vx-underground
The kids are making anti government surveillance memes and I love it.
If this were a meme made by someone in my age group it would be something like, "how I walk when I have hemorrhoids"
π€£143π₯13π10β€7π₯°4π―4π±2π€2β€βπ₯1π€―1π’1
Administrative update:
1. I am going to begin the process of thanking people for malware submissions and/or papers and/or recommendations. They will be placed somewhere on the website. You can exaggerate yourself on LinkedIn and say you're a collaborator.
2. I have a large volume of malware papers and malwares in queue. It is 175,000 malwares, 20 or so papers. As is tradition, malware analysis will be coupled with the papers too. That is expanded every month as new material comes in.
3. I have no plans to resurrect the virus exchange for the time being, unless someone (preferably a large company) is willing to bank roll the entire thing. I can provide the malware goopies, but computers are expensive.
4. Per request from OG vx-underground nerds, in more serious posts discussing technical topics, I will drop the silly cats and instead revive the classic edgy vx-underground dark. I will introduce a balance between seriousness, and edgy Hot Topic Goth, and generate kitty cat stuff.
Thank you everyone for the love and support. I see your messages and e-mails. I am enjoying the summer with my son and family, so I am simply less inside at the moment. I will (hopefully) do more malwares soon.
1. I am going to begin the process of thanking people for malware submissions and/or papers and/or recommendations. They will be placed somewhere on the website. You can exaggerate yourself on LinkedIn and say you're a collaborator.
2. I have a large volume of malware papers and malwares in queue. It is 175,000 malwares, 20 or so papers. As is tradition, malware analysis will be coupled with the papers too. That is expanded every month as new material comes in.
3. I have no plans to resurrect the virus exchange for the time being, unless someone (preferably a large company) is willing to bank roll the entire thing. I can provide the malware goopies, but computers are expensive.
4. Per request from OG vx-underground nerds, in more serious posts discussing technical topics, I will drop the silly cats and instead revive the classic edgy vx-underground dark. I will introduce a balance between seriousness, and edgy Hot Topic Goth, and generate kitty cat stuff.
Thank you everyone for the love and support. I see your messages and e-mails. I am enjoying the summer with my son and family, so I am simply less inside at the moment. I will (hopefully) do more malwares soon.
β€121π₯°12π’10π₯9
vx-underground
Administrative update: 1. I am going to begin the process of thanking people for malware submissions and/or papers and/or recommendations. They will be placed somewhere on the website. You can exaggerate yourself on LinkedIn and say you're a collaborator.β¦
Oh, I forgot. One other thing.
I had a few people say I should focus more on news. People said using keywords like "breaking" can improve engagement and potentially bring more people to this social media account.
I appreciate the insight, feedback, and thoughtfulness. However, I am very much ... I don't know the word ... I guess I don't really give a fuck bro. Yes, people and monies and stuff is cool, but I don't want to be a slop account. I'm just going to continue doing what I'm doing.
Malware source code, samples, and papers for free, forever.
Cheers
I had a few people say I should focus more on news. People said using keywords like "breaking" can improve engagement and potentially bring more people to this social media account.
I appreciate the insight, feedback, and thoughtfulness. However, I am very much ... I don't know the word ... I guess I don't really give a fuck bro. Yes, people and monies and stuff is cool, but I don't want to be a slop account. I'm just going to continue doing what I'm doing.
Malware source code, samples, and papers for free, forever.
Cheers
π₯°127β€35π₯12β€βπ₯7π3π€£3π’1π1
Hello, People Living Inside My Computer (PLIMC),
If you're someone who enjoys malware, I have good news.
If you're someone who dislikes malware, I have bad news.
I have uploaded 176,000 malwares and some malware papers. Please download it.
https://vx-underground.org/Updates
If you're someone who enjoys malware, I have good news.
If you're someone who dislikes malware, I have bad news.
I have uploaded 176,000 malwares and some malware papers. Please download it.
https://vx-underground.org/Updates
β€88π₯16π6π±6π’4β€βπ₯1π1
> be me
> havent taken malware inventory in a long time
> lol how much malware do i actually have?
> usually estimate 32,000,000-ish
> look inside
Argus Collection (archived): 24,830
ATM Malware (archived): 285
Bazaar (actively collected): 733,985
Families (retired): 122,888
InTheWild (actively collected): 8,195,377
Malware Analysis (actively collected): 53,746
Malware Ingestion (retired): 7,511,822
OpenSourceMalware (archived): 40
Twitter IOC Collection (archived): 40,324
VirusShare (actively collected): 23,775,600
VirusSign (actively collected): 1,786,542
Total malwares: 42,225,439
Total archives (7z files): 128,786
Total size: 12.9TB (7z ultra compressed)
Time performed collecting malware: 2,618 days
> havent taken malware inventory in a long time
> lol how much malware do i actually have?
> usually estimate 32,000,000-ish
> look inside
Argus Collection (archived): 24,830
ATM Malware (archived): 285
Bazaar (actively collected): 733,985
Families (retired): 122,888
InTheWild (actively collected): 8,195,377
Malware Analysis (actively collected): 53,746
Malware Ingestion (retired): 7,511,822
OpenSourceMalware (archived): 40
Twitter IOC Collection (archived): 40,324
VirusShare (actively collected): 23,775,600
VirusSign (actively collected): 1,786,542
Total malwares: 42,225,439
Total archives (7z files): 128,786
Total size: 12.9TB (7z ultra compressed)
Time performed collecting malware: 2,618 days
β€105π«‘49π₯13π€£13π3π’1π1
vx-underground
Found a compromised website with ClickFix that successfully bypasses uBlock. The ClickFix payload uses LOLBINs and uses a WebDAV server. It was promising. The C2 is dead. YOU LIED TO ME
Wait, no. The C2 domain changed and the C2 blocked my IP.
Give me your goopies.
Give me your goopies.
π₯113π₯°19π12β€8π€―3π―3π«‘2β€βπ₯1π€1π’1
> be me
> sleepin good
> hear wife scream
> ???
> throws open bedroom door
> "I NEED HELP"
> ???
> get up
> run into living room
> baby boy took off diaper
> pooped on floor
> stepped on poop
> poopy foot prints all over house
> sleepin good
> hear wife scream
> ???
> throws open bedroom door
> "I NEED HELP"
> ???
> get up
> run into living room
> baby boy took off diaper
> pooped on floor
> stepped on poop
> poopy foot prints all over house
π€£206π±44π«‘26β€6π₯°5π€―4π2β€βπ₯1
We desperately need someone to update noob malware literature.
The shit for malware noobs looks like it was written in 1995 and by someone who doesn't know shit about malware or how it actually works.
It reads like someone describing swimming who hasn't ever been in a pool
The shit for malware noobs looks like it was written in 1995 and by someone who doesn't know shit about malware or how it actually works.
It reads like someone describing swimming who hasn't ever been in a pool
π€£79β€18π₯°8π₯3π―3π’1
vx-underground
We desperately need someone to update noob malware literature. The shit for malware noobs looks like it was written in 1995 and by someone who doesn't know shit about malware or how it actually works. It reads like someone describing swimming who hasn'tβ¦
As an example, if I search "malware intro", the first page is from CISCO. CISCO writes that there is seven different types of malware.
- Virus
- Worm
- Trojan Virus
- Spyware
- Adware
- Ransomware
- Fileless malware
These definitions are too vague, I think a better explanation (although a little bit trickier...)
- Infector
- Stager
- Module
- Stealer
- Spyware
- Ransomware
- Loader
- Toolkit
However, this doesn't accurately capture the nuance of web based malware or IOT and/or ICS/SCADA malware.
- Virus
- Worm
- Trojan Virus
- Spyware
- Adware
- Ransomware
- Fileless malware
These definitions are too vague, I think a better explanation (although a little bit trickier...)
- Infector
- Stager
- Module
- Stealer
- Spyware
- Ransomware
- Loader
- Toolkit
However, this doesn't accurately capture the nuance of web based malware or IOT and/or ICS/SCADA malware.
β€68π€26π₯°6π3π€£2π’1π―1
> get dm
> "is this malware?"
> look inside
> malicious libre office macro
> looks funny tho
> raw shellcode
> 2,0,1,187,192,168,45,246
> malware tries connecting to IP address
> 192.168.45.246:443
> malware delivered from a live website
these dumb fucks vibe coded a malware payload and had it connect back to a local ip address. are they actually fucking retarded???
> "is this malware?"
> look inside
> malicious libre office macro
> looks funny tho
> raw shellcode
> 2,0,1,187,192,168,45,246
> malware tries connecting to IP address
> 192.168.45.246:443
> malware delivered from a live website
these dumb fucks vibe coded a malware payload and had it connect back to a local ip address. are they actually fucking retarded???
π€£256π19β€8π₯8π₯°3π3π’1π―1
vx-underground
> get dm > "is this malware?" > look inside > malicious libre office macro > looks funny tho > raw shellcode > 2,0,1,187,192,168,45,246 > malware tries connecting to IP address > 192.168.45.246:443 > malware delivered from a live website these dumb fucksβ¦
this is the malware equivalent of saying check out my website and linking 127.0.0.1
π€£133β€12π₯°7π4π3π3π1
I'm pretty impressed. The past four malware goopies people sent me were partially AI slop.
Despite them being AI slop, they were still relatively effective and got the job done.
If AI is helping the noobs, imagine how much it's augmenting the actual skilled Threat Actors
Despite them being AI slop, they were still relatively effective and got the job done.
If AI is helping the noobs, imagine how much it's augmenting the actual skilled Threat Actors
β€65π€£20π―10π₯°8π4π₯3π’3
Yesterday I was experimenting with using X articles for sharing malware bonkings. People wanted me to be slightly more verbose, primarily out of curiosity.
It was cool. However, for reasons I don't understand, the X algorithm doesn't do much for highlighting articles. I was under the impression they wanted people to write articles. When I used their article thingie my engagement was through the floor.
I don't understand how any of this works.
Regardless, with X articles it isolates the homies on Telegram (they're probably all criminals, I don't know, Telegram nerds are schizos).
Moving forward I'll probably just link to my goofy ass blog. It'll also make it easier for people to find it in the future (if they even care). I'm aiming to make them short, entertaining, and (hopefully) educational.
Thank you to the people who continue to send me free malware. It is cool and badass.
It was cool. However, for reasons I don't understand, the X algorithm doesn't do much for highlighting articles. I was under the impression they wanted people to write articles. When I used their article thingie my engagement was through the floor.
I don't understand how any of this works.
Regardless, with X articles it isolates the homies on Telegram (they're probably all criminals, I don't know, Telegram nerds are schizos).
Moving forward I'll probably just link to my goofy ass blog. It'll also make it easier for people to find it in the future (if they even care). I'm aiming to make them short, entertaining, and (hopefully) educational.
Thank you to the people who continue to send me free malware. It is cool and badass.
β€105π₯°19β€βπ₯14π’9π6
Hello mystery mini-people living inside of my computer. I want to speak into the void. You probably don't care, but I would like to share something with you.
Today I was hit in pee-pee so hard I thought I was going to die. I've been hit in the pee-pee area before, but this was like ... I was completely incapacitated.
I fell to the ground and began screaming like a sissy. I couldn't breath or move for like, 5 minutes probably. I couldn't breath, my stomach hurt for some reason, my pee-pee area was cramping. I don't know, bro. I've never experienced pain like this.
I got up and limped my soft squishy body to bed. I laid down in bed for over an hour and my pee-pee spot still hurt. It was pulsating, kind of swollen.
I ended up going to the hospital and ended up getting told I've got Testicular Contusion with probable soft tissue damage to my string thingies.
Will I die? No. Was it the most painful oof owie I've ever had in my pee-pee spot? Yes.
Today I was hit in pee-pee so hard I thought I was going to die. I've been hit in the pee-pee area before, but this was like ... I was completely incapacitated.
I fell to the ground and began screaming like a sissy. I couldn't breath or move for like, 5 minutes probably. I couldn't breath, my stomach hurt for some reason, my pee-pee area was cramping. I don't know, bro. I've never experienced pain like this.
I got up and limped my soft squishy body to bed. I laid down in bed for over an hour and my pee-pee spot still hurt. It was pulsating, kind of swollen.
I ended up going to the hospital and ended up getting told I've got Testicular Contusion with probable soft tissue damage to my string thingies.
Will I die? No. Was it the most painful oof owie I've ever had in my pee-pee spot? Yes.
π±104π«‘46π’21π€£9β€8π€―2π1π€1
vx-underground
Hello mystery mini-people living inside of my computer. I want to speak into the void. You probably don't care, but I would like to share something with you. Today I was hit in pee-pee so hard I thought I was going to die. I've been hit in the pee-pee areaβ¦
I guess basically what I'm trying to say, if you have testicles, you should not bruise them (contusion). It hurts really, really bad. It will literally ruin your day.
π€―55π«‘41π’15π4β€2π₯2π1π€£1π€1
> get dm
> "i got malwared, me stuff no good"
> ok send
> sends link
> look inside
> python script
> obfuscated with pyarmor
> using trial version
> lolwtf
> bonk with stick
> spits of goop
> getthem-dot-py
> ???
> look inside
> drops stuff called "nig"
> drops xmr miner
> drops more python scripts
> obfuscated with pyarmor (again)
> bonk with stick
> spits out more goop
> over 10 files
> all the files do p much the same stuff
> ???
> use ai slop machine and tools to get original src
> look inside
> repetitive code
> notes in code
> debug print statements
> sniff sniff
> ai slop
Chat, this is yet another Threat Actor using AI to slop up some malware. The only difference is this Threat Actor used professional level tools (although trial version) and put slightly more effort into the C2 and masquerading stuff.
If you'd like to see the source code I've reconstructed (and slightly more verbose writing), see post below this one.
> "i got malwared, me stuff no good"
> ok send
> sends link
> look inside
> python script
> obfuscated with pyarmor
> using trial version
> lolwtf
> bonk with stick
> spits of goop
> getthem-dot-py
> ???
> look inside
> drops stuff called "nig"
> drops xmr miner
> drops more python scripts
> obfuscated with pyarmor (again)
> bonk with stick
> spits out more goop
> over 10 files
> all the files do p much the same stuff
> ???
> use ai slop machine and tools to get original src
> look inside
> repetitive code
> notes in code
> debug print statements
> sniff sniff
> ai slop
Chat, this is yet another Threat Actor using AI to slop up some malware. The only difference is this Threat Actor used professional level tools (although trial version) and put slightly more effort into the C2 and masquerading stuff.
If you'd like to see the source code I've reconstructed (and slightly more verbose writing), see post below this one.
π72β€13π€£9π₯°1π’1
vx-underground
> get dm > "i got malwared, me stuff no good" > ok send > sends link > look inside > python script > obfuscated with pyarmor > using trial version > lolwtf > bonk with stick > spits of goop > getthem-dot-py > ??? > look inside > drops stuff called "nig" >β¦
more verbose stuff
https://malwaresourcecode.com/home/my-projects/malware-reversing-shorts/2026-07-22-free-ai-goop-malware-source-code
https://malwaresourcecode.com/home/my-projects/malware-reversing-shorts/2026-07-22-free-ai-goop-malware-source-code
Malwaresourcecode
2026-07-22 - Free AI goop (malware source code) | malware source code
π₯°39β€6π₯4π―3π€£2π’1
> get DM
> "i think i found malware"
> look inside
> fake raonfit (???) website?
> clickfix
> google
> korean fitness stuff?
> check clickfix payload
> powershell script
> downloads rustdesk
> notes present
> ai slop
> all in korean
idk wtf is going on but this is janky af
> "i think i found malware"
> look inside
> fake raonfit (???) website?
> clickfix
> korean fitness stuff?
> check clickfix payload
> powershell script
> downloads rustdesk
> notes present
> ai slop
> all in korean
idk wtf is going on but this is janky af
β€50π€£22π₯°3π’2