vx-underground
47.5K subscribers
4.1K photos
438 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Before my son was born my wife and I read all these books and stuff on babies. We also took these fancy classes.

Literally none of them told us the baby would try to headbutt.

THEIR HEADS HURT. THEY HEADBUTT YOUR FACE
πŸ₯°89😁33❀12🀯8❀‍πŸ”₯4πŸ’―2πŸ‘1πŸ”₯1
Meanwhile on X, I volunteered to run TorGuard VPNs social media. They're a big donor to vx-underground.

In one day I got in trouble. I made a joke we're laying off the engineering department and apparently it's not cool to joke about laying people off
😁182❀29🀣22😒10🀯8πŸ™5πŸ₯°2❀‍πŸ”₯1😱1
> be me
> long day at long day factory
> decide to relax
> open x
> it's the everything app
> click "For You"
> first post
> trans person crying
> say they're burden on family
> say they're being kicked out
> point camera at three bottles of pills
> open all bottles
> take all pills at once
> record their suicide
> x, the everything app
😒178😁37🀣36😱11🀯10❀6πŸŽ‰6πŸ₯°4πŸ€”2πŸ’―2😎2
FLARE released a paper on a Linux botnet using IRC as a C2.

WHAT YEAR IS IT???

Then I remembered Threat Actors can't use Discord as a C2 because they probably want ID verification
😁75🀣58πŸ₯°9❀6πŸ”₯3
I'm currently:
- writing over 500,000,000 lines of code a day
- running 400 different agents
- building 9 different apps

My wife and her boyfriend are so proud of me. What's your excuse?
🀣212πŸ₯°21πŸ€“17🫑8😁5❀3😱1😎1
When people ask what I do for a living I have no idea how to explain to them I collect, develop, and reverse engineer malware.

I usually say, "I do stuff with computers".

Then I immediately change the conversation and hide.
πŸ€“75πŸ₯°25❀8🀣8πŸ‘5😎3
Apparently this account is large enough now where this is important news to people

Yes, people actually received this on Xitter
🀣153πŸ₯°19😁9❀8πŸ”₯5πŸ‘1😒1πŸŽ‰1😍1
Media is too big
VIEW IN TELEGRAM
🀣57πŸ₯°16❀‍πŸ”₯6❀6πŸ€“3
Was surfing the internet and found some kid who is sharing his malware proof-of-concepts online. His work is primarily recycling and recreating existing techniques for him to study or to demonstrate the ideas to others.

Is his code good? No, God no. It is littered with errors, poor naming conventions, and extremely dangerous control flow. I love it him for this, unironically.

This kid having bad code shows he isn't using AI to work. He is legit. He is putting himself out there, demonstrating what he can do (or can't do), and showing he isn't afraid to get criticized.

I love seeing people grind and put in the work. It's the pain that makes you good. Taking shortcuts doesn't achieve anything.

I don't know if it he is on social media stuff, but you're doing good stuff, "CaptMag". Keep putting in work. You'll go far. I see you, gang.
❀171πŸ₯°15πŸ‘11🫑7❀‍πŸ”₯4πŸ‘3πŸŽ‰1πŸ’―1
vx-underground
Was surfing the internet and found some kid who is sharing his malware proof-of-concepts online. His work is primarily recycling and recreating existing techniques for him to study or to demonstrate the ideas to others. Is his code good? No, God no. It is…
I'm sorry, CaptMag, I love you, dawg, but I audibly laughed when you initialized your unsigned integers (DWORD) to NULL.

If you want to get really technical, NULL on Windows is defined as zero, so it ... sort of ... makes sense, you are technically setting your unsigned integers to zero, but NULL is supposed to indicate an invalid pointer.

I have no idea how your IDE hasn't been screaming at you about this.
❀79🀣33😱9😁7πŸ₯°5❀‍πŸ”₯3🀩1
❀72🀣41😒12😘4πŸ₯°1πŸ’―1πŸ˜‡1
nerds were goofing around on the internet and accidentally found mass surveillance technology owned by openai, persona-id, and working with the us gov

guess i gotta do a tl;dr on this mfer
❀65πŸ₯°15😁5😘5πŸ˜‡3πŸ‘2πŸ™1
> be nerds
> look into persona (used by discord)
> kyc (know your customer) service
> used for age verification
> search on internet (shodan)
> find weird server
> image 1
> openai-watchlistdb.withpersona
> openai-watchlistdb-testing.withpersona
> lolwtf
> look inside
> supposed to be behind cloudflare to hide ip
> openai messed up
> not behind cloudflare
> real ip shown
> using google cloud
> lookup cert history
> 2023-11-16 created
> 2024-02-28 gets cert
> 2024-03-04 prod goes live
> google stuff
> openai and persona partners
> partner around timeline of certs
> back to searching stuff
> find withpersona-gov
> look inside
> okta (image 2)
> lolwtf
> look inside
> website accidentally leaking stuff
> fedramp-private-backend-api
> look inside
> api .js accidentally exposed
> look inside
> wtf "SARInstructionsCard"
> wtf "app.onyx.withpersona-gov"
> wtf "FINTRAC"
> wtf "PrivatePartnershipProjectNameCodes"
> image 3
> wtf "AsyncSelfie"
> look inside
> openai, persona, send data to us gov
> feds map face to financial records
> map face using AI
> map face to ICE stuff
> api stores data for lots of stuff
> image 4

tl;dr persona kyc and openai are frens, using your selfie for verification and sending to ICE (or USGOV in general), using AI to tie to your financial records. see subsequent post for full write-up. its long and not mobile friendly
❀71😱34🀣19πŸ₯°5🀯4😒3πŸ”₯1
Earlier today X employees bragged X only has 30 employees. Guess which website is down again?
🀣133❀8πŸ’―7πŸ”₯4πŸ₯°2