vx-underground
45.4K subscribers
3.9K photos
413 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Based on the information from the IRGC (Iranian government) CharmingKitten leaks, this woman is a target. The Iranian government wants to target her because ???

I tried using a translation thingy and it didn't work (I didn't try very hard)
🤔40😁15🥰62🤯2😢1
This media is not supported in your browser
VIEW IN TELEGRAM
> openai sora released
> misinformation nightmare
> ai slop nightmare
> *scroll*
> redhat breached
> sensitive stuff included like nsa stuff
> *scroll*
> iran government leaks
> targets and malware logs and stuff

another day of internet schizophrenia
102💯28🥰14🤣12🫡7😁4❤‍🔥2😇2👏1😢1
The Ukraine government released this photo today. It's part of a series of photos on some criminal being arrested, I don't know, I don't care, some nerd shit probably. But dawg, look at this kitty cat
🥰14734😁17😎12🤣9😢6🤓2👍1🤔1🤝1
Mystical Malware Prediction time

Will there be another big FBI takedown before the end of 2025?
Anonymous Poll
68%
Yes
32%
No
💯22🤯54😁2🔥1😢1😘1
vx-underground
Mystical Malware Prediction time

Will there be another big FBI takedown before the end of 2025?
My prediction: No.

Governments shut down right now. It's closing in on the holiday season. FBI will probably begin re-arresting nerds in 2026
🤣82👍86😱6😢1
Dear Threat Actors,

I need Robux. Give me Robux. I know you're all a bunch of fucking degenerates spending your drainer money on that fucking game. Don't be stingy.
57🤣37🥰10🙏3😢1💯1
vx-underground
Dear Threat Actors, I need Robux. Give me Robux. I know you're all a bunch of fucking degenerates spending your drainer money on that fucking game. Don't be stingy.
Found some bullshit Roblox game. There is Robux spent leaderboard. Someone spent over $100,000 in this game.

I KNOW IT WAS ONE OF YALL. There is no human being on this planet burning $100,000 in a fucking kids game
🤣11315🥰8🔥4😎2😁1🤯1😢1
vx-underground
Found some bullshit Roblox game. There is Robux spent leaderboard. Someone spent over $100,000 in this game. I KNOW IT WAS ONE OF YALL. There is no human being on this planet burning $100,000 in a fucking kids game
UPDATE: I've learned there are video game nerds unironically spending thousands upon thousands of dollars in games. I thought it was stolen money, but it turns out nerds go fuckin' spazzo for in-game items. Some game items are as high as $11,000
🤣107😱169💯7😢5🫡2🤓1
My goal was to aggregate 10+ malware papers a day to the malware analysis collection (paper + samples, if applicable). However, at my current rate, it's going to take me about 3 years and 2 months.
😢6613🫡7😘7😱5🤔1🎉1🤣1
A lot of people don't know this, but since the United States government is shutdown due to funding, or whatever excuse they make up, ALL crimes are now LEGAL

You can't prosecute someone for something that isn't open!

I just drove 120mph through a school zone, with no windshield, playing "American Badass" by Kid Rock.

A police officer pulled me over (I stopped to be polite). He asked what I was doing, I told him I'm hurrying home to cook 7 bricks to methamphetamine before the government re-opens.

The police officer nodded. He understood this is a good business opportunity for him too.

He escorted me home and now we're slinging bricks of methamphetamine on Facebook to senior citizens.
🤣192🥰2720🤝8👏2🤩2🙏2💯2😢1
Discord has begun sending e-mails notifications about a cybersecurity incident which occurred September 20th, 2025.

It appears people who submitted support tickets are the ones primarily impacted.

Literally peoples entire identity stolen from this shit
😱56😁208🔥8🤣5🤔1🎉1🙏1
Dawg, this Discord Zendesk compromise is crazy. The Threat Actor has so much fucking leverage

Depending on what's in the data they could extort celebrities, crypto influencers, politicians, scammers and/or other Threat Actors, government officials

The possibilities are endless
🔥53😎23🤣13🫡43😁2🎉1
Oops, was memeing and accidentally did misinformation on the internet.

Discord Zendesk (3rd party support software) was compromised, if someone was flagged as being potentially underage a ticket would be created and the user would have to appeal to Discord support proving they're sufficiently aged to be on Discord. This would mean they have would have to submit government identification such as drivers license, passport, etc.

When I made the post (in the attached image) it was part of a series of posts discussing the Discord Zendesk compromise. People viewed the post without seeing the chain of other posts and mistook the context of it. It caused people to believe the actual Discord age verification feature was compromised but IT WAS NOT.

tl;dr ppl only saw 1 post out of chain of posts, caused confusion
🤓51🎉138🥰5👍1😢1🤩1😇1
This media is not supported in your browser
VIEW IN TELEGRAM
The vx-underground admin Discord account received a Discord 3rd party breach notification.

I thought this was unusual because this account has nothing of value on it. It uses a generic vx-underground e-mail, it doesn't have access to anything, it doesn't have a credit card or any sort of government identification on file.

Then I discovered someone (or someones?) submitted 255,620 complaints on the account trying to get it banned.

This is strange because this account, as stated previously, literally have NOTHING of value on it. NOTHING. It is just a way for people to contact us.

Look at this fuckin' e-mail bro, it was almost 1MB in size.
🤣139🥰125😁4😱1🎉1
The Discord Zendesk was not compromised by SLSH. I've received incontrovertible evidence displaying it was not SLSH.

SLSH compromised Salesforce. They have overlapping TTPs with the Discord Zendesk compromise. But it is not them.

The group who compromised Discord Zendesk currently does not have an attributed Threat Group name.

I'm absolutely flabbergasted right now.
🤯60🤣284😁4👍3😱2😢1
What a wonderful couple of days

First, on Thursday, an unknown person begins sharing photos of Discord Okta stuff. Images begin circulating. I first saw the images around 3pm EST. Some people speculated it was SLSH. SLSH took credit for something Discord related, I don't know.

Friday Discord did a press release disclosing a 3rd party compromise from (presumably) Zendesk. They began sending emails out.

Friday night people began attributing the Zendesk compromise to SLSH. Various posts were made on social media about it. The prevailing theory was overlapping TTPs from the SLSH attributed Salesforce campaign.

Saturday evening an unknown group officially took credit for the Discord Zendesk compromise disproving the attribution to SLSH.

Saturday night, SLSH retorted that they had never explicitly took credit for the Discord Zendesk compromise, hence they are not distributing misinformation, rather Cyber Threat Intelligence nerds on social media falsely attributed it and SLSH never explicitly confirmed or denied it. They took offense to me writing this weaponize misinformation.

Who really compromised Zendesk? Why didn't SLSH deny the allegations up front? Will One Punch Man season 3 have as good animation as season 1? Why does Friendlies have such good mozzarella sticks? Will I wait for the internet nerd drama to conclude before I make a post or just let chaos flow in perpetuity?

Find out next time on Dragon Ball Z
🤣71🔥87😁6🤔1😢1🤓1