vx-underground
47.7K subscribers
4.13K photos
441 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
vx-underground
California is proposing California Assembly Bill 1709 (AB 1709). It's age verification on the internet (again). This makes this the 3rd, or 4th, state in the United States wanting to introduce additional legislation on age verification online. This is different…
I don't want to sound like a schizo, but it's really weird that seemingly out of nowhere different parts of the United States are pushing aggressively to do age verification. It's also weird how some have pushed for it at the OS level (including Zuckerberg).
😱51💯36😢8🤣75😁3🥰1🤔1
Colorado politicians are smoking methamphetamine for even thinking an OS-based age verification system could work.

If it's local on someones machine it will be damn near impossible to prevent tampering. Beyond the difficulty of forcing it on something like Linux, nerds have historically shown to be incredibly persistent and grumpy when forced to do something they don't like.

For example, I purchased these goofy little toy things for my baby boy called a "Tonies". I was surprised to find there was a "Tonies" hacker community. Basically, any sort of thing nerds don't like, some small niche community pops up to bonk it with a stick.

If in the event an OS-level age verification system appeared, I wholeheartedly believe every nerd on the planet would unite to fight it, tamper with it, break it, reverse engineer it, and make politicians lives miserable.

In summary, it's a "nice idea" for politicians, but it would invoke weaponized autism on an international scale.
💯9716😁6🥰2🤣2
This media is not supported in your browser
VIEW IN TELEGRAM
Anthropic stealing a bunch of data to train their AI model just to see a bunch of places steal the data they stole to train their AI model
🤣122😁6😇43💯3🥰2
Medical startup idea

Pour some sort of cement mix into the lungs from nose, connected externally to a string

Let the cement solidify

When cement is solid, pull the string.

Cement comes out and pulls out all the nasty stuff in your lungs too

I've cured Emphysema
🤓68🔥15🤣122🤔2🥰1
vx-underground
Medical startup idea Pour some sort of cement mix into the lungs from nose, connected externally to a string Let the cement solidify When cement is solid, pull the string. Cement comes out and pulls out all the nasty stuff in your lungs too I've cured…
I'm really sick now, extremely congested. I unironically was like, "why can't we just pull the goop out of our lungs?"

Then I read about lungs and I realized they're really fucking complicated.

Anyway, cement mix should do the trick, it'll be fine
🤣63🫡7👍5😢21🥰1
Sometimes when I'm not motivated to do malware stuff (sickness or burnout), I keep my brain active by switching subjects.

I really enjoy history (all forms of it). I enjoy reading about other sciences. I also really enjoy reading philosophy and pretending to understand it and pretending to remember anything they're saying (I've read Nietzsche's "The Gay Science" and "Beyond Good and Evil" twice, can barely remember anything besides core concepts).

Because I am sick I have been reading about health and medicine, specifically in the historical context.

I'm not a physician. I am not a medical expert. I like to ask dumb questions about the body and see stuff about it. I discovered today that someone had the same question as me, "why can't we replace human blood with milk?"

Why? I don't know. Milk is pretty good. What if a patient is dying of blood loss or something, can we just fill them up with milk? Can we replace the blood with milk?

This question was asked in 1873. Physicians tried replacing blood with milk from cows or goats. They tried both old milk and milk freshly ... milked ... from the animal (they had an animal in the operating room). It turns out, if you inject milk into someone, in an attempt to replace their blood, it will kill them. Blood is really complicated, or something, and it turns out you can't just replace it with milk.

When you try a milk transfusion, it causes kidney failure, heart attack, stroke, fat embolism (milk curdles in the veins, I don't know), severe immune system reaction, etc.

Anyway, if you're curious: do not try to replace your blood with milk.
42🤯21🤣17🤓13🫡8🥰1
vx-underground
Sometimes when I'm not motivated to do malware stuff (sickness or burnout), I keep my brain active by switching subjects. I really enjoy history (all forms of it). I enjoy reading about other sciences. I also really enjoy reading philosophy and pretending…
If you're curious, look up: Intravenous Milk Experiments

It turns out many people just as dumb as me had this idea.

It will also unveil in 2024 when a nurse in Egypt accidentally administered baby formula in a babies IV bag instead of saline. It was such a medical disaster it was documented and studied.

Thankfully, medical experts freaked the fuck out and it was all hands on deck. The baby survived, made a full recovery, is doing great now. It isn't reported what happened to the nurse, but I assume they beat her to death in the parking lot for making such a fucking stupid mistake.
32🤣22🤯9🫡3🥰2
Yesterday Spanish authorities announced the arrest of individuals in Spain operating as a group under the moniker 'Anonymous Fénix' (Phoenix, but in Spanish).

The group of four carried out DDoS attacks against government infrastructure in Spain ... while residing in Spain.

Threat Actors (and also low-key law enforcement) will tell you it's a poor decision to perform cyber attacks in the country you reside in. It makes it much easier for authorities to collect evidence and arrest you. The phrase, "don't shit where you sleep" is used here.

Anonymous Fénix openly took credit on social media (X and Telegram) by writing they are "the responsible for the tragedy" [sic]

While Guardia Civil (military police force in Spain, handles cybercrime stuff and other stuff like terrorism) has apprehended all four individuals, no information has been released on the charges they face.

Depending on how the courts decide to punish the four individuals, each person is facing 6 months - 5 years.

Picture via Guardia Civil
🤣80🥰189😢2😁1💯1
Today the United States sanctioned Sergey Zelenyuk, and his company Matrix LLC, notably for "acquiring at least eight proprietary cyber tools exclusive to the United States government".

Want to guess what those tools were? See image two!

Info via jsrailton
🤣93😁83❤‍🔥2🥰1
Media is too big
VIEW IN TELEGRAM
CIA whistleblower John Kiriakou has been trending on TikTok and Instagram lately. Kids have discovered his interviews and have been making "clips".

I had to admit, their way to educate their peers on CIA activities is funny. I like it.
🤣888😁5🫡2🥰1
After I made a few grand memeing Bill Gates in the Jeffrey Epstein files, I did the only logical thing: used the money to buy myself an ILOVEYOU worm chain.
🔥78🥰22💯63👍3🎉3
In late 2025, the United States Department of Justice announced the apprehension of several individuals in Tren de Aragua (international crime syndicate from Venezelua) for using some sort of malware on ATMs.

Tren de Aragua were "ATM Jackpotting", using malware which would drain the money inside the machine. However, limited information at the time until January, 2026 and an official FBI IC3 FLASH report February 19th.

Tren de Aragua is using a custom variant of Ploutus. Ploutus first appeared in 2013 and has been active (in some capacity) since then, only appearing sporadically in 2013, 2014, 2017, 2018, 2019, 2021, and again in 2025 and/or 2026.
26🥰2
vx-underground
In late 2025, the United States Department of Justice announced the apprehension of several individuals in Tren de Aragua (international crime syndicate from Venezelua) for using some sort of malware on ATMs. Tren de Aragua were "ATM Jackpotting", using malware…
While this may appear like a lot (based on the years listed), with malware campaigns you'll see samples flooding in by the hundreds or thousands daily. Ploutus only appearing individually once every few years is due to the difficulty in using Ploutus. Ploutus requires physical access to the machine. Describing Ploutus as malware is accurate, however it is more akin to an ATM hacktool than "malware" in the traditional sense.

Furthermore, from a research perspective, getting access to Ploutus samples is challenging. Ploutus is nothing something found randomly on the internet.

Whoever wrote Ploutus, or maintains and updates it, will need access to an ATM and ATM API documentation. Basically, this isn't something some random nerd could get, test, and develop. It isn't surprising an international drug cartel has the capability to illegally acquire an ATM and/or ATM developer documentation.

And, as you're probably assuming while reading this, it is indeed incredibly dangerous to use Ploutus. ATMs have cameras. You need to be ballsy to run up on an ATM and try to use a hacktool on it. Unsurprisingly, international cartels have no shortage of money mules who are willing to risk their freedom for the group.
36🥰3
Ages ago some NATO-based Threat Actors were causing problems to the United States government. In the official Department of Justice court paperwork, the United States government was able to acquire precise Telegram chat logs from the Threat Actor apprehended.

The documents were partially sealed and information on how the chat logs were acquired was never disclosed.

Many Threat Actors on Telegram immediately jumped to the conclusion the United States government had utilized a Telegram exploit to get access to their conversations.

I believed this to be speculative and borderline schizo. However, I have continually been proven false by schizos repeatedly over-and-over-and-over again in 2026.

Do you think the United States government would authorize the usage of zero day exploits against ransomware operators who have proven to be difficult to identify?
💯94👍95🙏3🥰2🤝1
> be me
> can't math at all
> suffered in math in school
> mathematical dyslexia
> weird symbols scare me
> can program though
> self taught c programmer
> been programming for like, 20 years
> see spoopy calculus thingy
> ask ai thingy
> "can translate calculus to c?"
> ai thingy responds
> "programming just discrete mathematics lol r u dumb? of course"
> shows me calculus thingy translated to C
> makes literally perfect sense
> look inside
> calculus, discrete mathematics, algebra
> all make perfect sense

Wtf why did the public school system make math seem so crazy
103🔥16🤣15🤔11🥰2👍1👏1💯1