vx-underground
51K subscribers
4.48K photos
484 videos
84 files
1.56K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
vx-underground
We desperately need someone to update noob malware literature. The shit for malware noobs looks like it was written in 1995 and by someone who doesn't know shit about malware or how it actually works. It reads like someone describing swimming who hasn't…
As an example, if I search "malware intro", the first page is from CISCO. CISCO writes that there is seven different types of malware.

- Virus
- Worm
- Trojan Virus
- Spyware
- Adware
- Ransomware
- Fileless malware

These definitions are too vague, I think a better explanation (although a little bit trickier...)

- Infector
- Stager
- Module
- Stealer
- Spyware
- Ransomware
- Loader
- Toolkit

However, this doesn't accurately capture the nuance of web based malware or IOT and/or ICS/SCADA malware.
❀65πŸ€“26πŸ₯°6πŸ‘3🀣2😒1πŸ’―1
> get dm
> "is this malware?"
> look inside
> malicious libre office macro
> looks funny tho
> raw shellcode
> 2,0,1,187,192,168,45,246
> malware tries connecting to IP address
> 192.168.45.246:443
> malware delivered from a live website

these dumb fucks vibe coded a malware payload and had it connect back to a local ip address. are they actually fucking retarded???
🀣252😁19❀8πŸ”₯8πŸ₯°3πŸŽ‰3😒1πŸ’―1
This malwares c2 is bukkakegrandma
🀣127😁16❀‍πŸ”₯5❀3πŸ₯°3🀯2😒2πŸ€”1πŸ’―1🫑1
I'm pretty impressed. The past four malware goopies people sent me were partially AI slop.

Despite them being AI slop, they were still relatively effective and got the job done.

If AI is helping the noobs, imagine how much it's augmenting the actual skilled Threat Actors
❀61🀣20πŸ’―10πŸ₯°8πŸ‘4πŸ”₯3😒2
Yesterday I was experimenting with using X articles for sharing malware bonkings. People wanted me to be slightly more verbose, primarily out of curiosity.

It was cool. However, for reasons I don't understand, the X algorithm doesn't do much for highlighting articles. I was under the impression they wanted people to write articles. When I used their article thingie my engagement was through the floor.

I don't understand how any of this works.

Regardless, with X articles it isolates the homies on Telegram (they're probably all criminals, I don't know, Telegram nerds are schizos).

Moving forward I'll probably just link to my goofy ass blog. It'll also make it easier for people to find it in the future (if they even care). I'm aiming to make them short, entertaining, and (hopefully) educational.

Thank you to the people who continue to send me free malware. It is cool and badass.
❀99πŸ₯°18❀‍πŸ”₯14😒9πŸ‘6
Hello mystery mini-people living inside of my computer. I want to speak into the void. You probably don't care, but I would like to share something with you.

Today I was hit in pee-pee so hard I thought I was going to die. I've been hit in the pee-pee area before, but this was like ... I was completely incapacitated.

I fell to the ground and began screaming like a sissy. I couldn't breath or move for like, 5 minutes probably. I couldn't breath, my stomach hurt for some reason, my pee-pee area was cramping. I don't know, bro. I've never experienced pain like this.

I got up and limped my soft squishy body to bed. I laid down in bed for over an hour and my pee-pee spot still hurt. It was pulsating, kind of swollen.

I ended up going to the hospital and ended up getting told I've got Testicular Contusion with probable soft tissue damage to my string thingies.

Will I die? No. Was it the most painful oof owie I've ever had in my pee-pee spot? Yes.
😱99🫑43😒19🀣8❀7🀯2πŸ€“1
vx-underground
Hello mystery mini-people living inside of my computer. I want to speak into the void. You probably don't care, but I would like to share something with you. Today I was hit in pee-pee so hard I thought I was going to die. I've been hit in the pee-pee area…
I guess basically what I'm trying to say, if you have testicles, you should not bruise them (contusion). It hurts really, really bad. It will literally ruin your day.
🀯51🫑38😒15πŸ‘4❀2πŸ”₯2πŸŽ‰1🀣1πŸ€“1
> get dm
> "i got malwared, me stuff no good"
> ok send
> sends link
> look inside
> python script
> obfuscated with pyarmor
> using trial version
> lolwtf
> bonk with stick
> spits of goop
> getthem-dot-py
> ???
> look inside
> drops stuff called "nig"
> drops xmr miner
> drops more python scripts
> obfuscated with pyarmor (again)
> bonk with stick
> spits out more goop
> over 10 files
> all the files do p much the same stuff
> ???
> use ai slop machine and tools to get original src
> look inside
> repetitive code
> notes in code
> debug print statements
> sniff sniff
> ai slop

Chat, this is yet another Threat Actor using AI to slop up some malware. The only difference is this Threat Actor used professional level tools (although trial version) and put slightly more effort into the C2 and masquerading stuff.

If you'd like to see the source code I've reconstructed (and slightly more verbose writing), see post below this one.
😁60❀10🀣8πŸ₯°1😒1
> get DM
> "i think i found malware"
> look inside
> fake raonfit (???) website?
> clickfix
> google
> korean fitness stuff?
> check clickfix payload
> powershell script
> downloads rustdesk
> notes present
> ai slop
> all in korean

idk wtf is going on but this is janky af
❀40🀣19πŸ₯°3😒1
I'm a big fan of Windows 11.

One of my favorite features, which really boosts productivity, is the UI crashes (explorer), and whatever UI element was highlighted is now forever stuck in-memory.

"Copy" is stuck in the middle of my screen. I won't go away.

I love it.
🀣114❀21πŸ₯°16πŸ’―3😁2😒2πŸŽ‰1🀩1😘1
A colleague of mine notified me of actual super rare mega fuck off ultra malware identified in the wild.

He said the malware is sophisticated (by my standards) and has proven to be incredibly difficult to reverse engineer. He asked if I felt like trying to bonk it with a stick.

Chat, can I bonk the sophisticated Threat Actor malware with a stick? This malware is believed to originate from a well-known and very active Threat Group, which has posed a significant threat to vendors and consumers, for quite some period of time. Their new malware strain is believed to be augmented by AI, hence improving their malware development lifecycle and introducing enhanced capabilities.

I guess we'll find out later tonight, or tomorrow, when I get a chance to look at it. We'll review it and see if the hype is real, or if it's just malware goop.
❀51πŸ”₯20🫑9πŸ‘5πŸ€”2πŸ’―2
Had a lovely conversation with a Threat Actor from South America.

It turns out, one of the malwares I bonked with a stick was written by someone who follows this social media profile. They confirmed to me in private it was primarily written using ChatGPT.

We had a cool conversation though, last week bro made about $54,000 from his various malware campaigns he spreads on Discord. He was not lying about his "income". Crimes does indeed pay.

He also has a pretty nice computer setup.

We also made small talk about how to illegally immigrate into the United States for as low as $400, problems with money-mules and credit card fraud, and his opinions on other South American countries (he doesn't like Colombia, he says they're not good people).

Overall, bro was pretty chill, despite the large scale identify theft, extortion, money laundering, tax evasion and possibly illegal immigration he does.
❀41🀣36😎7🀝5πŸ₯°4πŸ”₯2😁1🀩1