vx-underground
45.4K subscribers
3.9K photos
413 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
> nerds say compromised nuclear power plant
> everyone yappin about some cryptocurrency

wtf is this shit? is this a crypto shill thingy? or a ICS/SCADA compromise? both?

???
πŸ€”34😁16🀣12❀2❀‍πŸ”₯1😒1
Pro malware nerd tip: you can tell when the malware IOCs are shared from ESET because, for reasons literally nobody understands, all of their IOCs are uppercase.

What does this mean? Nothing. It doesn't matter. But they're the only vendor that does it.
πŸ€”29😁15🀣10❀7πŸ‘1😒1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ”₯56🀣22πŸ₯°9❀5😒2😱1
Big drama today in the Tor community.

Conrad Rockenhaus, a Tor operator based out of Michigan, United States, was arrested in 2020 after refusing to cooperate with the United States Federal Bureau of Investigation

Rockenhaus, a disabled United States military veteran, ran the fastest Tor node in the United States. He was approached sometime in late 2019 when the FBI requested he allow them arbitrary access to his exit node and allow them to decrypt traffic. He denied their request.

Subsequently, in February, 2020 his home was raided. He was arrested for violating the CFAA (Computer Fraud and Abuse Act). It was alleged that he was a disgruntled ex-employee causing problems at his former place of employment.

Interestingly, to "help resolve the matter", law enforcement requested he decrypt his Tor exit node to prove his innocence (???). After he refused, he was held in a pre-trial detention cell for over 3 years. He was denied bail after law enforcement stated Mr. Rockenhaus used Linux to "access the dark web" and he was "not complying" and not allowing them access to this Tor exit node.

After Mr. Rockenhaus' wife filed an official complaint, and Mr. Rockenhaus was miraculously released, he was raided by the United States Marshal Fugitive Task Force TWO TIMES(???).

They took him out his home, threw him to the ground, beat him, smashed his windows, and threatened to murder his animals.

They are still requesting Mr. Rockenhaus allow them to access his Tor exit node. Mr. Rockenhaus still has not granted them that privilege.

All of this has been captured on home security camera footage. Additionally, his wife has released all court documents.

https://www.youtube.com/@AdrienneRockenhaus
😱85🫑30❀15🀯6😒3🀣2πŸŽ‰1
vx-underground
Big drama today in the Tor community. Conrad Rockenhaus, a Tor operator based out of Michigan, United States, was arrested in 2020 after refusing to cooperate with the United States Federal Bureau of Investigation Rockenhaus, a disabled United States military…
Chat, do you think the United States government would bully someone for not getting their way? Do you think the United States Federal Bureau of Investigation is capable of making someones life hell for not allowing them to invade the privacy of others?
πŸ’―112❀14πŸ‘5πŸ˜‡5😒4🀝3πŸŽ‰1
vx-underground
Big drama today in the Tor community. Conrad Rockenhaus, a Tor operator based out of Michigan, United States, was arrested in 2020 after refusing to cooperate with the United States Federal Bureau of Investigation Rockenhaus, a disabled United States military…
NOTE: Nerds found more court documents. Mr. Rockenhaus did violate the CFAA in 2014.

tl;dr fbi requested decrypt, he says no, but it turns out he did do something wrong (maybe?). did fbi have card up their sleeve? or is this unrelated? is anime good?

https://news.ycombinator.com/item?id=45262053
❀30😱8πŸ€”3πŸ‘2😒1
🚨BREAKING 🚨

LINUX NERDS ARE MAD. THIS IS NOT A DRILL.

Linux nerds do NOT fuck around with performance.

Noted from The Lunduke Journal, "Ubuntu’s plan to replace the GNU Core Utils with Rust-based reimplementations is going exactly as poorly as predicted. Some Rust versions being 17 times slower than the battle tested GNU C / C++ version. And other Rust-based versions simply failing to work on large files."
🀣147😱20❀13🫑4πŸ€”2😒2πŸ€“2πŸ”₯1
vx-underground
Connor Fitzpatrick a/k/a Pompompurin, the original administrator of the infamous Breached forums, has been sentenced to 3 years in federal prison https://www.justice.gov/opa/pr/founder-one-worlds-largest-hacker-forums-resentenced-three-years-prison
Not even memeing, I've seen people sentenced to prison for longer periods of time for far less severe crimes.

Shout out Pompompurin's legal team. Bro has that A1 salute defense attorney, or something.
❀52🀣24πŸ₯°4😎3😒2
Chat, is this true?
πŸ’―96🀣33πŸ‘10😁3❀1πŸŽ‰1
🚨 BREAKING 🚨

Today United States Federal Bureau of Investigation Director, Kash Patel, stated in a congressional hearing that they find no evidence Jeffrey Epstein trafficked people.

However, Mr. Patel did confirm Old McDonald had a farm. He also confirmed he said E-I-E-I-O
😁84🀣52πŸ”₯8😒6❀3🫑3πŸ‘1
People keep asking where the rest of the promised kitty cat picture collection is. The answer is I've been bamboozled and forsaken.

A family-friend asked if I could introduce their teen to cybersecurity. I agreed, but in a limited capacity, because I thought it wasn't a good idea to let a complete noob deal with active malware.

I decided to introduce them to boredom. I placed the entire kitty cat picture on an external hard drive. I told them I'd pay them in cash when they finished sorting out the contents on it and successfully removed all non-kitty cat pictures.

They were excited. They said they'd have it all done in a day. They seemed eager to help me more with vx-underground and doing more malware stuff.

Anyway, it's been like, 2 weeks, or something, and bro hasn't done shit. I asked what's up with the cat picture collection and they said, "oh my bad bro, I've been busy. I'll get to it when I can".

Dawg, your Mom told me all you've been doing is playing Roblox with the homies 😭 Your ass is NOT busy

I'll get the hard drive back from their Mommy and I'll get back to work on the kitty cat picture archive. I'm gonna have to tell their Mom their teenager is a BUM and isn't cut out for this malware game.
🀣133😁9😱9❀5😒5πŸŽ‰1
vx-underground
People keep asking where the rest of the promised kitty cat picture collection is. The answer is I've been bamboozled and forsaken. A family-friend asked if I could introduce their teen to cybersecurity. I agreed, but in a limited capacity, because I thought…
The kids heart is in the right place. They're interested in computers and cybersecurity. But bro isn't locked in. Their mind is focused on Roblox and their crush in math class. Maybe they'll lock in later.
πŸ™73πŸ₯°13🀣6🀯5🀝3❀1😒1πŸ€“1
vx-underground
The kids heart is in the right place. They're interested in computers and cybersecurity. But bro isn't locked in. Their mind is focused on Roblox and their crush in math class. Maybe they'll lock in later.
Unrelated, but the fuckin' kid keeps saying, "six seven" and waving their hands in pseudo gang signs. I don't know what it means. I just stare at them like this:
😱71🀣43😒10πŸ’―4❀2πŸ‘2🀯2πŸ”₯1πŸŽ‰1πŸ€“1
Wtf I went to nappy noo noo city and woke up to everyone yappin about another NPM supply chain attack
❀49🀣24πŸ₯°13πŸ‘2πŸŽ‰1
vx-underground
Wtf I went to nappy noo noo city and woke up to everyone yappin about another NPM supply chain attack
NPM is for nerds bro you don't need to install a third party dependency to do division ok

Jk idk I'm just talking shit idk what's going on yet
πŸ₯°46πŸ’―15❀8πŸ€”2😒1🀣1
While everyone was discussing the NPM supply chain attack, what else happened?

- _CPResearch_ did some article on some nerd named PureCoder (???) who was doing some ClickFix malware campaign with fake job offers. They did some kind of campaign, compromised some place for a few days, or something. They found the builder and cryptor and some other stuff. New malware guy on the block doing malware and stuff

- Securelist did an article on RevengeHotel. They target hotels, and steal credit cards, etc. They're back again and using AI for phishing and malicious scripts. Claude and/or ChatGPT is helping Threat Actors I guess

- PointWild discovered a new Information Stealer named Raven. It's written in C++ and Delphi.

- proofpoint did some news on TA415 (China?) targeting the United States think tanks and universities. They're using Visual Studio dev tunnels, Google Calenders, and Google Sheets as a C2

- Acronis discussed a new malware campaign that uses ClickFix and steganography together to be extra cool and badass. This malware campaign is in multiple languages or whatever. It just delivers an infostealer

- sekoia_io did a thing on APT28 (Russia?) and some new campaign Russia hacking thingy named "Phantom Net Voxel". They uncovered it when they looked at some stuff from the Ukraine government. It does a bunch of stuff and lands on BeardShell and SlimyAgent.

- GDATA released another paper on ManualFinder. They found some more malware campaigns, and deception, and blah blah blah. It's called AppSuite and OneStart

That's all in just 1 day. Smh yall gotta LOCK IN (its like this everyday, everyday is an inescapable nightmare)
❀41πŸ₯°11😱10😒1
vx-underground
While everyone was discussing the NPM supply chain attack, what else happened? - _CPResearch_ did some article on some nerd named PureCoder (???) who was doing some ClickFix malware campaign with fake job offers. They did some kind of campaign, compromised…
Note: I skimmed the paper too skimmingly. PureCoder and pure stuff is known. I misread when skimming (I skim stuff).

I'm sorry to everyone who I let down. Please stop bonking me.
🀝45πŸ€“8❀5😒1🫑1