vx-underground
45.4K subscribers
3.9K photos
413 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
vx-underground
Big drama today in the Tor community. Conrad Rockenhaus, a Tor operator based out of Michigan, United States, was arrested in 2020 after refusing to cooperate with the United States Federal Bureau of Investigation Rockenhaus, a disabled United States military…
NOTE: Nerds found more court documents. Mr. Rockenhaus did violate the CFAA in 2014.

tl;dr fbi requested decrypt, he says no, but it turns out he did do something wrong (maybe?). did fbi have card up their sleeve? or is this unrelated? is anime good?

https://news.ycombinator.com/item?id=45262053
❀30😱8πŸ€”3πŸ‘2😒1
🚨BREAKING 🚨

LINUX NERDS ARE MAD. THIS IS NOT A DRILL.

Linux nerds do NOT fuck around with performance.

Noted from The Lunduke Journal, "Ubuntu’s plan to replace the GNU Core Utils with Rust-based reimplementations is going exactly as poorly as predicted. Some Rust versions being 17 times slower than the battle tested GNU C / C++ version. And other Rust-based versions simply failing to work on large files."
🀣147😱20❀13🫑4πŸ€”2😒2πŸ€“2πŸ”₯1
vx-underground
Connor Fitzpatrick a/k/a Pompompurin, the original administrator of the infamous Breached forums, has been sentenced to 3 years in federal prison https://www.justice.gov/opa/pr/founder-one-worlds-largest-hacker-forums-resentenced-three-years-prison
Not even memeing, I've seen people sentenced to prison for longer periods of time for far less severe crimes.

Shout out Pompompurin's legal team. Bro has that A1 salute defense attorney, or something.
❀52🀣24πŸ₯°4😎3😒2
Chat, is this true?
πŸ’―96🀣33πŸ‘10😁3❀1πŸŽ‰1
🚨 BREAKING 🚨

Today United States Federal Bureau of Investigation Director, Kash Patel, stated in a congressional hearing that they find no evidence Jeffrey Epstein trafficked people.

However, Mr. Patel did confirm Old McDonald had a farm. He also confirmed he said E-I-E-I-O
😁84🀣52πŸ”₯8😒6❀3🫑3πŸ‘1
People keep asking where the rest of the promised kitty cat picture collection is. The answer is I've been bamboozled and forsaken.

A family-friend asked if I could introduce their teen to cybersecurity. I agreed, but in a limited capacity, because I thought it wasn't a good idea to let a complete noob deal with active malware.

I decided to introduce them to boredom. I placed the entire kitty cat picture on an external hard drive. I told them I'd pay them in cash when they finished sorting out the contents on it and successfully removed all non-kitty cat pictures.

They were excited. They said they'd have it all done in a day. They seemed eager to help me more with vx-underground and doing more malware stuff.

Anyway, it's been like, 2 weeks, or something, and bro hasn't done shit. I asked what's up with the cat picture collection and they said, "oh my bad bro, I've been busy. I'll get to it when I can".

Dawg, your Mom told me all you've been doing is playing Roblox with the homies 😭 Your ass is NOT busy

I'll get the hard drive back from their Mommy and I'll get back to work on the kitty cat picture archive. I'm gonna have to tell their Mom their teenager is a BUM and isn't cut out for this malware game.
🀣133😁9😱9❀5😒5πŸŽ‰1
vx-underground
People keep asking where the rest of the promised kitty cat picture collection is. The answer is I've been bamboozled and forsaken. A family-friend asked if I could introduce their teen to cybersecurity. I agreed, but in a limited capacity, because I thought…
The kids heart is in the right place. They're interested in computers and cybersecurity. But bro isn't locked in. Their mind is focused on Roblox and their crush in math class. Maybe they'll lock in later.
πŸ™73πŸ₯°13🀣6🀯5🀝3❀1😒1πŸ€“1
vx-underground
The kids heart is in the right place. They're interested in computers and cybersecurity. But bro isn't locked in. Their mind is focused on Roblox and their crush in math class. Maybe they'll lock in later.
Unrelated, but the fuckin' kid keeps saying, "six seven" and waving their hands in pseudo gang signs. I don't know what it means. I just stare at them like this:
😱71🀣43😒10πŸ’―4❀2πŸ‘2🀯2πŸ”₯1πŸŽ‰1πŸ€“1
Wtf I went to nappy noo noo city and woke up to everyone yappin about another NPM supply chain attack
❀49🀣24πŸ₯°13πŸ‘2πŸŽ‰1
vx-underground
Wtf I went to nappy noo noo city and woke up to everyone yappin about another NPM supply chain attack
NPM is for nerds bro you don't need to install a third party dependency to do division ok

Jk idk I'm just talking shit idk what's going on yet
πŸ₯°46πŸ’―15❀8πŸ€”2😒1🀣1
While everyone was discussing the NPM supply chain attack, what else happened?

- _CPResearch_ did some article on some nerd named PureCoder (???) who was doing some ClickFix malware campaign with fake job offers. They did some kind of campaign, compromised some place for a few days, or something. They found the builder and cryptor and some other stuff. New malware guy on the block doing malware and stuff

- Securelist did an article on RevengeHotel. They target hotels, and steal credit cards, etc. They're back again and using AI for phishing and malicious scripts. Claude and/or ChatGPT is helping Threat Actors I guess

- PointWild discovered a new Information Stealer named Raven. It's written in C++ and Delphi.

- proofpoint did some news on TA415 (China?) targeting the United States think tanks and universities. They're using Visual Studio dev tunnels, Google Calenders, and Google Sheets as a C2

- Acronis discussed a new malware campaign that uses ClickFix and steganography together to be extra cool and badass. This malware campaign is in multiple languages or whatever. It just delivers an infostealer

- sekoia_io did a thing on APT28 (Russia?) and some new campaign Russia hacking thingy named "Phantom Net Voxel". They uncovered it when they looked at some stuff from the Ukraine government. It does a bunch of stuff and lands on BeardShell and SlimyAgent.

- GDATA released another paper on ManualFinder. They found some more malware campaigns, and deception, and blah blah blah. It's called AppSuite and OneStart

That's all in just 1 day. Smh yall gotta LOCK IN (its like this everyday, everyday is an inescapable nightmare)
❀41πŸ₯°11😱10😒1
vx-underground
While everyone was discussing the NPM supply chain attack, what else happened? - _CPResearch_ did some article on some nerd named PureCoder (???) who was doing some ClickFix malware campaign with fake job offers. They did some kind of campaign, compromised…
Note: I skimmed the paper too skimmingly. PureCoder and pure stuff is known. I misread when skimming (I skim stuff).

I'm sorry to everyone who I let down. Please stop bonking me.
🀝45πŸ€“8❀5😒1🫑1
tl;dr

- By default it uses the Perplexity search engine
- Installing the browser requires a Perplexity account
- Not available on Linux (yet)
- The browser "uses AI to securely handle your data"(?)
- Generic features of all modern web browsers
- Probably Chromium based
😁72😱15❀6😒3πŸ€”1🀩1
vx-underground
tl;dr - By default it uses the Perplexity search engine - Installing the browser requires a Perplexity account - Not available on Linux (yet) - The browser "uses AI to securely handle your data"(?) - Generic features of all modern web browsers - Probably…
In my opinion, this will probably secure your password, ya. It is 1Password. However, I'm inclined to believe this is an attempt at harvesting more data for AI research.

They no longer need to scrape when they're inside your machine.
πŸ’―73😱9πŸ‘5❀1😒1
HOLY FUCK.

Department of Justice nabbed one of the Scattered Spider guys. They got him on 120 counts of computer intrusions.

He's facing over 95 years in prison. I've NEVER seen a cyber crime charge this high.
🀯79❀12🀣11😒6πŸ€”2πŸ‘1πŸ‘1
what the fuck thats me
🀣91πŸ₯°12πŸ‘10😁4❀2😒1