vx-underground
45.4K subscribers
3.9K photos
413 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
😱44❀14🀣14πŸ₯°6πŸ”₯4😁1😒1
My internet connectivity has been absolute dog ass for years. I've been using this old ass fuck off modem and router combo. It was like, 10 years old.

I went to the local poopy pants store (computer store) and purchased this stupid expensive modem router combo thingy that looks like its from the year 3035

Dawg, I'm getting 2Gbps down 😭

Before I was getting 25 Mbps down (if I was lucky). I never even questioned why my connection was so slow despite paying so much money. I was too focused on cat pictures and malware to think good

tl;dr im dumb as hell
😁82🀯22πŸ€”8πŸ”₯5❀4πŸŽ‰1
Updates:

- Malware Analysis section expanded for 2025
- Papers section expanded
- New categories for papers added
- 100,000+- malware samples uploaded

New papers:
- 2025-09-18 - More Fun With WMI
- 2025-07-16 - Under the Hood of AFD.sys Part 1
- 2021-01-25 - Advanced obfuscation with LLVM and template metaprogramming
❀34πŸ”₯9πŸ₯°5😱1😒1πŸ™1
As is tradition, 4chan is doing some trolling.

They've launched "Operation Clogged Toilet".

They're intentionally reserving flights (prior to payment confirmation) from places such as India to the United States to prevent potential H1B holders to return to the United States
🀣144πŸ”₯21😒14❀8πŸ€”4😁2πŸ₯°1🀩1
This media is not supported in your browser
VIEW IN TELEGRAM
I lied. I didn't add 100,000 malwares yesterday. I added 325,000 malwares yesterday.
πŸ”₯85❀‍πŸ”₯18❀9πŸ₯°6😱5πŸ€“4😁3😘2😒1
wtf why do cats need context
❀96🀣46πŸ’―8πŸ”₯4πŸ₯°4πŸ‘1πŸ€”1😒1
Hello,

2,000 kitty cat pictures have been added to the kitty cat picture collection. Please look at them. It is very important.

./Archive/Cat Picture Collection
https://vx-underground.org/
πŸ₯°80❀25πŸ‘7πŸ”₯2😒1
This media is not supported in your browser
VIEW IN TELEGRAM
Yesterday a video game streamer named RastalandTV inadvertently livestreamed themselves being a victim of a cryptodraining campaign.

This particular spearphishing campaign is extraordinarily heinous because RastaLand is suffering from Stage-4 Sarcoma and is actively seeking donations for their cancer treatment. They lost $30,000 of the money which was designated for their cancer treatment. In the steam clip their friend tries to console them while they cry out, "I am broken now."

They were contacted by an unknown person who requested they play their video game demo (downloadable from Steam). In exchange for RastaLand playing their video game demo on stream, they would financially compensate them.

Unfortunately, the Steam game was actually a cryptodrainer masquerading as a legitimate video game.
😒164😱19❀11😁4🀣4πŸŽ‰2🫑1
Previously we made a post about a cancer patient being a victim of a malicious Steam game. It is a cryptodrainer masquerading as a free-to-play video game.

Based on reports and conversations occurring online, this is the malicious video game:

https://store.steampowered.com/app/3872350/BlockBlasters/
❀22😁9πŸ₯°4😒1
vx-underground
Previously we made a post about a cancer patient being a victim of a malicious Steam game. It is a cryptodrainer masquerading as a free-to-play video game. Based on reports and conversations occurring online, this is the malicious video game: https://st…
However, it is important that I note that I have not personally reviewed the game yet to determine if this is actually malware. This is what the victims allege or believe to be the culprit.
🫑35❀9😁6πŸ€”2😒1
vx-underground
I guess we lookin' at this mfer fr
Chat, I'm not video game developer, but this file looks strange. Why does this video game contain a .bat file that looks for your browser credentials and crypto wallets?
🀣109😱21πŸ€”7❀4πŸ€“4😒2
vx-underground
Chat, I'm not video game developer, but this file looks strange. Why does this video game contain a .bat file that looks for your browser credentials and crypto wallets?
Dawg, one of their boys is on VirusTotal flagging ransomware files as safe (comments or safe upvotes)

https://www.virustotal.com/gui/user/zombiebunny/comments
🀣97😱10❀7😎2😒1🀩1🀝1
Dawg, why did these cryptodrainer nerds leave their Telegram credentials exposed in plain text in their drainer?
🀣119😁17❀9πŸ‘7πŸ”₯4πŸ₯°3😒2😱1
vx-underground
Dawg, why did these cryptodrainer nerds leave their Telegram credentials exposed in plain text in their drainer?
Who are these people and why do they target cancer patients?
😒100πŸ”₯27🀣18❀9πŸ€“9πŸŽ‰1
vx-underground
Who are these people and why do they target cancer patients?
Update: entire channel has been deleted. Accounts also deleted.

Where did they go? :(
🀣148🫑22❀7😁5πŸ€”4😒4πŸ₯°1😎1
vx-underground
Update: entire channel has been deleted. Accounts also deleted. Where did they go? :(
Clicked the wrong button, accidentally pulled their infrastructure and victim logs, all 907 victims
πŸ₯°143🀣45πŸ‘33😱9❀5πŸ”₯4❀‍πŸ”₯3😁2😒2πŸ‘1
> find sketchy steam game
> download it
> find shitty .bat
> open it
> find hardcoded telegram creds
> get everything
> pull infra and all logs

dawg, you have to write better malware. took less than 30 minutes bro. you gotta lock in
🀣180❀27πŸ”₯15😁9πŸ₯°4😱3😒1