vx-underground
45.4K subscribers
3.9K photos
413 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Security researcher "Bob da Hacker" has been doing more security research.

*This an expansion to a previous post because... it gets worse.

The following applications are all incorrectly configured and exposing user PII (Personal Identifiable Information) in various manners:
- Wimkin
- Reelster
- Cancel the Hate
- Date on the Right

Based on analysis from nerds, Wimkin and Reelster are hand-crafted. They are not vibe coded. "Cancel the Hate" and "Date on the Right" are vibe coded. Each application listed is believed to be made by the same group of individuals.

Very little effort is required to get user data. It is a simple POST request.

Over 500,000 peoples PII are being leaked across all 4 applications.

Data exposed includes:
- Email
- Date of Birth (if supplied)
- Phone number (if supplied)
- Longitude/Latitude (Reelster specific)
- Private messages (Wimkin, Reelster specific)
- User session tokens (Wimkin. Reelster specific)
- User preferences
45😁25🤣23😱4😢2
🤣169🔥188🥰6😁5🤯4🙏4👍1😢1🎉1
You don't have to write super sophisticated malware with 9000 different evasion techniques

Just name it important_file.pdf.exe and have it prompt for UAC. They'll probably allow it
90🤣41💯15🔥9🫡5🥰2😢2👍1
Lots of drama on the internet today with Bug Bounty Nerds and HackOne

Bug Bounty Nerds are saying HackerOne is ran by Zionists, or something, and saying HackerOne is Islamophobic, or something

I don't know the whole lore behind this and I don't know the main characters arguing back and forth. It feels like I've walked into the shit show in the middle of season two of the anime.

Will report back if I understand what's going on (I probably won't report back, but people keeping tagging me).
👍34😁269🤯3🥰1😢1
vx-underground
Photo
This image got censored on Xitter for violence, or something. Makes zero sense. There was footage of the Charlie Kirk assassination all over Xitter and literally nothing was censored. You'd be scrolling and accidentally find the murder video, yet they block a cartoon meme with ms-paint blood

Wtf are they doing over there
🤣111😁22🤔96💯4😢1
This media is not supported in your browser
VIEW IN TELEGRAM
cybersecurity
❤‍🔥84🥰2912🤣6😢3🤔2🤓2😍1💯1
The volume of updates I've pushed to the malware library far exceed Xitter limits. I also don't want to do Xitter articles for it. I'll instead push them to VX FEED Discord.

This Discord is straight business. There is no memeing, silly posts, or talking allowed.
42😱18🔥5👍3🤓3🤔1😢1
There is someone exposing IRGC (Islamic Revolutionary Guard Corps) stuff on GitHub.

I'm not a IRGC geopolitical nerd, so I can't assess the value of the content. However, if you know what the fuck is going on, maybe you'll find it interesting:

https://github.com/KittenBusters/CharmingKitten
🤣30🔥17🤔144👍3😱1😢1
Based on the information from the IRGC (Iranian government) CharmingKitten leaks, this woman is a target. The Iranian government wants to target her because ???

I tried using a translation thingy and it didn't work (I didn't try very hard)
🤔40😁15🥰62🤯2😢1
This media is not supported in your browser
VIEW IN TELEGRAM
> openai sora released
> misinformation nightmare
> ai slop nightmare
> *scroll*
> redhat breached
> sensitive stuff included like nsa stuff
> *scroll*
> iran government leaks
> targets and malware logs and stuff

another day of internet schizophrenia
102💯28🥰14🤣12🫡7😁4❤‍🔥2😇2👏1😢1
The Ukraine government released this photo today. It's part of a series of photos on some criminal being arrested, I don't know, I don't care, some nerd shit probably. But dawg, look at this kitty cat
🥰14734😁17😎12🤣9😢6🤓2👍1🤔1🤝1
Mystical Malware Prediction time

Will there be another big FBI takedown before the end of 2025?
Anonymous Poll
68%
Yes
32%
No
💯22🤯54😁2🔥1😢1😘1
vx-underground
Mystical Malware Prediction time

Will there be another big FBI takedown before the end of 2025?
My prediction: No.

Governments shut down right now. It's closing in on the holiday season. FBI will probably begin re-arresting nerds in 2026
🤣82👍86😱6😢1
Dear Threat Actors,

I need Robux. Give me Robux. I know you're all a bunch of fucking degenerates spending your drainer money on that fucking game. Don't be stingy.
57🤣37🥰10🙏3😢1💯1
vx-underground
Dear Threat Actors, I need Robux. Give me Robux. I know you're all a bunch of fucking degenerates spending your drainer money on that fucking game. Don't be stingy.
Found some bullshit Roblox game. There is Robux spent leaderboard. Someone spent over $100,000 in this game.

I KNOW IT WAS ONE OF YALL. There is no human being on this planet burning $100,000 in a fucking kids game
🤣11315🥰8🔥4😎2😁1🤯1😢1