vx-underground
50.3K subscribers
4.41K photos
479 videos
84 files
1.55K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
> steam malware stuff
> all the click bait places screaming
> malware from wallpaper engine
> don't cite original article
> from Kaspersky

Dawg, these Threat Actors targeted true degenerates. Look at this malware payload. This is seriously one of the malicious wallpapers
๐Ÿคฃ111โค6๐Ÿฅฐ5๐Ÿ‘3๐Ÿ˜ข1
vx-underground
> steam malware stuff > all the click bait places screaming > malware from wallpaper engine > don't cite original article > from Kaspersky Dawg, these Threat Actors targeted true degenerates. Look at this malware payload. This is seriously one of the maliciousโ€ฆ
Telegram nerds missed it, but some dumb fucks on X were discussing malware on Steam wallpaper engine, but no one cited the fucking source, provided images, or malware sample goopies. I looked into it, and it's legit, it's from Kaspersky. I called them mean words (I wasn't mad, I'm just passionate and at the time I was hungry).

https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/
๐Ÿฅฐ50โค10๐Ÿคฃ7๐Ÿ˜6๐Ÿ‘4๐Ÿ˜ข1
> be gamers
> "I DONT TRUST KERNEL MODE ANTI CHEATS!11"
> "ILL NEVER TRUST A VIDEO GAME COMPANY"
> runs anime_waifu_wallpaper.exe as admin
๐Ÿคฃ205๐Ÿ˜16โค8๐Ÿฅฐ6โคโ€๐Ÿ”ฅ2๐Ÿ”ฅ2๐ŸŽ‰1๐Ÿค“1๐Ÿ˜‡1
I'm being CYBER BULLIED on the INTERNET
๐Ÿ˜145๐Ÿคฃ101๐Ÿ˜ฑ12๐Ÿ˜ข10๐Ÿ™8๐Ÿ’ฏ5โค4๐Ÿคฏ3๐Ÿ‘2๐Ÿ˜Ž2โคโ€๐Ÿ”ฅ1
The United Kingdom is ran by a bunch of fucking morons. I mean that wholeheartedly. These stupid fucks think you can "ban" VPNs and think "banning" VPNs will "protect the children".

"Ban" VPNs and watch what happens next.
๐Ÿ˜162๐Ÿคฃ79๐Ÿ’ฏ31โค12๐Ÿ‘6โคโ€๐Ÿ”ฅ5๐Ÿ”ฅ1๐ŸŽ‰1๐Ÿ™1
One of my favorite people in the world is petikvx.

He randomly showed up one day and was like, "Bonjour, j'ai beaucoup de logiciels malveillants."

I said, "I don't speak German, pal".

Then he started giving me a bunch of malware. He is the primary person who does our bulk malware stuff. Everyday he sends me malware. I receive it, sync it with the malware place, and go on about my business.

I checked my chat logs, I haven't spoken to the guy since February, 2026. Before that it was like, July, 2025, yet EVERY SINGLE DAY he is sending me malware.

I barely know the guy. He shows up, he says, "J'aime beaucoup les logiciels malveillants. S'il vous plaรฎt, partagez ce logiciel malveillant avec d'autres personnes.", and that's it.

I don't know his name, I don't know where he works, I don't know how old he is, I literally know almost nothing about the guy.

He doesn't even speak English that well

I fucking love this guy. He is my best friend.
โค246๐Ÿฅฐ35๐Ÿคฃ20๐Ÿ˜17๐Ÿ”ฅ4๐Ÿ˜ข2๐Ÿ˜˜2๐Ÿ‘1
๐Ÿฅฐ194๐Ÿคฃ95โค23๐Ÿซก11๐Ÿ˜7๐Ÿค2๐Ÿ˜ข1
Was thinking about online age verification stuff today

It dawned on me that I've got underwear that is probably 18 years old

Yeah, I'm killing myself tonight
๐Ÿคฃ178๐Ÿ˜21๐Ÿ˜ข13โค11๐Ÿ˜ฑ3๐Ÿ”ฅ1๐Ÿ˜1
Someone DMd me something they received on Discord. They thought it could potentially be malware.

It was malware.

However, it was Electron JS AI slop malware. You can tell because it was easily disassembled and the AI notes were present.

I'm so god damn tired of malware slop
๐Ÿคฃ155โค10๐Ÿ˜5๐Ÿ”ฅ4๐Ÿ’ฏ3๐Ÿฅฐ2๐Ÿ˜ข1
vx-underground
Someone DMd me something they received on Discord. They thought it could potentially be malware. It was malware. However, it was Electron JS AI slop malware. You can tell because it was easily disassembled and the AI notes were present. I'm so god damnโ€ฆ
Interesting, it was undetected virtually everywhere. It was also undetected in a sandbox because it's a bloated piece of shit and has too many dependencies.

The only AVs that detected it from static analysis was Rise and MalwareBytes
๐Ÿค”106๐Ÿ˜26โค6๐Ÿ”ฅ3๐Ÿ˜ข1
Just cancelled my Codex Claude Slop subscription.

I'm running my own AI thingie at home. It'll be cheaper in the long run, it just required a few hardware purchases.
๐Ÿคฃ213โค26๐Ÿ”ฅ13๐Ÿฅฐ5๐Ÿ˜˜2๐Ÿ‘1๐Ÿ‘1๐Ÿ˜ข1๐Ÿค1
It's Father's Day this weekend.

My wife asked what I wanted and the answer was shrimple.

I want to lay in bed and not move for 24 hours. I will only move to urinate, or defecate, or consume the fast food slop I have delivered from Uber Eats.

Let me rot in peace for 1 day.
๐Ÿฅฐ158๐Ÿ˜47๐Ÿซก38๐Ÿ’ฏ18โค11๐Ÿ”ฅ7๐Ÿ‘5๐Ÿ˜ข5๐Ÿค4โคโ€๐Ÿ”ฅ2๐Ÿ˜˜1
โค101๐Ÿค“31๐Ÿ˜15๐Ÿค”7๐Ÿ’ฏ7๐Ÿคฃ5๐Ÿ”ฅ4๐Ÿคฏ3๐Ÿ˜ข1
Dawg, I don't want to sound like a hater, but some of you malware nerds NEED to lock in and TRY HARDER.

Someone found a malicious GitHub repo and DM'd it to me. It had piss poor obfuscation (if you even want to call it that, it's Base64 encoding) and the malware C2 is basically plain text.

The delivery method is masquerading as an Adobe Acrobat plugin? My Brother in Christ, WHAT ARE YOU DOING

The C2 is literally houndsregimeskid-dot-com

Hounds Regime Skid? Hounds Regimes Kid?

Also, for the record, if the people who wrote this malware are reading this: I'm not the guy spamming your Telegram C2. That is someone else. You left all of Telegram channel stuff plain text too
๐Ÿคฃ112๐Ÿฅฐ9โค6๐Ÿ˜ข1
Image 1. Website with uBlock Origin on
Image 2. Website with uBlock Origin off

uBlock Origin IS PREVENTING US FROM FREE MALWARE
๐Ÿคฃ162๐Ÿฅฐ14โค9๐Ÿ˜ข7๐Ÿ˜ฑ6๐Ÿ‘1๐Ÿค”1
vx-underground
Image 1. Website with uBlock Origin on Image 2. Website with uBlock Origin off uBlock Origin IS PREVENTING US FROM FREE MALWARE
I'm torn mentally, physically, and maybe a little bit sexually.

I hate advertisements. On the other hands, I like malware. I don't know what to do. I am forsaken.
โค73๐Ÿคฃ22๐Ÿ˜5๐Ÿค”4๐Ÿ˜ข4๐Ÿฅฐ3๐Ÿ’ฏ2๐Ÿ‘1
> be me
> "smelly is this malware?"
> download file
> file.exe
> click to rename file
> accidentally hit enter
> detonate malware on personal pc

chat, ive accidentally detonated an information stealer on my pc. brb
๐Ÿคฃ219๐Ÿ˜ฑ17โค12๐Ÿฅฐ7๐ŸŽ‰4๐Ÿ˜3๐Ÿ˜ข2โคโ€๐Ÿ”ฅ1
vx-underground
> be me > "smelly is this malware?" > download file > file.exe > click to rename file > accidentally hit enter > detonate malware on personal pc chat, ive accidentally detonated an information stealer on my pc. brb
shout out to salat stealer for having my banking information right now
๐Ÿ˜100๐Ÿคฃ34โค9๐ŸŽ‰6๐Ÿฅฐ5๐Ÿ™3โคโ€๐Ÿ”ฅ1
vx-underground
> be me > "smelly is this malware?" > download file > file.exe > click to rename file > accidentally hit enter > detonate malware on personal pc chat, ive accidentally detonated an information stealer on my pc. brb
What do I do in this scenario?

1. Disconnect from internet
2. Sigh, take a huge rip off my vape
3. Blame the keyboard, not me.
4. Remove the .exe, any persistence mechanism on my machine
5. Angrily reset all my passwords
6. Refuse to use a VM in the future, I'm not a coward
๐Ÿคฃ174๐Ÿ™19โค14๐Ÿฅฐ9๐Ÿ’ฏ6๐Ÿ˜3๐Ÿ˜˜3โคโ€๐Ÿ”ฅ2๐Ÿ‘1๐Ÿ˜ข1
I guess the only thing more embarrassing than accidentally detonating an information stealer payload on your computer, while trying to remove the .exe file extension, is reviewing the payload closer and seeing it comes with cartoon pornography (I've censored it) and an image of a random woman
๐Ÿคฃ164๐Ÿ˜ข12๐Ÿค”10โค7๐Ÿคฏ7๐Ÿ”ฅ4๐Ÿฅฐ3๐Ÿ˜ฑ2๐Ÿ˜‡2๐Ÿ‘1๐Ÿ˜1