vx-underground
47.7K subscribers
4.13K photos
441 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
vx-underground
Sometimes when I'm not motivated to do malware stuff (sickness or burnout), I keep my brain active by switching subjects. I really enjoy history (all forms of it). I enjoy reading about other sciences. I also really enjoy reading philosophy and pretending…
If you're curious, look up: Intravenous Milk Experiments

It turns out many people just as dumb as me had this idea.

It will also unveil in 2024 when a nurse in Egypt accidentally administered baby formula in a babies IV bag instead of saline. It was such a medical disaster it was documented and studied.

Thankfully, medical experts freaked the fuck out and it was all hands on deck. The baby survived, made a full recovery, is doing great now. It isn't reported what happened to the nurse, but I assume they beat her to death in the parking lot for making such a fucking stupid mistake.
34🤣22🤯9🫡3🥰2
Yesterday Spanish authorities announced the arrest of individuals in Spain operating as a group under the moniker 'Anonymous Fénix' (Phoenix, but in Spanish).

The group of four carried out DDoS attacks against government infrastructure in Spain ... while residing in Spain.

Threat Actors (and also low-key law enforcement) will tell you it's a poor decision to perform cyber attacks in the country you reside in. It makes it much easier for authorities to collect evidence and arrest you. The phrase, "don't shit where you sleep" is used here.

Anonymous Fénix openly took credit on social media (X and Telegram) by writing they are "the responsible for the tragedy" [sic]

While Guardia Civil (military police force in Spain, handles cybercrime stuff and other stuff like terrorism) has apprehended all four individuals, no information has been released on the charges they face.

Depending on how the courts decide to punish the four individuals, each person is facing 6 months - 5 years.

Picture via Guardia Civil
🤣82🥰189😢2😁1💯1
Today the United States sanctioned Sergey Zelenyuk, and his company Matrix LLC, notably for "acquiring at least eight proprietary cyber tools exclusive to the United States government".

Want to guess what those tools were? See image two!

Info via jsrailton
🤣97😁83❤‍🔥2🥰1
Media is too big
VIEW IN TELEGRAM
CIA whistleblower John Kiriakou has been trending on TikTok and Instagram lately. Kids have discovered his interviews and have been making "clips".

I had to admit, their way to educate their peers on CIA activities is funny. I like it.
🤣938😁5🫡2🥰1
After I made a few grand memeing Bill Gates in the Jeffrey Epstein files, I did the only logical thing: used the money to buy myself an ILOVEYOU worm chain.
🔥86🥰23💯63👍3🎉3
In late 2025, the United States Department of Justice announced the apprehension of several individuals in Tren de Aragua (international crime syndicate from Venezelua) for using some sort of malware on ATMs.

Tren de Aragua were "ATM Jackpotting", using malware which would drain the money inside the machine. However, limited information at the time until January, 2026 and an official FBI IC3 FLASH report February 19th.

Tren de Aragua is using a custom variant of Ploutus. Ploutus first appeared in 2013 and has been active (in some capacity) since then, only appearing sporadically in 2013, 2014, 2017, 2018, 2019, 2021, and again in 2025 and/or 2026.
28🥰2
vx-underground
In late 2025, the United States Department of Justice announced the apprehension of several individuals in Tren de Aragua (international crime syndicate from Venezelua) for using some sort of malware on ATMs. Tren de Aragua were "ATM Jackpotting", using malware…
While this may appear like a lot (based on the years listed), with malware campaigns you'll see samples flooding in by the hundreds or thousands daily. Ploutus only appearing individually once every few years is due to the difficulty in using Ploutus. Ploutus requires physical access to the machine. Describing Ploutus as malware is accurate, however it is more akin to an ATM hacktool than "malware" in the traditional sense.

Furthermore, from a research perspective, getting access to Ploutus samples is challenging. Ploutus is nothing something found randomly on the internet.

Whoever wrote Ploutus, or maintains and updates it, will need access to an ATM and ATM API documentation. Basically, this isn't something some random nerd could get, test, and develop. It isn't surprising an international drug cartel has the capability to illegally acquire an ATM and/or ATM developer documentation.

And, as you're probably assuming while reading this, it is indeed incredibly dangerous to use Ploutus. ATMs have cameras. You need to be ballsy to run up on an ATM and try to use a hacktool on it. Unsurprisingly, international cartels have no shortage of money mules who are willing to risk their freedom for the group.
38🥰3
Ages ago some NATO-based Threat Actors were causing problems to the United States government. In the official Department of Justice court paperwork, the United States government was able to acquire precise Telegram chat logs from the Threat Actor apprehended.

The documents were partially sealed and information on how the chat logs were acquired was never disclosed.

Many Threat Actors on Telegram immediately jumped to the conclusion the United States government had utilized a Telegram exploit to get access to their conversations.

I believed this to be speculative and borderline schizo. However, I have continually been proven false by schizos repeatedly over-and-over-and-over again in 2026.

Do you think the United States government would authorize the usage of zero day exploits against ransomware operators who have proven to be difficult to identify?
💯97👍105🙏3🥰2🤝1
> be me
> can't math at all
> suffered in math in school
> mathematical dyslexia
> weird symbols scare me
> can program though
> self taught c programmer
> been programming for like, 20 years
> see spoopy calculus thingy
> ask ai thingy
> "can translate calculus to c?"
> ai thingy responds
> "programming just discrete mathematics lol r u dumb? of course"
> shows me calculus thingy translated to C
> makes literally perfect sense
> look inside
> calculus, discrete mathematics, algebra
> all make perfect sense

Wtf why did the public school system make math seem so crazy
112🤣25🔥17🤔12👍3💯3🥰2👏1😱1