vx-underground
45.4K subscribers
3.9K photos
412 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
I know absolutely nothing about AI or LLMs. But, the boys and I decided to goof around (as is tradition) and built an LLM using all the papers we've collected.

1. It's really cool
2. It's super slow and super resource intensive
3. It likes to hallucinate because we fed it super unstructured data (see image 2)
4. No idea what to do with this. This would require insane infrastructure, significant time investment, and ???, to not make this ghetto.
❀57😁13πŸ‘11πŸ”₯5🫑4🀣2😱1😒1
Probably not that big a deal tbh no one uses NPM
🀣73πŸ‘9😱5❀4😒1πŸŽ‰1
vx-underground
Probably not that big a deal tbh no one uses NPM
Also, don't see any facts to back up these claims. Could be some dork going bananas over nothing.

Guess we'll wait and see
❀27πŸ₯°7πŸ”₯5😒1
> do largest supply chain attack in history
> potentially infect millions of apps
> doesnt do the thing good
> makes $0 from compromise

I don't wanna support the villain here, but my guy, you gotta lock in. You could have infected hundreds of millions of apps and you FUMBLE IT
🀣150❀10😁6😒1
vx-underground
> do largest supply chain attack in history > potentially infect millions of apps > doesnt do the thing good > makes $0 from compromise I don't wanna support the villain here, but my guy, you gotta lock in. You could have infected hundreds of millions of…
Look... If you had... one shot... or one opportunity...
To seize everything you ever wanted... one moment...
Would you capture it? Or just let it slip?

...

*slips*
🀣123πŸ’―11❀6πŸ˜‡2🀝2😁1😒1
BREAKING

LARGEST SUPPLY CHAIN ATTACK IN HISTORY PULLS OFF MASSIVE CRYPTO HEIST

ATTACKS STEAL $20.05 OF ETH. ENTIRE WORLD CRUMBLING
🀣117πŸ”₯8πŸ₯°4😁4❀‍πŸ”₯2❀1πŸŽ‰1
Drama unfolding in Brazil right now where it was discovered a popular and trending Lesbian Dating App was vibe coded

Turns out all you need to do is a GET request and you can pull everything
🀣92😒11😎4❀2πŸ‘1πŸ€”1
vx-underground
Photo
Posting from mobile. Im not sure why my phone wrote "Lesbian Dating App" like it was an official title or acronym or something (LDA)....

Lolwtf
🀣53😁7❀4😒1πŸ€“1
vx-underground
Photo
I recommend following this thread (comments and quoted retweets) to follow the drama and shit storm.

STOP THE SLOP. NO MORE AI VIBE CODED APPS.

https://x.com/acgfbr/status/1965116645556600882
🀣34❀10πŸ€”5πŸ’―3πŸ‘1😒1
If people keep pushing AI vibe coded slop imagine how much money us cybersecurity nerds are gonna make

Chat, it's going to be a very prosperous couple of decades
πŸ‘91πŸ’―20❀9😁9❀‍πŸ”₯2πŸ”₯2😒1
> TeaApp
> Used Firebase
> Bucket not configured correctly

> Brazil dating app (Sapphos)
> Used Firebase
> Bucket not configured correctly

It's literally free money
❀84😁38πŸ”₯8πŸ˜‡5😒2
The drama in Brazil continues.

Sapphos, a lesbian-focused dating app, was compromised as a result of a poorly developed API with users speculating it was vibe coded.

Sapphos, after discovering the situation unfolding on social media, quickly put out a message regarding the compromise.

Sapphos begins by implying the compromise was a targeted campaign by men. However, while it was compromised by men, it does not appear (based on social media conversations and threads) to be compromised as a result of disdain toward women. Rather, the compromise was the result of nerds being nerds and messing with the application.

The message concludes with the statement that no documentation was exfiltrated. However, based on photo evidence on social media, this is incontrovertibly false. Photos and logs have been presented which proves this is false.

tl;dr Brazil mentioned?
🀣87❀12πŸŽ‰8😒1
vx-underground
The drama in Brazil continues. Sapphos, a lesbian-focused dating app, was compromised as a result of a poorly developed API with users speculating it was vibe coded. Sapphos, after discovering the situation unfolding on social media, quickly put out a message…
I say Brazil mentioned because following the post about the compromise and/or data leak, Brazil nerds seemed happy to see Brazil mentioned.

Brazilian people are cool and badass
❀62🀣28πŸ”₯6❀‍πŸ”₯3😒2😁1
Mildly interesting

As I'm working on collecting older malware samples I've made some observations.

1. The word "IOC" (Indicator of Compromise) has not been present in a report from 2001 - 2010.

2. Most malware samples were not shared. If they were shared they used MediaFire

3. Around 2008 people began referencing VirusTotal for malware detection rates and names. VirusTotal reports from that era are broken because they URLs have changed. VirusTotal's URLs were originally in spanish and were HTTP based

4. One of the first vendors to share malware MD5 (or SHA1, haven't seen a SHA256 yet) was FireEye (now Trellix) and Secureworks

5. Malware campaigns using social networks for target users was revolutionary concepts in 2009.

6. Conficker malware analysis reports illustrate how much malware has evolved. The malware techniques used by Conficker are amateur at best compared to modern malware techniques. Conficker was declared revolutionary (not exact words) because of its modularity. See attached image. A modern malware payload doing what Conficker did is ... meh ... everyone can do this. Interesting how much has changed.
πŸ‘40❀16πŸ’―14πŸ€”3πŸ”₯1😒1
The most interesting person in the world was messaging me.

They've suddenly deleted their e-mail and Xitter account.

Come back:(
😒49❀18😁7πŸ₯°2πŸŽ‰1🫑1
MALAYSIA, STOP. DO NOT VIBE CODE A BANK
🀣139πŸ”₯10❀5😒3🀩2