vx-underground
45.4K subscribers
3.9K photos
413 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
vx-underground
Weird stuff going on. This is a CRAZY anime arc. I beg you to read this post. This shit is crazy. Check this shit out June 16th, 2025: Phrack reports suspected offensive state-sponsored activity from China and/or North Korea targeting South Korea. They notify…
Oh, for the record, I actually don't know what's going on. I don't know if malware is making batteries explode burning down places, or paid arsons, or truly insane coincidence.

All I know is that this is a weird story and it makes me go "Hmmmmm"
πŸ€”41πŸ₯°9πŸ€“4❀1πŸ‘1😒1
WHOAOAOAOAOAOA!!!!!

LET PERPLEXITY SCRAPE EVERY DROP OF DATA OFF YOUR MACHINE AND DISCORD WILL GIVE YOU ORBS!!!!

WHAT ARE UOU WAITING FOR???
🀣161❀17😁9πŸŽ‰5😱2πŸ₯°1😒1
This media is not supported in your browser
VIEW IN TELEGRAM
🀣100😱9πŸ₯°5😒3🀯2πŸ’―2πŸ€“2πŸ‘1😁1
This media is not supported in your browser
VIEW IN TELEGRAM
πŸ₯°60😒16😍4❀3πŸ‘1
Some shit head piece of shit was shit faced talking shit. He thought he was tough shit and the shit for going apeshit on some dipshit. It's all bullshit for shit heads to get involved in shit like that. I told bro to get his shit together because when shit happens none of these shit for brains are going to give a shit when shit hits the fan

Believe it or not this does make sense to a native English speaker
🀣104❀13πŸ€”12πŸ’―8πŸ‘7πŸ”₯3πŸŽ‰3πŸ‘2πŸ₯°1😁1🫑1
A group of Threat Actors operating under the moniker "FulcrumSec" claim to have compromised an electronics manufacturer named Avnet

Fulcrum contacted me regarding the compromise.

Under normal circumstances I'd probably ignore the e-mail, or look into the group more, and wait and see what happens. However, they were nice enough to provide me with an autobiography, a breakdown of the data they possess, their motives for the compromise, information on their logo design (and why their logo was chosen), a complete file listing from the compromise, a breakdown of the files (what it is, what they are, what they contain), images of the files, an onion domain, a clearnet domain, large samples of the data ...

They pretty much did the full fuckin' write up and research for me. I was able to verify pretty much everything they wrote. It doesn't appear like they're lying.

I've never had a Threat Group notify me of a compromise and do every bit of research and write up for me. What the fuck is this shit? Here's a picture of the e-mail they sent me. I'm trimming it because it's a massive e-mail and they explain every little piece of data they possess
🀣101πŸ”₯25❀9πŸ€”5πŸ‘2πŸ’―2😒1😎1
vx-underground
A group of Threat Actors operating under the moniker "FulcrumSec" claim to have compromised an electronics manufacturer named Avnet Fulcrum contacted me regarding the compromise. Under normal circumstances I'd probably ignore the e-mail, or look into the…
It literally says in the e-mail pictured they used ChatGPT to summarize the data. It says they used the stolen OpenAI key from Avnet

People messaging me like, "yo dat looks like chatgpt"
😁73🀣50πŸ”₯5❀4πŸ‘3πŸ€“3😒1
When you have enough computers you don't need a heater. It's like, 45f outside (7c) and my office is 75f (23c).
πŸ”₯64❀7πŸ₯°7😁5πŸ‘2😒1
🀣166❀10πŸ€“6πŸ‘4πŸ”₯2😁1😒1πŸ’―1😘1
Chat, we are cooked

Discord is being extorted by the people who compromised their Zendesk instance

They've got 1.5TB of age verification related photos. 2,185,151 photos

tl;dr 2.1m Discord users drivers license and/or passport might be leaked. Unknown number of e-mails
🀣222🀯21πŸ”₯13❀‍πŸ”₯10❀9😱5πŸ‘3πŸ‘2😁2😎2πŸŽ‰1
BREAKING

The United States Federal Bureau of Investigation has released new photographs of a recent arrest of an international wanted Threat Actor
😒120🀣55❀14πŸ€“8🀩2πŸ₯°1πŸ‘1😱1🫑1
Yesterday I briefly spoke with the Threat Actor(s) responsible for compromising Discord's Zendesk.

They said they were able to compromise Discord Zendesk by compromising a "BPO Agent" (outsourced support).

They never specified how they compromised them.
πŸ₯°42πŸ€”8❀7πŸŽ‰2πŸ‘1
vx-underground
Yesterday I briefly spoke with the Threat Actor(s) responsible for compromising Discord's Zendesk. They said they were able to compromise Discord Zendesk by compromising a "BPO Agent" (outsourced support). They never specified how they compromised them.
Of course, as is tradition, it is also entirely possible they're lying and they compromised their helpdesk system in some other way. It's not uncommon for Threat Actors to lie to obfuscate how they achieved access.

Interesting times
πŸ€”52πŸ€“11❀9πŸ’―5πŸ‘1😒1
Dawg, I'm trying to fucking work and I've got notifications about the Salesforce compromise, the RedHat compromise, the Discord compromise, this fucking Asuraisjfjsjfiw botnet fucking DDoS shit going on

Threat Actors, will you CHILL THE FUCK OUT. God damn
🀣94❀12πŸ₯°7😒2πŸ”₯1
vx-underground
Dawg, I'm trying to fucking work and I've got notifications about the Salesforce compromise, the RedHat compromise, the Discord compromise, this fucking Asuraisjfjsjfiw botnet fucking DDoS shit going on Threat Actors, will you CHILL THE FUCK OUT. God damn
I can't sit down for 2 seconds without some crazy shit happening the past few days. One of y'all's mfers needs to hit the pause button or something wtf bro

I'm on mobile, but if I had an angry cat picture readily available I'd post it
🀣62❀11πŸ’―7😒3πŸ₯°1
Thank you, Riverbank, for sending me an angry cat picture. But it's too late. No one gets a cat picture
😒104😱7πŸ€”3❀2
Bro, I've got people messaging me saying they're worried they're in the Discord leaks and if their photo and/or drivers license is leaked they're going to kill themselves because it'll out them for being gay, or it'll potentially expose them to stalkers again

Wtf
🀣102😒41😱10❀5πŸ’―3πŸ‘2😁2πŸ˜‡2πŸŽ‰1πŸ€“1
This Discord Zendesk compromise has gotten more silly.

Previously, the Threat Actors responsible for the Discord Zendesk compromise claimed they had gotten access by compromising a BPO (Business Process Outsource) employee.

They were not lying.

It turns out that in August the Threat Actors who compromised Discord began sending emails to Discord outsourced employees offering them money in exchange for access to Discords internals.

The people they emailed was a very small team located in Southeast Asia. This particular office only has a handful of employees assigned to working Discord helpdesk (including age verification). This team is assigned to primarily handle back log work. This team had a great deal of access and were believed to be "trusted".

One of the emails this small team received offered $500 compensation to prove they're a Discord BPO employee. They offered an additional "several thousand dollar" lump sum payment in exchange for giving them access.

The Discord BPO employees were told to ignore the emails. Unfortunately, it appears one of these BPO employees did not ignore the emails and accepted the bribe.

$500 in this Southeastern Asian country is an astronomical amount of money. The "several thousand dollar" lump sum payment would be enough for this person to live comfortably for several years in their country.
πŸ₯°66🫑20❀16🀣5😒4😁1πŸŽ‰1πŸ€“1