vx-underground
47.5K subscribers
4.1K photos
437 videos
84 files
1.48K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Uhaul was breached. 13GBs of data was exfiltrated from their SharePoint. Initial access was granted by social engineering an employee through text messages.

tl;dr another day in Shangri-La
❀32πŸ’―14😁6😱5πŸ‘3🀣2
CloudFlare did a blog yesterday about how the company they use (Okta) was breached (again) and how the Threat Actor tried to pivot into their network (again) and how they mitigated it (again).

The blog gives recommendations to Okta πŸ˜‚πŸ˜‚

https://blog.cloudflare.com/how-cloudflare-mitigated-yet-another-okta-compromise/
🀣68❀6😁6❀‍πŸ”₯2
Thank you to the person who submitted their Black Mass Volume II SOC Analyst coloring page.

It looks very nice. We will hang it on the refrigerator
πŸ”₯69🀣41❀8😁4πŸ‘3πŸ‘3🀩1
Okta stock fell 11% today 😭😭😭

... after they admitted they got compromised (again) through their support system (again) and the Threat Actor(s) tried to pivot to clients (again).

Even the $2/user SSO can't save them 😭
🀣71❀6πŸ‘4😒3
Luckily, even though their stock fell 11%, they're saving money. They laid off their entire internal Red Team in March because ???

Who needs internal security audits anyway???
🀣120😱6🫑5πŸ‘3😒2❀1
Coding malware is good for you.

- Teaches you low level programming concepts
- Helps get a better understanding of computer security
- Can help improve reverse engineering skills
- Improves focus, attention to detail, critical thinking skills
❀152πŸ’―30πŸ‘16πŸ‘6😎6πŸ€”5
Not everyone who codes malware is a bad person. Is every person who admires the engineering behind weapons a dangerous person? No.

Also, the engineering behind the AK47 is badass.

https://youtu.be/_eQLFVpOYm4
❀75πŸ’―18πŸ‘9🀣7πŸ€“3πŸ‘2πŸ€”2😒1
Seeing non-technical people seriously discussing malware will tempt you into diving face first into a woodchipper
πŸ”₯78🀣40😁9❀‍πŸ”₯6😒5πŸ‘3πŸ’―3
> post learning to code malware has its perk
> people comment lack of resources
...
> 11,372 malware papers
> 7,125 old-school-cool archived malware works
> 37,745 papers on state-sponsored malware
> 3,173 malware source code projects

NOT ENOUGH RESOURCES?! DO WE NEED MORE?!
🀣74❀25πŸ‘14πŸ‘4🀯2πŸ”₯1
ITS FREE BTW
❀71πŸ™9πŸ”₯6🀣3πŸ‘1🀯1
Security Researcher ValdikSS discovered German law enforcement have been MITM-ing XMPP data from jabber-dot-ru for the past 90 days. ValdikSS believes the MITM on jabber-dot-ru could have been persistent for atleast 6 months.

https://notes.valdikss.org.ru/jabber.ru-mitm/
🀯51πŸ‘10❀‍πŸ”₯8🀣6🫑6😁3😱3πŸ€”2πŸ€“2
Today an individual known online as "Tongue" was sentenced to 13.3 years in prison for advertising (and carrying out) Violence-as-a-Service on Telegram and Discord.

He is 22 years old. He will be released when he is 35 in 2037.

More information: https://krebsonsecurity.com/2023/10/nj-man-hired-online-to-firebomb-shoot-at-homes-gets-13-years-in-prison/
🀣80🀯11😱10❀4🫑4πŸ˜‡3😁1😍1
Yesterday 1Password released an Incident Response Report believing that when Okta was breached (again) the Threat Actor(s) tried to pivot to them.

They noted they used MalwareBytesβ„’ FREE AV
🀣107😁15πŸ€”8❀‍πŸ”₯2😒2❀1πŸ‘1
We'd like to note there isn't anything necessarily wrong with an enterprise environment using MalwareBytes, but it just seemed kind of odd to specifically note the usage of the free version... or even the specific AV itself.
πŸ€“53πŸ‘13🀣3πŸ”₯2❀‍πŸ”₯1
October 20th security researcher rivitna2 noted the return of HIVE ransomware rebranded as Hunters International. Additionally, BushidoToken noted a 60% code overlap between Hunters International and HIVE.

Hunters International denies the allegations Β―\_(ツ)_/Β―
😁38πŸ‘3😱1
tl;dr "we are not HIVE, but we have their code"
😁60🫑6πŸ€“5πŸ‘2❀‍πŸ”₯1
We've updated the vx-underground Windows malware paper collection

- 2022-03-11 - AV and EDR Evasion Using Direct System Calls
- 2023-04-18 - Process injection in 2023 - evading leading EDRs
- 2023-07-25 - Prefetch - The Little Snitch That Tells on You

https://vx-underground.org/
🫑35❀‍πŸ”₯8πŸ‘4❀2πŸ”₯2
Yeah, we got compromised by APT29, but luckily MalwareBytesβ„’ FREE AV stopped the Kremlin in their tracks! To be extra safe, we swung by the local Hilton Hotel and used their WiFi to install it
🀣121😁10❀8πŸ”₯2πŸ€“2
Everyone knows Russians can't visit Hilton Hotels. They're too decadent. They instantly explode and turn into sand.
🀣87😁8πŸ€”5❀‍πŸ”₯3πŸ’―3πŸ‘1😒1πŸŽ‰1πŸ€“1
🀣121πŸ”₯38😱10❀7🫑6❀‍πŸ”₯5πŸ€“4πŸ˜‡4😎4πŸ‘1😒1
The vx-underground podcast - but instead of discussing anything technical or meaningful we mumble incomprehensible nonsense for an hour and express our misanthropy in form of creative dance
πŸ‘56😁13❀5πŸ₯°3🀝2πŸ”₯1