vx-underground
48.6K subscribers
4.28K photos
457 videos
84 files
1.51K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Look at this and tell me God exists
🀣227πŸ€“19😒18πŸ”₯9😁8🀯5πŸŽ‰3❀2πŸ₯°2
Dear Threat Actors,

I typically do not reply on weekends. I am busy doing stuff with my 1 year old son. Please send your e-mails during regular business hours M-F so I have an opportunity to send silly pictures of kitty cats.

Thanks,
-smelly
❀97πŸ₯°20πŸ”₯6❀‍πŸ”₯2πŸ‘1
vx-underground
Dear Threat Actors, I typically do not reply on weekends. I am busy doing stuff with my 1 year old son. Please send your e-mails during regular business hours M-F so I have an opportunity to send silly pictures of kitty cats. Thanks, -smelly
Bro is sending me e-mails from a (extremely convincing) Police Department ON A SATURDAY.

Dawg, Saturday I am in SHAMBLES. I am trying to survive with this baby. Do you have any idea how often these things defecate and eat? It's unreal
🀣106😁11πŸ₯°10🫑7❀1πŸ”₯1
1 year olds are far more exhausting than 6 month olds.

Parents warned me. They were correct.

Bro HAS to put ALL FOOD on his head.

- Beans
- Soup
- Mac and Cheese
- Strawberries
- Blueberries

If he doesn't rub it on his head, or eat it, he throws it on the floor.

I'm tired.
🫑135🀣55πŸ™16❀11πŸ”₯5πŸ₯°5πŸ’―3πŸŽ‰2😁1
Hi

I've added another 550,000+ malwares to the malware library. Please download the malware and share it with your friends and family.

https://vx-underground.org/Updates
❀82🀣57πŸ₯°20🀝7😱5πŸ’―3😁2🫑2
This is very good malware.

This is solid-solid-SOLID B+ malware, very close to A- malware.

APT37 is using a old-school playbook. They're doing EPO (Entry Point Obfuscation) on a self-delivered binary for evasion. They also unironically are using something akin to cavity infection ... but on themselves. This is something you saw more in the Windows 95 - Windows XP era, not something you see in 2026.

Very cool. I respect it.

The multi-staged fragmentation of shellcode phases is also really, really, really cool. This is (once again) a more old-school technique usually reserved for infected binaries, not self-delivered binaries.

Despite all of these super cool features, APT37 shoots themselves in the foot immediately.

- EAT walking for Kernel32 functionality (???)
- XOR decryption is a huge red flag
- Allocating with PAGE_EXECUTE_READWRITE (???)
- Hardcoded OAuth token (???)
- Used external dependency for AES (???)

Why not use NT functionality to hook evasion? XOR is easily identified in static analysis, why XOR? Allocating memory with VirtualAlloc with RWX is a MASSIVE RED FLAG. They also hardcode a OAuth token ... they can multi-staged shellcode payload with old-school malware techniques but hardcore AN OAUTH TOKEN?

It unironically makes me wonder if they had one old-head malware guy working on it, then they had some newer dude do the non-hardcore stuff. There is a huge gap in skill sets here.

Or the old-head hasn't kept up to date on malware stuff since 2005... or they got lazy... I don't know, really weird.

https://www.genians.co.kr/en/blog/threat_intelligence/pretexting
❀49πŸ₯°12πŸ‘4😁4πŸ’―1
Over 200 media outlets are blocking Internet Archive.

Media outlets say because AI, or something, but also (and TOTALLY UNRELATED) since they're blocking Internet Archive there is no way to tell if the government or media outlet has deleted or change something.

However, they say this is TOTALLY UNRELATED and they block Internet Archive because AI can train off Internet Archive, or something, I don't know, it's all bullshit.

https://www.wired.com/story/the-internets-most-powerful-archiving-tool-is-in-mortal-peril/
😒94πŸ€”12πŸ₯°6❀3πŸ’―2πŸ‘1
vx-underground
Over 200 media outlets are blocking Internet Archive. Media outlets say because AI, or something, but also (and TOTALLY UNRELATED) since they're blocking Internet Archive there is no way to tell if the government or media outlet has deleted or change something.…
In fairness, media outlets want to charge you $9.99/month to read their half-AI generated web articles and Internet Archive does sometimes sort of provide a way to evade this.

However, there are tons of other ways to bypass this pay wall. I also do not trust the government. I also am extremely suspicious of media outlets. Sometimes I read what they're saying and I go, "HMMMMMMMM", hence I am extremely biased in this post.
πŸ₯°64πŸ‘18πŸ’―7πŸ€”5❀3
ShinyHunters leaked the RockStar Games data.

The data isn't anything special. There is no PII or source code. The data is primarily financial metrics.

This may come as a surprise to some of you, but based off of this data, it appears RockStar Games makes a FUCK TON of money
😁106πŸŽ‰14πŸ‘9❀3πŸ₯°3😱1🫑1
BREAKING: New intelligence from the United States Department of War suggest cars go all like VRRROOOOOM, SKRRRT, and PFFFTBLOOOOSH.

Donald Trump is being briefed on the situation now.
❀42😁23πŸ₯°8πŸ”₯6🀣6πŸŽ‰3🀝2
It appears I have made a series of mistakes when reviewing some of the financial data from RockStar Games.

What does this mean? I've spread misinformation and I will be burned at the stake by gamers.

It was nice knowing all of you
❀70🫑19πŸ₯°16🀣9😁5🀝1
vx-underground
It appears I have made a series of mistakes when reviewing some of the financial data from RockStar Games. What does this mean? I've spread misinformation and I will be burned at the stake by gamers. It was nice knowing all of you
Please remember me as man who tried his best and really enjoyed pictures of silly kitty cats.

I'm ready now. I'm at peace. The gamers will now call me a retard and the N-word for an eternity.
πŸ₯°74🀣26πŸ™17🫑16❀9😁7😱2πŸ€“1
> ramp up cyber defenses
> look inside
> change password to include !
> pay for nord vpn (protects from hackers)
> re-up norton antivirus subscription
> ask 7 year old nephew for help with ipad

we are cybersecurityied now dawg
🀣189❀25😁18πŸ₯°1πŸ’―1
I was pretty busy today. From what I saw when skimming the internet:

- More AI hot takes
- More laws about age verification
- Arguments about age verification
- Some cool new malware found
- Drama about fake ledger in Apple Store
- PUBG CEO used ChatGPT for business advice
- More malware stuff
- Malware AI slop
- Booking dot com drama, even though it's been poop forever
- More web compromises
- Kraken being extorted
- GitHub stars as a service
- Something about CloudFlare and OpenAI
- Something with malicious FireFox extensions
- Google hires Philosopher for AI
- Vulnerable AV drivers from China

Did I miss anything or am I good?
πŸ₯°32🫑8❀5🀝3❀‍πŸ”₯1🀯1πŸ€“1