malicious. Leave them a simple message, leave a string in the code as simple as "this is not malware, go away".
🀣87πŸ€“26🀯11πŸ‘6❀5πŸ‘4😁3πŸ’―2
We're uploading 228,030 new malware samples to our VXDB (223GB uncompressed).

Reminder that our malware database is free. You can search through our entire malware collection and download to your hearts content =D

Total samples available: 18,995,422

https://virus.exchange
❀‍πŸ”₯69❀15πŸ‘6πŸ”₯3
Hello Kitty ransomware group, the group most known for ransoming video game publisher CD Projekt Red, had their source code leaked online today.

Information and data via 3xp0rtblog

You can view the source code here: https://github.com/vxunderground/MalwareSourceCode
πŸ”₯40πŸ’―5πŸ‘3😒2
vx-underground
Hello Kitty ransomware group, the group most known for ransoming video game publisher CD Projekt Red, had their source code leaked online today. Information and data via 3xp0rtblog You can view the source code here: https://github.com/vxunderground/MalwareSourceCode
It should be noted however that the leaker, kapuchin0, states he (Hello Kitty ransomware?) no longer need this and they intend on developing something superior to Lockbit ransomware group.
🀣55πŸ’―5πŸ‘3❀1πŸ”₯1
Sebastien Raoult, known online as Sezyo Kaizen, an affiliate (or as the courts write, 'co-conspirator') to the ShinyHunters data broker group, has plead guilty in the United States for conspiracy to commit wire fraud and aggravated identity theft

He is facing 27 years in prison
🫑76😱21🀯8🀣8❀3πŸ‘1
Dark Angels ransomware group hasn't even finished their payment portal for victims. The Johnson Controls page is just Lorem Ipsum 😭

Image via malwrhunterteam
🀣121❀4😒2πŸ‘1
If exploit developers, reverse engineers, and malware developers were alive in the medieval era they'd be the crazy person living out in the woods trying to perform alchemy spells like turning wood into gold
❀‍πŸ”₯86😁50πŸ’―18πŸ‘5❀4🫑3
🀣144❀70πŸ’―30😒15😎8😁7πŸ€“5πŸ‘4πŸ”₯3🀯2
Dharma ransomware (alternatively referred to as Crysis ransomware) creates payloads which work on Windows 2000.
😍114🀣50🫑26πŸ‘6πŸ‘5😁3😱3
🀣142😁10πŸ‘6πŸ‘4😒3πŸ”₯2πŸ€”2😱1
We've updated the vx-underground malware sample collection

- NokoyawaRansomware
- RhadamanthysLoader
- RoyalRansomware
- Vidar
- BoldMove
- DarkBitRansomware
- BlackSnakeRansomware
- ParadiseRansomware
- GigabudRAT
and more...

Check it out here: https://www.vx-underground.org/
πŸ”₯28❀4πŸ‘2❀‍πŸ”₯1πŸ™1
Exchange this desktop with a Gateway computer, with the weird cow commercials, and a 50lbs (22kg) CRT monitor.
πŸ‘35❀17🀣7πŸ€”5
A man on Twitter has created the dumbest post (and thread) in all of Twitter history. This is not an easy achievement either.

!!! Caution: reading this thread may result in spontaneous combustion !!!

tl;dr random guy writes erotic hacker fiction, says incomprehensible nonsense, normies foam out the mouth at the epic 1337ness

https://twitter.com/PatrickByrne/status/1711440905943572918
🀣68πŸ‘4πŸ€”3❀2😱2🀯1
We've updated the vx-underground InTheWild malware collection. We've added InTheWild.0088 - InTheWild.0094. It is 120,000 new malware samples available for bulk download.

Have a nice day.

https://vx-underground.org
πŸ”₯27❀8πŸ‘5🀣2πŸ€“1
We've uploaded more malware samples to VXDB. There are now 19,223,330 samples available for download.

It is free. 🫑

https://virus.exchange
🫑36❀18πŸ‘3πŸ₯°3πŸ”₯2πŸ€“1
More updates to vx-underground.

- The Old New Thing archive has been updated for August, 2023 and September, 2023

- The Malware Analysis collection has been updated, 95 new malware analysis papers have been added via @malpedia.

More to come. 🫑

https://www.vx-underground.org/
😘18🫑6πŸ‘3❀2πŸ”₯1πŸ€“1
David, why you gotta leave us a mixed review on our book because of Amazon recommendations 😭
🀣186πŸ€“11😁8🫑4πŸ‘3🀯1
It's that time of the year again.
πŸ”₯109🀣74😎11😁6❀2πŸ’―2πŸ‘1😱1πŸ€“1🫑1