vx-underground
45.4K subscribers
3.9K photos
412 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
I've seen a few people talk about crazy stories in cybersecurity. I'll share mine. I remember it so vividly it's like it happened yesterday.

This is a 100% real and true story.

I was hired on at a large AI company as the Master Chief Artificial Intelligence Engineer Scientist. However, unbeknownst to my colleagues, I was also a super cool and badass hacker (as you know).

One day the phone is ringing off the hook. I answer it. IT tells me there's been a cybersecurity attack in sector 79C.

Oh. My. God.

Sector 79C is where all top secret level code black data is stored. That's where Barack Obama's birth certificate is stored, the nuclear launch codes, and the corpse of Jimmy Hoffa. I was petrified.

I immediately ran full speed over to sector 79C. Although that sector is far away, I'm extremely fast and agile. I'm like a cool and badass ninja, or something. I used to coach Usain Bolt, no big deal.

Anyway, I kicked in the door. Sirens and alarms are blaring. The people in the room are screaming, running in circles, ripping their clothes off (they're on fire for some reason).

I told everyone to calm down. I'm arrived. I have come. I'm hot and ready.

I push the fat stupid loser Richard off his computer (he likes watching anime) and get to work. I see over 200 of our IP addresses have been hacked. I immediately write a JSON 0day botnet to fight back. Everyone is amazed at my skill.

BOOM! Kash Patel kicks in the door. I said, "Kash, what the hell is going on, Brotha?". He replied, "I'll see you in Hacker Valhalla.". Then he salutes me, throws me the American flag, and runs out the room. Even he was scared.

Back to business.

I check on my JSON botnet. It's winning. IP addresses have been whitelisted by Cloudflare and Google is pinging again. Close call.

I look at the IP addresses trying to hack us back. I was flabbergasted. It was Vladimir Putin himself. It was his home IP address. He made an amateur mistake and forget to use NordVPN before starting the cybersecurity IP address hack attack.

Within minutes the attack stopped and every started jumping for joy.

The fires that magically appeared had disappeared. People stopped running in the circles. Several smokin hot babes were so impressed they threw their bras at me. I was the man.

Afterward I went to the parking lot and hopped in my 2013 Lamborghini Veneno. Woman began chasing after me. I put on my cool hacker sunglasses, waved at them and said "toodles". I took off at 120MPH on my way to Bestbuy (I needed to update my antivirus).

Once I got home to my 47 bedroom and 14 bath mega mansion I decided to relax by taking a swim in my mote. I raced the alligators. I won again.

That's my hacker story (real and true)
😎189❀23🀣23🫑9πŸ€“8πŸ”₯5πŸ‘4πŸ’―3πŸ€”2πŸ₯°1😒1
vx-underground
I've seen a few people talk about crazy stories in cybersecurity. I'll share mine. I remember it so vividly it's like it happened yesterday. This is a 100% real and true story. I was hired on at a large AI company as the Master Chief Artificial Intelligence…
Oh yeah, I forgot. That company I saved? Amazon.

Jeff Bezos thanked me personally and handed me a crisp $100,000,000 bill as a thank you.
🀣123πŸ‘15❀12πŸ”₯9πŸ’―5πŸ€“4😎3😒1
Rest in Peace to yunginnanet a/k/a Kayos.

I'm at a total loss of words. I have no idea what to say. When vx-underground first started him, and his friends with ThugCrowd, were the first to offer us hosting when no one else would. He helped us before anyone gave a shit about the project. Kayos was always bleeding edge when it came to finding cool and new stuff.

In 2020, or 2021, him and I had a disagreement (which we settled privately). But that's all water under the bridge. That was years ago. He went on to form TCP DIRECT.

Occasionally throughout the years I tried contacting him on Signal. I saw him updating his profile picture, but he never replied. His friends, who I was friends with, said he was very busy, probably forgetful, and was simply living his best life. I tried not to take it personal. I was always told he's doing good, living the dream.

I can't believe he's gone, man. Kayos was genuinely a really fuckin' nice guy. My deepest, most heartfelt, sincere condolences to his friends and family. His passing will leave an infinite emptiness in the hearts to many people who surrounded him and cherished him.

I'm so incredibly sorry to his girlfriend, lifelessAI. Kayos was a really special person with a personality larger than life. He radiated charisma and pride. He was a super unique person and he always had something interesting to share or add to a conversation. He was always locked in, a hardcore Linux nerd, and always doing crazy projects too just for the love of the game.

These photos were shared via ytcracker. These are great photos which encapsulate his energy and charisma. Kayos was other worldly.
🫑162❀38🀣6πŸ”₯5😁4πŸŽ‰2😱1🀩1
Wow I feel like a fucking asshole.

Steve Bridges, the comedian, died. Not Mike Bridges. I'm so fucking deep fried today from being sick and everything else I fucked up his name despite looking directly at his wife's Instagram post.

Sigh. I'm sorry, Steve. I'm dumber than hell.
❀92🀣30😁16🫑15πŸ‘3❀‍πŸ”₯2πŸ‘1πŸ”₯1🀝1
❀62πŸ₯°24🀣9😍3πŸ”₯1😒1
Yesterday Xubuntu was compromised and the sites download button was delivering malware. I saw a bunch of people yappin about it so I decided to reverse engineer it.

I am profoundly disappointed in the results. The people who compromised Xubuntu and made it deliver malware could have done some serious damage and done some cool malware stuff

Instead it delivered a C#.NET binary that helps people download Xubuntu (???) but when they click the download Xubuntu thingy it also extracts a malicious file outside the C# program.

The malicious file just swaps crypto addresses from the clipboard so they can hijack transactions, or something.

Smh

My full weird up is here if you have X and want to read it

https://x.com/vxunderground/status/1979885711579865307
🀣76πŸ₯°18❀7πŸ€”6πŸ”₯2😱1😒1
ok
🀣104πŸ₯°57😁8πŸ”₯7πŸ’―4❀3πŸ€“3🫑2😱1😒1
AWS is having problems today.

Everyone go back to bed.

Internet infrastructure will come back later today (probably).

Enjoy this cat picture.
❀131πŸ₯°30πŸ‘5😒1😍1πŸ’―1
This media is not supported in your browser
VIEW IN TELEGRAM
October 17th, 2025 EUROPOL performed Operation SIMCARTEL

They arrested 7 people. EUROPOL seized:
- 1,200 sim boxes
- 40,000 active sim cards
- 5 servers
- gogetsms
- apisim
- 4 luxury cars
- $502,000 in bank accounts
- $310,000 in cryptocurrency

They also released a badass video
πŸ₯°74🀣20❀19🫑6πŸ€”2😒2
vx-underground
October 17th, 2025 EUROPOL performed Operation SIMCARTEL They arrested 7 people. EUROPOL seized: - 1,200 sim boxes - 40,000 active sim cards - 5 servers - gogetsms - apisim - 4 luxury cars - $502,000 in bank accounts - $310,000 in cryptocurrency They also…
The suspects apprehended were allegedly responsible for over 1,700 fraud cases in Austria and over 1,500 in Latvia which amounted in damages exceeding €4,900,000

They services provided allowed people to perform phishing and social engineering campaigns.

Cool infrastructure+
πŸ₯°61😁9❀4πŸ€“4πŸ€”2πŸ‘1
Yesterday I spazzed out for a bit about malware terminology. Now that I'm calm (I've had my morning coffee, a delicious sandwich, and my yummy cigarettes) let's have a conversation about malware nomenclature.

Educational material in regards to malware, specifically in schools, is painfully outdated and is in desperate need to being updated.

It's not uncommon for schools to list the generic, broad, vague, and ambiguous terms for malware being (something along the lines of): Adware, Spyware, Ransomware (NEW!), Backdoor, Trojan, Rootkit, and Worm. Sometimes they'll sprinkle in something like "Zip Bomb" or "0day".

All of these terms heavily overlap with each other. It is entirely possible for something to be a "backdoor" while also simultaneously being a "trojan" "rootkit".

These terms are fossils from the 1990's, early 2000's, and don't accurately reflect how modern malware works.

Proposed update:
- Stager
- Loader
- Module
- Ransomware
- Stealer
- Drainer
- Wiper
- RAT
- ???

Each should also note the motive of the malware (state-sponsored, financially motivated, "troll", or hacktivist).
❀97πŸ‘8πŸ₯°5πŸ’―3😒2🫑2
imagine being some stinky nerd and europol rides up and hits your ass with a flash bang at 9 IN THE MORNING and on a FRIDAY

smh rude af
πŸ₯°91🀣35😒29😁10πŸ”₯8❀6
YouTuber, and stinky malware degenerate, John "BigMoney" Hammond a/k/a _JohnHammond created a CTF and references vx-underground whereas he asserts the password could potentially be infected.

smh makes me PHYSICALLY sick
🀣122❀14πŸ₯°14😁6❀‍πŸ”₯1😒1
A large VPN provider reached out to me.

They were wanting to do some stuff together to reach the cybersecurity audience, or something.

The primary reason I don't do ads, while I very much enjoy having money, is because I can't in good faith recommend a product to my audience which I cannot in totality stand behind.

vx-underground's success is partially due to transparency, honesty, admitting mistakes, and willingness to accept fault and/or responsibility.

I believe there is a shift in the VPN-sphere whereas some providers are trying to capture a more cybersecurity attentive audience.

That's cool. Do your thing homie. I understand the VPN business is rough and your company is always on the grind to make money. No hate.

However, I can't deceive my audience because they're the only reason I have success

Thank you for the love and support despite my many (MANY) faults, mistakes, typos, repetitive corrections and updates, unnecessarily crass tone when writing, failed and/or abandoned vx-underground experiments, etc.

I have no idea what the fuck I'm doing and why so many people follow this account. But we're riding this bitch, dawg

Ride and die malware ✊(I'm scared and confused)
❀199πŸ₯°22🫑17🀝4πŸ‘3πŸ€”1😒1
vx-underground
A large VPN provider reached out to me. They were wanting to do some stuff together to reach the cybersecurity audience, or something. The primary reason I don't do ads, while I very much enjoy having money, is because I can't in good faith recommend a product…
Anyway, now that I'm done virtue signaling and pretending I'm all high and mighty, here is a new formula I'm experimenting with.

I'll be pushing updates to the "Updates" directory. It has cool and badass ASCII art like old VXUG

https://vx-underground.org/Updates
πŸ₯°60πŸ”₯26❀14🀝3😒1
No, vx-underground is not associated with any cryptocurrencies. I don't know why people keep asking.

I'm not a cryptocurrency nerd.

I (very sincerely) don't even understand how it works. I perceive it as imaginary internet money that nerds use for nerd stuff.
❀76🀣29πŸ₯°11πŸ€“9πŸ‘4😁3😒1πŸ™1
Want to stop cybercrime tomorrow? Simple. Decriminalize cybercrime.

Can't be a crime if it's not illegal

Think smarter not harder
❀129🀣65πŸ‘20πŸ€“11πŸ₯°9πŸ’―7πŸ”₯4❀‍πŸ”₯2πŸ™1🀝1
This media is not supported in your browser
VIEW IN TELEGRAM
Nintendo wanted to do an advertisement on the Switch and FOX news Milwaukee, Wisconsin, jumped the gun and went doomer mode on bro😒
🀣68❀2πŸ”₯1😒1
Hello,

More updates have been pushed. Look at it, enjoy the spoopy ASCII art.

https://vx-underground.org/Updates
❀42🀣8πŸ₯°5😒1