vx-underground
47.6K subscribers
4.11K photos
438 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
๐Ÿค”
Updates:

-We are aware some samples have become corrupted post migration. All have been repaired. Go live is October 22, 2021

-18,000+ PDBs & symbols in queue for our reverse engineer friends
Monday, October 18th, 2021 a Turkish individual leaked source code to Cerberus Android Banking Trojan. This appears to a variant of a previously leaked version we possess.

You can download Android.Cerberus.d here: https://github.com/vxunderground/MalwareSourceCode/tree/main/Leaks/Android
Additions to the VXUG papers collection:

-SmashEx: Smashing SGX Enclaves Using Exceptions by Jinhua Cui, Jason Yu, Shweta Shinde, Prateek Saxena, Zhiping Cai

-Analyzing ransomware negotiations with CONTI: An in-depth analysis by DIFR Research Group

https://vx-underground.org/papers
Groove ransomware groups asks ransomware operators to unite to attack the United States. Groove asks operators to stop attacking Chinese organizations and warns of a possible race war in the United States.

Image 1: EN
Image 2: RU
Conti ransomware group has put out a statement regarding the recent REvil activities. We have archived it and placed it on Pastebin.

Title: Announcement. ReviLives.
Subject: Own opinion.

You can read it here: https://pastebin.com/kMQAbcFa
Following the recent fallout of REvil, the new spokesperson of REvil, 0_neday, has been banned from XSS.
Espector.7z
101.6 KB
I will share something on Telegram before it goes live on vx-underground. Here are samples to APT Espector, a Chinese UEFI Bootkit and FiveSYS, a Microsoft signed Windows Rootkit. :) Have a good weekend:)

-smelly
We have another ransomware toolkit leak. We will share it soon.

Happy weekend, Blue Teams.
Updates to the vx-underground APT collection:

- FiveSYS, Microsoft signed Rootkit
- TinyVNC from Kimsuky Group
- APT Harvester campaign
and more...

Check it out here: https://vx-underground.org/apts

*Samples includes
Total malware samples in the vx-underground malware collection: 2,348,257

Goal: 26,000,000
We've made updates to the vx-underground APT collection:

- FontOnLake, linux malware
- APT InSideCopy

Samples and papers included.

Check it out here: https://vx-underground.org/apts
We've updated the vx-underground malware source code repository. We have added Android.GhostBot. An Android spyware proof-of-concept capable of surveillance on the target, functionality similar to Pegasus

You can check it out here (under Android section): https://github.com/vxunderground/MalwareSourceCode
Grief ransomware group has ransomed the National Rifle Association (NRA).

Link: http://griefcameifmv4hfr3auozmovz5yi6m3h3dwbuqw7baomfxoxz4qteid.onion
๐Ÿ‘1
Friday, October 29th, 2021 we will release the ransomware toolkit we have acquired.

The tools we possess we have confirmed to be used by both Conti ransomware group and BlackMatter ransomware group. They are scripts stolen from TeamTNT - modified to deliver ransomware.