vx-underground
45.9K subscribers
3.94K photos
419 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
mfw I realize you can use C++ WINAPI COM IUIAutomation to communicate with Copilot directly and tell it do things like "execute this file" (Copilot is now Copiloting my malicious payload)
πŸ”₯118😱17🀣16😎14πŸ€“8❀4πŸ₯°2😒1
vx-underground
mfw I realize you can use C++ WINAPI COM IUIAutomation to communicate with Copilot directly and tell it do things like "execute this file" (Copilot is now Copiloting my malicious payload)
I made a joke about asking Copilot to encrypt my files. Then I got curious and looked into if Copilot can launch files (it can). I've been able to pipe input directly to Copilot using COM, it's very silly (SendMessage doesn't work on it, it's their new fancy UI bullshit).
❀52🀣10😁7πŸ₯°4😒2
vx-underground
mfw I realize you can use C++ WINAPI COM IUIAutomation to communicate with Copilot directly and tell it do things like "execute this file" (Copilot is now Copiloting my malicious payload)
Note: It's wildly inconsistent during my testing. I'll release my code and let others experiment with it who are better with that sort of stuff.

I think it's a neat project and there is room for more growth and exploration

Sometimes it displays a consent prompt (haven't automated that), sometimes it tells me to do it myself. Sometimes it tells me to do it via voice command (???).
❀45🀣24πŸ™4πŸ‘3😒2πŸ₯°1🀩1
Good news everyone,

MS-Paint, the legacy art software which has shipped with Windows since 1985, has been dramatically IMPROVED to now include Microsoft Copilot Image Creator.

*subscription required, need Microsoft Copilot AI credits
😒85🀣49😁5❀3πŸ”₯1πŸ₯°1πŸ€”1πŸ€“1
vx-underground
Good news everyone, MS-Paint, the legacy art software which has shipped with Windows since 1985, has been dramatically IMPROVED to now include Microsoft Copilot Image Creator. *subscription required, need Microsoft Copilot AI credits
I guess this goes back to 2022, I'm just blind as hell and dumb as hell.

I'm late to the outrage, but I'm still outraged gosh dangit
🀝40πŸ”₯11❀2😒1
In 2003 Travis Grygla was convicted of possession of CSAM (Child Sexual Abuse Material).

In 2008 Travis Grygla was convicted of distribution of CSAM.

Following his release, in 2024 he was subject to a federal raid for possession and distribution of CSAM (again). However, when the United States Homeland Security Investigation Unit showed up to his house he ran outside and stole the federal agents car.

As you could probably assume, Homeland Security loves it when a convicted CSAM distributor steals their vehicle (which has a loaded gun in the vehicle) and leads them on a 110MPH (117KPH) police chase.

January 4th, 2026, Midwest Safety was able to get a copy of the police cam body footage as a result of a court subpoena.

If you'd like to watch United States Homeland Security Investigation Unit, Portland Oregon Police Bureau, Vancouver Oregon Police Department, Washington State Patrol, and Cowlitz County Sheriff’s Office, chase Travis Grygla I recommend watching the attached video.

https://www.youtube.com/watch?v=s_HmsifhNaw
πŸ₯°25😁6❀4πŸŽ‰2😒1
Abusing Microsoft Copilot: Copilot, copilot my payload

*please read limitations notes on the page. It's important you read that.

tl;dr inconsistent, needs more research, potential avenue to explore

https://malwaresourcecode.com/home/my-projects/proof-of-concepts/microsoft-copilot-copilot-my-payload
πŸ₯°32❀12πŸ‘3😒1
Discussions online today of 17,500,000 people involved in an "Instagram" leak.

This is a clarification from a previous post I made, which I've subsequently deleted, to avoid confusion and add more details.

Normally these sort of "leaks" are a result of API scraping. This has happened in the past with LinkedIn and Trello. Basically someone writes a program that communicates with Instagram and requests information on a user profile. They then loop this through as many Instagram profiles as possible.

New information has come forward, as people have provided me with feedback, suggesting this is a combination of API scraping, a giant list of known stolen Instagram accounts, blah blah blah, and content from a previous leak.

Others have speculated this is someone who is doing mass password resets to try to correlate phone numbers and emails with accounts.

Basically, nobody knows. We can only make educated guesses. Regardless, Instagram wasn't "hacked" or compromised.

These sort of "leaks" resurface and reappear every couple of months, sometimes years, and is basically just a database for scammers and extortionists to do lookups or try to do phishing campaigns.

Pic of weird looking cat riding motorcycle is me rn fr
πŸ₯°40❀13πŸ€“10😒2πŸ™2😎1
Hi

vxdb (on Twitter, no idea if he's on Telegram), initially unrelated to vx-underground, will now be a vx-underground staffer. He isn't a malware nerd, but he is terminally online, a degenerate, and continues to help me with stuff (which I deeply appreciate).

He'll be doing some administrative work for me. It is becoming increasingly difficult to do stuff while managing full time employment, a baby boy, and a vx-underground. He won't have access to this account, or vx-underground infrastructure, but he'll be handling other stuff (read below)

In summary, one of the first things we'll be doing is making a social media profile exclusive to g1v3aw4ys. This will eliminate the g1v3aw4y spam from this profile. I have yet to finish the g1v3aw4ys from 2025. Oops.

Thanks to TorGuard, and our monthly sponsors, I am hoping to do more g1v3aw4ys on the other profile throughout 2026. Maybe like, books, or something, I don't know. It won't be big stuff. But ideally like, $200/month of free stuff. Then, during the end of the year, the account does big stuff.

ok ily ttyl bye
❀‍πŸ”₯64❀19πŸ₯°4πŸ‘2😒2
vx-underground
Hi vxdb (on Twitter, no idea if he's on Telegram), initially unrelated to vx-underground, will now be a vx-underground staffer. He isn't a malware nerd, but he is terminally online, a degenerate, and continues to help me with stuff (which I deeply appreciate).…
I haven't finished g1v3aw4ys because instead of dealing with hundreds of people I've been doing malware stuff, spending time with my baby boy (he's angry, his top teeth are coming out, he WILL bite you), and posting silly pictures of cats.

Sorry.
❀62πŸ₯°15😒7🀣1
UK and Australia discussing banning X because Grok keeps putting people in bikinis
😁122πŸ”₯20πŸ₯°12🀣12πŸ€“7🫑4πŸ‘3❀2πŸ‘2😱2πŸ€”1
Lots of negativity on social media the past few days.

Will continually post silly cat pictures until morale improves
❀159πŸ₯°34🫑22❀‍πŸ”₯2πŸ€”2😒1
Lots of negativity on social media the past few days. Will continually post silly cat pictures until morale improves
πŸ₯°95❀34❀‍πŸ”₯11😎5😁3
A sort of small, sort of long, observation or note, or something.

tldr nerds mad, touch grass

The internet (and humans in general, I suppose) love negativity and drama. There becomes a point though where negativity goes beyond spectacle and entertainment and it bleeds over into public anger and mass hysterics.

While I don't traditionally make political commentary (or try to rather, I'm human, make mistakes, or accidentally present bias), and stray away from political banter, my curated and compartmentalized information security feed has transformed into some pretty nasty dialogue regarding the recent United States governments actions both domestic and abroad. While some of my peers engage in political banter, an upward trend being observed, whereas even the "non-political" begin discussing things, is paramount and is an indicator that a profound event has occured.

This typically results in me saying "huh?" and acting like the cat in the attached image below.

Outside of this bubble I've made, it is chaotic (I'm sure you're well aware of what I'm addressing at this moment). Historically, it is unusual for this degree of anger and frustration to bleed into my bubble, previous and noteworthy "bleeds" include Mr. Rittenhouse, the death George Floyd, Ukraine-Russia conflict (beginning), Palestine-Israel conflicts (elevated, major event occuring), the COVID19 pandemic, January 6th, the assassination of Charlie Kirk, ... and now the recent events occuring.

I think being exposed to this polarization for too long is unhealthy, it makes people angrier, and deepens a divide. It's important to remember that political commentators profit off of outrage, it boosts their engagement and advertisement revenue, thus want to continually stoke the fire and ensure you're perpetually agitated.

I unironically recommend my colleagues and peers to touch grass. Disconnecting and disengaging with the internet hate machine puts things into perspective. Hug your children, pet a kitty cat, eat some junk food, go for a walk, ... do something other than being angry on the internet. There is a difference between being informed and being drawn into the political "event horizon".

Okay, back to kitty cat posting until morale improves and also nerd stuff.
❀98πŸ₯°10πŸ‘6πŸ€”3πŸ’―3🀝2
vx-underground
A sort of small, sort of long, observation or note, or something. tldr nerds mad, touch grass The internet (and humans in general, I suppose) love negativity and drama. There becomes a point though where negativity goes beyond spectacle and entertainment…
I unironically perceive myself and you nerds as like, a bunch of old ass monks or priests or something, up on like High Hrothgar.

Shits gotta get wild down there with the normies if we can hear it
πŸ’―70πŸ₯°10😁7🀣7πŸ€”2πŸ€“2❀1πŸ‘1πŸ”₯1😱1🀝1
Hi

I've added more malware and malware accessories to the website you sometimes visit.

https://vx-underground.org/Updates
❀46🀣10πŸ€”3🀯3πŸ₯°1😍1
Person on YouTube uploads a video that is 114,115 years long (1,000,000,000 hours).

The video is (probably) a One Piece anime review.
🀣161❀8πŸ₯°8πŸ”₯5