vx-underground
47.8K subscribers
4.2K photos
448 videos
84 files
1.5K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Malware defense stuff is boring and I respect these AV and/or EDR nerds so much for working on this stuff.

I've spent the past few days really locking in on developing an ETW consumer and using the YARA static analysis engine in conjunction with it.

It is all documented. It is easy-ish to follow. It all makes sense. Even the more "hardcore" stuff like the kernel mode callback routines and minifilters are handed to you on a silver platter with tons of documentation and examples from Microsoft.

These AV and/or EDR nerds unironically have to spend their days monitoring microscopic potential edge cases for malware evasion and then making a tiny little change in code to account for it. If they don't account for this tiny little potential attack vector they're criticized and insulted endlessly.

Conversely, this tiny line of code they've added burns the hours of research I've placed into developing something.
πŸ₯°56❀15😍2πŸ’―2
vx-underground
Malware defense stuff is boring and I respect these AV and/or EDR nerds so much for working on this stuff. I've spent the past few days really locking in on developing an ETW consumer and using the YARA static analysis engine in conjunction with it. It is…
Malware defense stuff is pretty much just standing by the front door with a really big stick waiting for someone to walk in, bonking them on the head with it, and then throwing their unconscious body back outside ... forever and ever ... until you're dead or retire.
πŸ’―70πŸ˜‡11❀6🀣6πŸ₯°5πŸ”₯1
Someone sent me a malware sample they found on Discord. I'll tell you one thing right now, Chat. StealIt is a colossal pain in the fucking ass to reverse engineer.

I was crashing out on Xitter for a second about it. This thing is soooo annoying. It is super evasive because of their GOD DAMN SEA BLOBS AND NODE JS BULLSHIT
πŸ₯°73❀20😁15🀯7😒2
RIP Chuck Norris

I'll never forget all the goofy jokes you inspired
🫑207❀27😒14🀯5🀣5❀‍πŸ”₯4😱3πŸŽ‰2πŸ€”1πŸ™1πŸ˜‡1
vx-underground
RIP Chuck Norris I'll never forget all the goofy jokes you inspired
Chuck Norris doesn’t read books.
He stares them down until he gets the information
❀119🀣44πŸ‘6🫑4πŸ‘2😁2πŸ€”2πŸ₯°1
November, 2024 weight:
285lbs
129.2kg

March, 2026
226lbs
102.5kg

After my son was born I fell off the weight loss wagon due to sleep deprivation and exhaustion from baby stuff. I got back on it.

I feel a lot better since losing so much weight. Health and science and stuff
❀157πŸ‘56πŸ”₯13🀣9πŸŽ‰8❀‍πŸ”₯3πŸ‘2🀝2πŸ₯°1πŸ™1😘1
Mildly Interesting:

Windows Defender 1.445.674.0 contains logic to detect malware designed to target "AIGen" threats.

It is titled "AIGen.Trojan.ClawHavoc".
🀣50πŸ₯°40πŸ‘9πŸ€”7❀3
> be IT
> new hardware comes in
> need to image 2000 new DELLs
> protect kids from pedos law drops
> id verification at OS level
> enter my ID for 2000 PCs
> FBI raids office building
> everyone arrested
> everyone was using pc with my ID
> all arrested for identity theft
🀣122πŸ₯°90🀯8❀5πŸ‘3😁1🀝1
vx-underground
> be IT > new hardware comes in > need to image 2000 new DELLs > protect kids from pedos law drops > id verification at OS level > enter my ID for 2000 PCs > FBI raids office building > everyone arrested > everyone was using pc with my ID > all arrested for…
this is how i imagine ID verification at OS level working in enterprise environments. it haunts me (it makes me giggle)
πŸ₯°66😁37😒6πŸ˜‡4🀝4❀2❀‍πŸ”₯1πŸ’―1
Claude, raise my children. Make no mistakes.
❀89😁61πŸ₯°8🫑6πŸ”₯5🀩2πŸ’―2🀣2πŸ‘1
> wake up
> take a shit
> get out of bed
> baby screaming
> see whats wrong
> mad as hell cause hungry
> feed him
> hes eepy
> snuggle him
> headbutts face
> busts my lip
> ow
> calm down
> snuggle him
> rips glasses off my face
> bends my glasses
> laughs in my suffering
> get glasses back
> he shits his pants
> try to clean up
> angry at me because ???
> new fresh diaper on
> holding him
> slaps my face
> tries to put fingers in my nose
> put him down
> crawls to plants
> tries to eat dirt
> take away dirt
> mad as hell because wont let eat dirt
> calm him down
> shits pants again some how
> try to change him
> mad because ???
> rolls around bed
> poop stamps from ass cheeks on bed
> wrestle him
> calm him down
> new diaper again
> put him in walker to prepare breakfast
> runs over my toes
> ow
> pulls spatula off table
> chases dog around kitchen with spatula
> take away spatula
> mad as hell again
> pick him up to calm him down
> kicks me in testicles

anyway, thats been my sunday so far with a 1 year old
❀120🀣75🫑17πŸ™8πŸ’―8πŸ₯°4😱4πŸ”₯1
Meanwhile in San Francisco: random startup nerd thinks he ran into CEO of YCombinator at Chipotle, was actually just some random Asian guy. Random Asian guy apparently goes along with it. CEO of YCombinator breaks the bad news
🀣218🀩12❀7πŸ₯°1😒1
This media is not supported in your browser
VIEW IN TELEGRAM
Me at BSides doing a talk on cybersecurity
😒35🀣35πŸ”₯17πŸ₯°5πŸ’―2❀1πŸŽ‰1
vx-underground
Me at BSides doing a talk on cybersecurity
Context:
🀣144πŸ”₯7πŸ₯°5❀2🀝1
πŸš¨β€ΌοΈ BREAKING: Crunchyroll breached through outsourcing partner in India.

A threat actor exfiltrated data from Crunchyroll's ticketing system and also managed to pull 100 GB of personally identifiable customer analytics data.

We've analyzed sample data and it includes IP addresses, email addresses, credit card details, and more.

An employee of their outsourcing partner Telus had executed malware on his system, which gave a threat actor access to Crunchyroll's environment.

The threat actor told us the breach happened on March 12, 2026. Crunchyroll revoked their access after 24 hours.

They also said Crunchyroll is ignoring all messages and still hasn't publicly disclosed the breach.
🀣103πŸ”₯59😱17❀8πŸ₯°6πŸ€“6🫑3πŸ‘1😒1
Leonid Radvinsky, founder of MyFreeCams and majority owner of OnlyFans, has died of cancer.
πŸŽ‰223🫑72🀣37😒17❀9πŸ‘8πŸ˜‡5πŸ₯°2😱2πŸ”₯1