vx-underground
47.5K subscribers
4.09K photos
437 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Google yielded poor results. Bing immediately understood the issue.

Thanks, Bing.
🤣109😁9🎉7👍42🔥2💯2
This media is not supported in your browser
VIEW IN TELEGRAM
A video illustrating how internet nerd fights work
🤣665😍3👍2
Trellix reported they've observed suspected state-sponsored activity abusing the Discord CDN for malware delivery.

This is disgusting.

Who would abuse a free and publicly accessible chatroom system for nefarious purposes?!
🤣121🤯13😇5👍4😁42
vx-underground
Trellix reported they've observed suspected state-sponsored activity abusing the Discord CDN for malware delivery. This is disgusting. Who would abuse a free and publicly accessible chatroom system for nefarious purposes?!
The post is meant to be satirical. Chat systems have been abused to deliver malware, house it, or exfiltrate data since ... the 90s?

¯\_(ツ)_/¯
🤓65😁10❤‍🔥9😍3👍1🤝1😘1
Graf, while we appreciate the 5-star review, we are disappointed you would disrespect us with such hurtful words.

Of course the book has anime girls.
😁79🤣42🫡18👍6🤓31💯1
The Ukrainian Cyber Alliance has taken down Trigona ransomware group.

Information via AlvieriD
🔥126🤣46👍17❤‍🔥7😢6🫡6👏5🤯5🤓5🤔2🥰1
We've updated the vx-underground APT collection. We've added papers ranging from August, 22nd 2023 - October 13th, 2023.

See attached image for list of all additions.

Have a nice day.

https://www.vx-underground.org/
25🔥13👍3🎉1💯1🫡1
We've had people continually inquire on buying a physical copy of vx-underground.

This is a difficult thing for us to do. It is 5TB+ and continually growing. A 5TB harddrive would be required, shipping, and payment for our time and effort.

Est. cost $150 - $300+
53🤣32🤝14🔥8🫡7👍4👏4😎3❤‍🔥2😢1
This is Maksim Yakubets. Feel old yet?
🤣68😁9😱5🫡52🤔2👍1🤯1
October 17th - Ukrainian Cyber Alliance takes down Trigona ransomware group, taking down servers and seizing wallets.

October 19th - EUROPOL takes down RagnarLocker ransomware group

Image 1 & 2: Ukrainian Cyber Alliance
Image 3: Ragnar Locker
😎57👍15😢11🤣8🫡87💯3🤔2
vx-underground
This is Maksim Yakubets. Feel old yet?
It appears people do not know (or remember) Maksim Yakubets.

Yakubets is a member of Evil Corp. He is behind Zeus, Dridex, and suspected to have ties to ransomware groups.

He married an FSB officers daughter and owns a Lamborghini with the license plate "Thief".
🤣121🫡2111😎8🔥7❤‍🔥3🤔3👍2🙏1
We have a reverse engineering challenge for you nerds.

In Black Mass Vol. 3, scheduled for October, 2024, we will unveil "Matryoshka". Matryoshka is a strange malware proof-of-concept. We would like you to reverse engineer it to tell us how you think it works.

* Matryoshka only works on Windows 10 or above
* proof-of-concept is not malicious
* you're free to reverse engineer it by any means necessary: static, dynamic, sandbox, making your friend do it, whatever.
* malware proof-of-concept is NOT packed
* Matryoshka does not possess any anti-debug or anti-VM functionality
* source code and full explanation of code will be released in Black Mass Vol. 3
* best write up goes in Black Mass Vol. 3 to show the defensive aspect to Matryoshka!
* binary is being shared in .7z with a super 1337 password!!!!11

inb4 someone reverse engineers it in totality in 2 minutes because they've seen "Kob*".

Matryoshka download: https://samples.vx-underground.org/root/Samples/Matryoshka.7z
👍47❤‍🔥2110🫡10🤣6🤔5💯1
The whole "Red Team Fit" thing on Twitter is a complete joke. Try "Malware Nerd Fit". Last night we traversed the entire planet 12 TIMES. We were Naruto running so fast this dumb app couldn't even calculate our rate of speed.
😁99🤣167👍4👏3🤯3😢1
Parents, now is the time to be on guard. We are once again reminding you to be diligent about checking your child's candy throughout the Halloween season. vx-underground recently discovered THREE ransomware affiliates from ALPHV ransomware group inside of a Snickers.
🤣107🤯16🔥4😱2
DO NOT TRY TO DOWNLOAD MALWARE SAMPLES ONTO A PS4
🤣148😁26🤓15🔥12😱11❤‍🔥5👍41🤝1
Yeah, Okta's support system was compromised. Yeah, they had access for over 2 weeks. Yeah, the Threat Actor(s) probably went through some pretty sensitive stuff...

But they offer SSO at $2/user, so it's not really that big of a deal, right?
🤣57😁8👍4🫡2❤‍🔥1🤔1😍1