> get dm
> "i got malwared, me stuff no good"
> ok send
> sends link
> look inside
> python script
> obfuscated with pyarmor
> using trial version
> lolwtf
> bonk with stick
> spits of goop
> getthem-dot-py
> ???
> look inside
> drops stuff called "nig"
> drops xmr miner
> drops more python scripts
> obfuscated with pyarmor (again)
> bonk with stick
> spits out more goop
> over 10 files
> all the files do p much the same stuff
> ???
> use ai slop machine and tools to get original src
> look inside
> repetitive code
> notes in code
> debug print statements
> sniff sniff
> ai slop
Chat, this is yet another Threat Actor using AI to slop up some malware. The only difference is this Threat Actor used professional level tools (although trial version) and put slightly more effort into the C2 and masquerading stuff.
If you'd like to see the source code I've reconstructed (and slightly more verbose writing), see post below this one.
> "i got malwared, me stuff no good"
> ok send
> sends link
> look inside
> python script
> obfuscated with pyarmor
> using trial version
> lolwtf
> bonk with stick
> spits of goop
> getthem-dot-py
> ???
> look inside
> drops stuff called "nig"
> drops xmr miner
> drops more python scripts
> obfuscated with pyarmor (again)
> bonk with stick
> spits out more goop
> over 10 files
> all the files do p much the same stuff
> ???
> use ai slop machine and tools to get original src
> look inside
> repetitive code
> notes in code
> debug print statements
> sniff sniff
> ai slop
Chat, this is yet another Threat Actor using AI to slop up some malware. The only difference is this Threat Actor used professional level tools (although trial version) and put slightly more effort into the C2 and masquerading stuff.
If you'd like to see the source code I've reconstructed (and slightly more verbose writing), see post below this one.
π75β€13π€£10π₯°1π’1
vx-underground
> get dm > "i got malwared, me stuff no good" > ok send > sends link > look inside > python script > obfuscated with pyarmor > using trial version > lolwtf > bonk with stick > spits of goop > getthem-dot-py > ??? > look inside > drops stuff called "nig" >β¦
more verbose stuff
https://malwaresourcecode.com/home/my-projects/malware-reversing-shorts/2026-07-22-free-ai-goop-malware-source-code
https://malwaresourcecode.com/home/my-projects/malware-reversing-shorts/2026-07-22-free-ai-goop-malware-source-code
Malwaresourcecode
2026-07-22 - Free AI goop (malware source code) | malware source code
π₯°39β€6π₯4π―3π€£2π’1
> get DM
> "i think i found malware"
> look inside
> fake raonfit (???) website?
> clickfix
> google
> korean fitness stuff?
> check clickfix payload
> powershell script
> downloads rustdesk
> notes present
> ai slop
> all in korean
idk wtf is going on but this is janky af
> "i think i found malware"
> look inside
> fake raonfit (???) website?
> clickfix
> korean fitness stuff?
> check clickfix payload
> powershell script
> downloads rustdesk
> notes present
> ai slop
> all in korean
idk wtf is going on but this is janky af
β€51π€£23π₯°3π’2
vx-underground
> get DM > "i think i found malware" > look inside > fake raonfit (???) website? > clickfix > google > korean fitness stuff? > check clickfix payload > powershell script > downloads rustdesk > notes present > ai slop > all in korean idk wtf is going on butβ¦
Gist
weird korean goop malware ai slop
weird korean goop malware ai slop. GitHub Gist: instantly share code, notes, and snippets.
β€27π€£14π₯°1π’1
I'm a big fan of Windows 11.
One of my favorite features, which really boosts productivity, is the UI crashes (explorer), and whatever UI element was highlighted is now forever stuck in-memory.
"Copy" is stuck in the middle of my screen. I won't go away.
I love it.
One of my favorite features, which really boosts productivity, is the UI crashes (explorer), and whatever UI element was highlighted is now forever stuck in-memory.
"Copy" is stuck in the middle of my screen. I won't go away.
I love it.
π€£152β€23π₯°17π’3π―3π2π€©2π1π1
vx-underground
I'm a big fan of Windows 11. One of my favorite features, which really boosts productivity, is the UI crashes (explorer), and whatever UI element was highlighted is now forever stuck in-memory. "Copy" is stuck in the middle of my screen. I won't go away.β¦
It also overlays other UI elements. This is amazing. Look what I see when I open Telegram
π€£115β€βπ₯8β€4π₯4π₯°4π±2π2
A colleague of mine notified me of actual super rare mega fuck off ultra malware identified in the wild.
He said the malware is sophisticated (by my standards) and has proven to be incredibly difficult to reverse engineer. He asked if I felt like trying to bonk it with a stick.
Chat, can I bonk the sophisticated Threat Actor malware with a stick? This malware is believed to originate from a well-known and very active Threat Group, which has posed a significant threat to vendors and consumers, for quite some period of time. Their new malware strain is believed to be augmented by AI, hence improving their malware development lifecycle and introducing enhanced capabilities.
I guess we'll find out later tonight, or tomorrow, when I get a chance to look at it. We'll review it and see if the hype is real, or if it's just malware goop.
He said the malware is sophisticated (by my standards) and has proven to be incredibly difficult to reverse engineer. He asked if I felt like trying to bonk it with a stick.
Chat, can I bonk the sophisticated Threat Actor malware with a stick? This malware is believed to originate from a well-known and very active Threat Group, which has posed a significant threat to vendors and consumers, for quite some period of time. Their new malware strain is believed to be augmented by AI, hence improving their malware development lifecycle and introducing enhanced capabilities.
I guess we'll find out later tonight, or tomorrow, when I get a chance to look at it. We'll review it and see if the hype is real, or if it's just malware goop.
β€85π₯23π«‘14π5π€2π―2π₯°1π’1π1
Had a lovely conversation with a Threat Actor from South America.
It turns out, one of the malwares I bonked with a stick was written by someone who follows this social media profile. They confirmed to me in private it was primarily written using ChatGPT.
We had a cool conversation though, last week bro made about $54,000 from his various malware campaigns he spreads on Discord. He was not lying about his "income". Crimes does indeed pay.
He also has a pretty nice computer setup.
We also made small talk about how to illegally immigrate into the United States for as low as $400, problems with money-mules and credit card fraud, and his opinions on other South American countries (he doesn't like Colombia, he says they're not good people).
Overall, bro was pretty chill, despite the large scale identify theft, extortion, money laundering, tax evasion and possibly illegal immigration he does.
It turns out, one of the malwares I bonked with a stick was written by someone who follows this social media profile. They confirmed to me in private it was primarily written using ChatGPT.
We had a cool conversation though, last week bro made about $54,000 from his various malware campaigns he spreads on Discord. He was not lying about his "income". Crimes does indeed pay.
He also has a pretty nice computer setup.
We also made small talk about how to illegally immigrate into the United States for as low as $400, problems with money-mules and credit card fraud, and his opinions on other South American countries (he doesn't like Colombia, he says they're not good people).
Overall, bro was pretty chill, despite the large scale identify theft, extortion, money laundering, tax evasion and possibly illegal immigration he does.
β€123π€£105π17π₯°8π€5π₯4π3π1π1π€―1π€©1
I keep having noobs message me and call me a hacker and ask about computer exploitation
Dawg, I am NOT a hacker, I'm not memeing either.
I can write malware, reverse engineer malware, bonk stuff with sticks. But, if you asked me to move laterally in a network it would take me 6000 hours.
Likewise, I know nothing about web exploitation. I couldn't compromise a website if you gave me the username and password
I'm just stinky malware man, I am not cool and badass hacker man.
Dawg, I am NOT a hacker, I'm not memeing either.
I can write malware, reverse engineer malware, bonk stuff with sticks. But, if you asked me to move laterally in a network it would take me 6000 hours.
Likewise, I know nothing about web exploitation. I couldn't compromise a website if you gave me the username and password
I'm just stinky malware man, I am not cool and badass hacker man.
β€117π€31π9β€βπ₯7π₯°7π€£7π«‘2π₯1π’1π1π1
vx-underground
A colleague of mine notified me of actual super rare mega fuck off ultra malware identified in the wild. He said the malware is sophisticated (by my standards) and has proven to be incredibly difficult to reverse engineer. He asked if I felt like trying toβ¦
> wake up
> take a shit
> get out of bed
> remember colleagues hardcore malware thingie
> download
> look inside
> confused.mp4
> regular .exe, but has .exe inside of it
> bonk with stick
> .exe inside of it is the same .exe
> .exe has itself inside of itself
> only small difference
> cant tell difference
> confusion_intensifies.mp5
> has anti-vm code
> cant get to work in emulation
> written using delphi
> delphi tform GUI thingy
> weird af de-compilation
> 16,000 functions present
> most do basic stuff, like add or subtract
> staticly links a bunch of random libraries
> LOLWTF WHO WROTE THIS
> bonk with really big stick
> eventually find some good goop
> new .exe randomly appears in-memory
> ???
> grab from memory
> c++ .exe, staticly linked
> 500 functions
> heavily obfuscated
> has anti-code tampering in place
> ???
> this in-memory .exe references 1st .exe goop
> ask colleague about goop
> "We discovered this Threat Actor likely created their own custom .exe encryptor and decryptor"
I've been bonking this malware with a stick for over an hour, I think, maybe two hours. I've been able to grab an in-memory mapped PE file which the original .exe loads into memory. However, I am unable to determine precisely where this PE file is mapped exactly because it's a Delphi TForm application, its statically linked, and is intentionally obfuscated.
This secondary .exe loaded into memory has tamper protection, patching it to force itself to give me more malware won't be easy. This binary also has anti-VM features as well, I think from calculating disk space. However, I can't tell right now either, but this is what it appears like based on the API it imports.
1. Delphi TForm application
2. Does stuff, lots of junk
3. Maps secondary PE into memory (somehow)
4. Secondary PE does recon to assess the machine
5. ???
Somewhere in the midst of this, this binary is going to make an external call, somewhere, somehow, but it's proven to be difficult due to how obfuscated this code is, coupled with the custom PE cryptor, decoy data present, ... and everything else.
Initially I was under the impression one of the obvious .EXEs I saw was the actual secondary payload, but it's not (I think?), it appears to be a decoy (I think).
I don't know who wrote this, but this is probably one of the most sophisticated malware payloads I've seen in recent time.
It has successfully evaded my VM, RecordedFuture Triage, VirusTotal VM, and AnyRun
I still don't know what this malware is trying to do.
> take a shit
> get out of bed
> remember colleagues hardcore malware thingie
> download
> look inside
> confused.mp4
> regular .exe, but has .exe inside of it
> bonk with stick
> .exe inside of it is the same .exe
> .exe has itself inside of itself
> only small difference
> cant tell difference
> confusion_intensifies.mp5
> has anti-vm code
> cant get to work in emulation
> written using delphi
> delphi tform GUI thingy
> weird af de-compilation
> 16,000 functions present
> most do basic stuff, like add or subtract
> staticly links a bunch of random libraries
> LOLWTF WHO WROTE THIS
> bonk with really big stick
> eventually find some good goop
> new .exe randomly appears in-memory
> ???
> grab from memory
> c++ .exe, staticly linked
> 500 functions
> heavily obfuscated
> has anti-code tampering in place
> ???
> this in-memory .exe references 1st .exe goop
> ask colleague about goop
> "We discovered this Threat Actor likely created their own custom .exe encryptor and decryptor"
I've been bonking this malware with a stick for over an hour, I think, maybe two hours. I've been able to grab an in-memory mapped PE file which the original .exe loads into memory. However, I am unable to determine precisely where this PE file is mapped exactly because it's a Delphi TForm application, its statically linked, and is intentionally obfuscated.
This secondary .exe loaded into memory has tamper protection, patching it to force itself to give me more malware won't be easy. This binary also has anti-VM features as well, I think from calculating disk space. However, I can't tell right now either, but this is what it appears like based on the API it imports.
1. Delphi TForm application
2. Does stuff, lots of junk
3. Maps secondary PE into memory (somehow)
4. Secondary PE does recon to assess the machine
5. ???
Somewhere in the midst of this, this binary is going to make an external call, somewhere, somehow, but it's proven to be difficult due to how obfuscated this code is, coupled with the custom PE cryptor, decoy data present, ... and everything else.
Initially I was under the impression one of the obvious .EXEs I saw was the actual secondary payload, but it's not (I think?), it appears to be a decoy (I think).
I don't know who wrote this, but this is probably one of the most sophisticated malware payloads I've seen in recent time.
It has successfully evaded my VM, RecordedFuture Triage, VirusTotal VM, and AnyRun
I still don't know what this malware is trying to do.
β€105π€―44π₯19π₯°6π5π€4π2π±2π―2π’1
This super ultra mega rare fuck off ultra malware my colleague sent me has a really fancy schmancy anti-VM feature. It is the fanciest I've seen to date. I like it.
After bonking this goop with a stick, sifting through dummy and decoy data, I figured out how they evaded my VM, RecordedFuture Triage, AnyRun, and VirusTotal.
They made a really fancy entropy thingie by collecting a bunch of data and doing fancy math.
I respect it.
https://gist.github.com/vxunderground/b8accc6e05d956889e0282e1926a6feb
After bonking this goop with a stick, sifting through dummy and decoy data, I figured out how they evaded my VM, RecordedFuture Triage, AnyRun, and VirusTotal.
They made a really fancy entropy thingie by collecting a bunch of data and doing fancy math.
I respect it.
https://gist.github.com/vxunderground/b8accc6e05d956889e0282e1926a6feb
Gist
fancy schmancy antivm
fancy schmancy antivm. GitHub Gist: instantly share code, notes, and snippets.
π33π€―29β€17π₯11π₯°3π€3π2π’1
πBAKING π
I had a ton of people ask me about the super cool and badass malware sample my beloved colleague sent me. I also had a ton of people me to share more details on it.
Here are some FAQ:
1. What does it do?
It's an Information Stealer, but it's super fancy
2. Does it have a name?
Yes, as of like, last Tuesday (I have no idea when it was named, I'm just talking shit). It's officially called RevStealer by my peers. There is limited information it at the moment.
3. How long have you been bonking it?
I invested about 4 hours over the time span of a few days, I think. I wish I had more free time for bonkings, but I don't
4. Can you share it?
Yes, I am sharing it now. I'm pushing it to prod now. It's under /Samples/Families/RevStealer. I encourage you to bonk it too. It's really cool and fun to explore. I haven't had enough time to explore it and appreciate it, but I enjoyed it.
5. Can you share hashes?
Initial .zip:
251aa2b0831d88a6f796bb6ca01d0242c11476b2fc6a5baa3f9c64a9134cd61d
Stage 1 (packer, stager): d23b9609b06ab23243543ee0d8ff0d4c1966530576fa37bb2ecde97309ebbc9e
Stage 2 (in-memory payload):
724b400afcec2064a3477abd9a117103abfb51f7f7c8acd9c429fcdabd656ffc
Decoy (maybe?):
851383fb22dcb1d16367839178271eef6504199b8ca60405e1698879696e49d4
6. Who is it attributed to?
I have no idea. My colleagues have speculations, but nothing is solid yet.
Pic unrelated (or maybe it is).
I had a ton of people ask me about the super cool and badass malware sample my beloved colleague sent me. I also had a ton of people me to share more details on it.
Here are some FAQ:
1. What does it do?
It's an Information Stealer, but it's super fancy
2. Does it have a name?
Yes, as of like, last Tuesday (I have no idea when it was named, I'm just talking shit). It's officially called RevStealer by my peers. There is limited information it at the moment.
3. How long have you been bonking it?
I invested about 4 hours over the time span of a few days, I think. I wish I had more free time for bonkings, but I don't
4. Can you share it?
Yes, I am sharing it now. I'm pushing it to prod now. It's under /Samples/Families/RevStealer. I encourage you to bonk it too. It's really cool and fun to explore. I haven't had enough time to explore it and appreciate it, but I enjoyed it.
5. Can you share hashes?
Initial .zip:
251aa2b0831d88a6f796bb6ca01d0242c11476b2fc6a5baa3f9c64a9134cd61d
Stage 1 (packer, stager): d23b9609b06ab23243543ee0d8ff0d4c1966530576fa37bb2ecde97309ebbc9e
Stage 2 (in-memory payload):
724b400afcec2064a3477abd9a117103abfb51f7f7c8acd9c429fcdabd656ffc
Decoy (maybe?):
851383fb22dcb1d16367839178271eef6504199b8ca60405e1698879696e49d4
6. Who is it attributed to?
I have no idea. My colleagues have speculations, but nothing is solid yet.
Pic unrelated (or maybe it is).
π₯°18π₯8β€5