vx-underground
45.5K subscribers
3.9K photos
413 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Weird thing to say on Discord. Hopefully it was just a meme and bro wasn't really scheming to XMRig tons of people
😱42😁20🀣16πŸ’―4❀2😒1
Day in the life of working at vx-underground:

> Wake up
> Take a shit
> Get out of bed
> Scroll MISP looking at malware
> Download malware
> Skim some papers
> Skim DMs (cat pictures and stuff)
> Scroll MISP looking at malware
> Spam cat pictures randomly
> Go eepies
❀91πŸ₯°23🀣20🫑5πŸ‘3😒1
vx-underground
I received a message today from an ex-affiliate of Lockbit ransomware group who is currently on FBI's Most Wanted. He told me he thought it was disgusting someone would cryptodrain a cancer patient. dawg this guy ransomed elementary schools. even he thought…
There appears to be some confusion about this post and how groups such as Lockbit operate.

Lockbit offers a "service" of ransomware. He gives you a pretty panel, some tools for making ransomware (his), a chatroom to harass victims and bully them, etc.

In exchange for him providing this service he takes a cut of any money you receive from ransoming companies.

Lockbit ransomware group did ransom hospitals. However, it was not "Lockbit" the "service" provider. Rather, it was someone who used his service.

The people who use this service are called "affiliates".

At Lockbits peak they had over 100 affiliates. Some affiliates did ransom hospitals. This particular affiliate who messaged me, who is FBI Most Wanted, believed it was unethical to ransom healthcare because it could potentially endanger someone's life. Although, he was still a criminal and harassed, bullied, and extorted companies of all sizes including public schools. One time he ransomed a car wash. He didn't care.

Anyway

Lockbit themselves (the "service" provider) allowed affiliates to ransom hospitals because ... they didn't really care. Lockbit (the service provider) approved of schools, churches, non profits, hospitals, doctors, government agencies, etc. to all be victims of ransomware. He didn't really have exclude anything. Nothing was off limits.

Lockbit (the service provider) made an estimated $1,000,000,000 from their crimes as providing this service and facilitating ransomware all across the planet.

One administrator resides in Russia. The other (ex administrator) was located in Israel. However, he was arrested and deported to the United States some time ago when the FBI found him.
🀣66❀22πŸ₯°11πŸ‘2πŸ‘2πŸ€”1😒1🫑1
Yesterday someone was being very silly and defaced Nintendo's topics page. Nintendo has restored the deface.

No data was stolen.

Archive: https://archive.ph/n5Lgp
😁46πŸ₯°11❀7πŸ”₯3πŸ‘1😒1
🀣69❀33πŸ₯°6πŸ‘1πŸ€”1😒1
This media is not supported in your browser
VIEW IN TELEGRAM
me getting on the computer when someone needs pictures of cats
❀41😁18πŸ”₯11πŸ€”3πŸ₯°2❀‍πŸ”₯1😒1🀣1
vx-underground
me getting on the computer when someone needs pictures of cats
πŸ”₯60🀣16πŸ₯°13❀5😁3❀‍πŸ”₯1😒1
> 2 day ago
> collins aerospace hit by ransomware
> 5hrs ago
> "hardbit ransomware" did it
> 1hr ago
> nca arrests hacker for collin aerospace attack

wtf
πŸ₯°70🀣35❀8πŸ‘4😁2😒1🫑1
vx-underground
> 2 day ago > collins aerospace hit by ransomware > 5hrs ago > "hardbit ransomware" did it > 1hr ago > nca arrests hacker for collin aerospace attack wtf
tldr ransomware arrest speedrun attempt

p fast at being busted, doesnt top gta extortion guy tho. bro got caught in like, 12hrs. thats an all time record. hard to beat that
😁73πŸ‘13❀8πŸŽ‰3😒1
Wtf the guy they arrested for the ransomware attack against Collins aerospace thingy was in his 40s

He's gonna be charged as a terrorist.

What was he thinkin
😁66❀12🫑11😒7🀣6πŸ€”4😱4πŸ₯°2πŸ‘1πŸ’―1
vx-underground
Wtf the guy they arrested for the ransomware attack against Collins aerospace thingy was in his 40s He's gonna be charged as a terrorist. What was he thinkin
I immediately thought I'd be a com kid just being a menace to society. Dude is too old for this shit. He's gonna be released when he's 95
😁57🫑24❀7😒4πŸ’―4🀣4πŸ₯°2🀯1
Hello,

Someone in the com supposedly has a really cool and badass piece of malware I'm really interested in. I've been trying to find the nerd who has it for like, 2 days, and I've messaged every com person I know (like 5 people)

I really really want to see this Terraria malware payload.
❀62πŸ™16πŸ€”13🀣10😁3😱3❀‍πŸ”₯2🀝2😎2πŸ₯°1😒1
This media is not supported in your browser
VIEW IN TELEGRAM
❀78πŸ₯°18πŸ”₯10🀣2πŸ‘1😒1
Media outlets today announced the apprehension of a 17 year old individual residing in the United States believed to be tied to the infamous Scattered Spider.

Historically, Owen Flowers, Thalha Jubair, and Noah Urban were identified as key members.

who tf is this guy???
πŸ€”40🀣19❀4πŸ‘1😒1
vx-underground
Media outlets today announced the apprehension of a 17 year old individual residing in the United States believed to be tied to the infamous Scattered Spider. Historically, Owen Flowers, Thalha Jubair, and Noah Urban were identified as key members. who tf…
My best guess at this point is that the Federal Bureau of Investigation is now low-key sniping off any person who even orbited the main players

Tldr even associates getting cooked
🀣44🫑7😒4❀2πŸ’―2πŸ‘1πŸ‘1
πŸ”₯86🀣25❀16πŸ₯°3😁2😒1
There's so much shit with malware TTPs, malware development, reverse engineering, shit on financially motivated malware nerds, state sponsored malware nerds, malware nerds being arrested

I just can't keep up anymore bro I'm just focusing on cat pictures fuck it
❀‍πŸ”₯46🀣16πŸ₯°8❀6😒1
Sorry for spam.

I received a message from a person named "Riverbank". He was upset that I failed to supply a photo of a kitty cat. He stated what I delivered was a video and/or gif. I apologize for the confusion. As promised I will deliver one (1) cat picture.

Thank you for understanding.
πŸ₯°52❀14🀣8πŸ”₯3πŸ‘1😒1
πŸ₯°86❀22πŸ€“7❀‍πŸ”₯6🀣3πŸ”₯2😒1