vx-underground
> get dm on telegram > forget to reply > check vxug email today > 3,200+ emails > all different emails > all compromised emails > all calling me the n word > asking to reply on telegram Chat, I'm no doctor, but I think this person wants me to reply
> get another email
> "hello, my name is ___, some hacker got into my email, idk how. im really sorry about the n word stuff"
> "hello, my name is ___, some hacker got into my email, idk how. im really sorry about the n word stuff"
π€£244β€25π17π4β€βπ₯2π’2π±1π1
No goop bonking tonight
Some fucking dumbass drunk driver crashed into a telephone pole, a few blocks don't have electricity now
I want to punch this dude in the face
Some fucking dumbass drunk driver crashed into a telephone pole, a few blocks don't have electricity now
I want to punch this dude in the face
π€£108π39π’21π18β€4π₯4π«‘3π1π1
vx-underground
No goop bonking tonight Some fucking dumbass drunk driver crashed into a telephone pole, a few blocks don't have electricity now I want to punch this dude in the face
Who the fuck is driving drunk on a Thursday anyway? Who is this guy???
π€£138π€23β€8π₯4π―4π2π«‘2
WELL, IT SURE IS STRANGE how so many of my colleagues have all SUDDENLY decided to start doing ALT+0147 (β) and of course the ALT+0148 (β). Did I miss the memo? Is this the new standard? Because I could have SWORN we all did SHIFT + ' (") for literally forever.
I didn't even know how to do these fucking quotes, or the name of them (curly open quote and curly close quote), I had to look it up.
It's so odd... I can't figure out how THEY ALL learned the easy to remember ALT+0147 and ALT+0148 when we have SHIFT+' right next to our ENTER key.
SURE IS STRANGE HUH? TOTAL COINCIDENCE.
I didn't even know how to do these fucking quotes, or the name of them (curly open quote and curly close quote), I had to look it up.
It's so odd... I can't figure out how THEY ALL learned the easy to remember ALT+0147 and ALT+0148 when we have SHIFT+' right next to our ENTER key.
SURE IS STRANGE HUH? TOTAL COINCIDENCE.
π€£155π21β€14π±5π₯3π2π€1π’1
vx-underground
WELL, IT SURE IS STRANGE how so many of my colleagues have all SUDDENLY decided to start doing ALT+0147 (β) and of course the ALT+0148 (β). Did I miss the memo? Is this the new standard? Because I could have SWORN we all did SHIFT + ' (") for literally forever.β¦
Also, I have THOUSANDS of malware analysis and malware development write-ups. It is soooo weird how SUDDENLY so many of these new write-ups have a summary with something named like "Why this matters".
Hmmmmmmmmmmmmmmm
Hmmmmmmmmmmmmmmm
π―87π€£52π22π€6β€3π’1π€1
This media is not supported in your browser
VIEW IN TELEGRAM
> be me
> get dm
> "smelly i found goop"
> wtf i love goop (malware)
> sends like to GitHub
> download
> look inside .zip
> instantly, at the blink of an eye, i recognize it
> SmartLoader
every single time, without fail, this is precisely how the SmartLoder malware campaign works
> find random github repo
> kind of popular
> make identical github but with typo or smth
> make "download" button link to .zip
> .zip contains EXACTLY 4 files
> launcher.bat, lua51.dll, *.exe, *.txt
> tell user to run .bat
> .bat tells .exe to read .txt
> .exe is lua engine thingie
> .txt is obfuscated lua
> always uses Prometheus obfuscator
> always uses ETH smart contracts for c2 stuff
I've had so many various SmartLoader campaigns sent to me I can smell the stink off of it from a mile away. The SPLIT SECOND they tell me something like, "haha ya it was a github kind of like the one i wanted" i IMMEDIATELY KNOW its fucking SmartLoader
> get dm
> "smelly i found goop"
> wtf i love goop (malware)
> sends like to GitHub
> download
> look inside .zip
> instantly, at the blink of an eye, i recognize it
> SmartLoader
every single time, without fail, this is precisely how the SmartLoder malware campaign works
> find random github repo
> kind of popular
> make identical github but with typo or smth
> make "download" button link to .zip
> .zip contains EXACTLY 4 files
> launcher.bat, lua51.dll, *.exe, *.txt
> tell user to run .bat
> .bat tells .exe to read .txt
> .exe is lua engine thingie
> .txt is obfuscated lua
> always uses Prometheus obfuscator
> always uses ETH smart contracts for c2 stuff
I've had so many various SmartLoader campaigns sent to me I can smell the stink off of it from a mile away. The SPLIT SECOND they tell me something like, "haha ya it was a github kind of like the one i wanted" i IMMEDIATELY KNOW its fucking SmartLoader
π₯81β€23π’9π6
My stinky degenerate nerds, I'm begging of you, some of you need to get a grip (key weird some, not all, don't go ooga booga on me)
Every now and then I see some booger eater getting mad because when I do my dumb little malware posts I do:
> be me
Instead of
>be me
They get angry I insert a space.
Dawg, I know the standard image board etiquette is to not insert a space. I've seen the comments. I was a teenager on 4chan when people were asking if you like Mudkips.
I'm not doing an actual "greentext". I'm doing a silly write up with a 4chan like influence that also acts as a bulletin system, like a summary, or something.
Get a grip my guy. It's going to be okay.
Have a silly picture of a cat to clam your nerves
Every now and then I see some booger eater getting mad because when I do my dumb little malware posts I do:
> be me
Instead of
>be me
They get angry I insert a space.
Dawg, I know the standard image board etiquette is to not insert a space. I've seen the comments. I was a teenager on 4chan when people were asking if you like Mudkips.
I'm not doing an actual "greentext". I'm doing a silly write up with a 4chan like influence that also acts as a bulletin system, like a summary, or something.
Get a grip my guy. It's going to be okay.
Have a silly picture of a cat to clam your nerves
π―98π€£47β€11β€βπ₯3π€―3π’2π±1π€1π1
Post attempt number four. I'm sorry to people who have notifications enabled and keep receiving notifications.
tl;dr this is active goop, i am sharing the link because someone asked for Lua goop, but if you visit the GitHub it's not my fault if you download the .zip and accidentally run it (itll steal all your sensitive documents and passwords hehe)
Someone asked where the Lua goop was, this is the Lua goop I discussed earlier today. This GitHub profile is an active (updated 9 hours ago) SmartLoader malware campaign.
The repository "MicVST" masquerades as a legitimate open-source solution. However, the "How to Install" section in the ReadMe links to a .zip file which is the SmartLoader payload.
The .zip contains Launcher.bat which executes the *.exe and tells the *.exe to read the *.txt. The *.txt file is obfuscated Lua which is piped into the *.exe. The *.exe is a Lua VM.
This profile has been active on GitHub for about 3 months completely undetected. The SmartLoader campaign resolves an additional secondary GitHub page which acts as a configuration file for the SmartLoader payload, instructing it what to do.
https://github.com/tenrececaudatusarmour182
tl;dr this is active goop, i am sharing the link because someone asked for Lua goop, but if you visit the GitHub it's not my fault if you download the .zip and accidentally run it (itll steal all your sensitive documents and passwords hehe)
Someone asked where the Lua goop was, this is the Lua goop I discussed earlier today. This GitHub profile is an active (updated 9 hours ago) SmartLoader malware campaign.
The repository "MicVST" masquerades as a legitimate open-source solution. However, the "How to Install" section in the ReadMe links to a .zip file which is the SmartLoader payload.
The .zip contains Launcher.bat which executes the *.exe and tells the *.exe to read the *.txt. The *.txt file is obfuscated Lua which is piped into the *.exe. The *.exe is a Lua VM.
This profile has been active on GitHub for about 3 months completely undetected. The SmartLoader campaign resolves an additional secondary GitHub page which acts as a configuration file for the SmartLoader payload, instructing it what to do.
https://github.com/tenrececaudatusarmour182
GitHub
tenrececaudatusarmour182 - Overview
tenrececaudatusarmour182 has one repository available. Follow their code on GitHub.
β€31π₯4π’1
vx-underground
Post attempt number four. I'm sorry to people who have notifications enabled and keep receiving notifications. tl;dr this is active goop, i am sharing the link because someone asked for Lua goop, but if you visit the GitHub it's not my fault if you downloadβ¦
This is this particular SmartLoader payloads configuration GitHub. This link is safe to view. It is very silly.
ae.log is the configuration SmartLoader uses.
dec.log I couldn't figure out. It looks like it has another .exe inside of it encrypted and encoded as ASCII, but I stopped caring.
https://github.com/yawalinte
ae.log is the configuration SmartLoader uses.
dec.log I couldn't figure out. It looks like it has another .exe inside of it encrypted and encoded as ASCII, but I stopped caring.
https://github.com/yawalinte
GitHub
yawalinte - Overview
yawalinte has one repository available. Follow their code on GitHub.
β€24π6π₯1π’1
BREAKING: NEW AI MODELS CONFIRM THE COW GO MOO MOO AND DUCK GOES QUACK QUACK
AI EXPERTS MEETING MONDAY TO DISCUSS WHAT THIS MEANS
AI EXPERTS MEETING MONDAY TO DISCUSS WHAT THIS MEANS
π€£156β€20π±15π7π€―5π€2π―2π’1π1π€1
vx-underground
BREAKING: NEW AI MODELS CONFIRM THE COW GO MOO MOO AND DUCK GOES QUACK QUACK AI EXPERTS MEETING MONDAY TO DISCUSS WHAT THIS MEANS
UPDATE: NEW DETAILS EMERGING THIS DISCOVERY WAS DONE BY A SINGLE MAN IN A REMOTE CABIN IN MAINE. IT ONLY COST HIM $36,000,000 IN TOKENS AND ENOUGH ELECTRICITY TO POWER NEW YORK CITY FOR 11,000 YEARS
β€86π€£49π€―20π₯9π―6π±5β€βπ₯1π€1π’1π1
Working on my first ever video on goop (malware) reverse engineering and analysis.
It is extremely ghetto, has lots of filler photos with pictures of cats I have saved on my desktop as I explain some concepts.
I also don't have a fancy mic, a fancy machine, ... or anything really.
My video is trying to be as short and condensed as possible, with no filler and no absurd explanations on every tiny detail of Windows internals.
I want to get to the point as fast as possible, assume the watcher understands what's going on, and if they don't they can try to learn themselves, ask questions, or just appreciate how silly the malware is.
The malware being bonked in the video is from a random DM I received. It is ordinary malware people come across in the wild. I want it to be as authentic as possible.
When I share it in the next couple of days, let me know what you think. I am well aware it not nearly as polished as pro YouTube nerds (I don't want to be a pro YouTube nerd).
I've never made a video before, it seemed kind of like a fun thingie to try, and there is a sort of demand for it from my audience... so whatever dawg, fuck it, we ball.
It is extremely ghetto, has lots of filler photos with pictures of cats I have saved on my desktop as I explain some concepts.
I also don't have a fancy mic, a fancy machine, ... or anything really.
My video is trying to be as short and condensed as possible, with no filler and no absurd explanations on every tiny detail of Windows internals.
I want to get to the point as fast as possible, assume the watcher understands what's going on, and if they don't they can try to learn themselves, ask questions, or just appreciate how silly the malware is.
The malware being bonked in the video is from a random DM I received. It is ordinary malware people come across in the wild. I want it to be as authentic as possible.
When I share it in the next couple of days, let me know what you think. I am well aware it not nearly as polished as pro YouTube nerds (I don't want to be a pro YouTube nerd).
I've never made a video before, it seemed kind of like a fun thingie to try, and there is a sort of demand for it from my audience... so whatever dawg, fuck it, we ball.
β€169π₯28π6β€βπ₯2π2π€―2π2π’1π1
vx-underground
Working on my first ever video on goop (malware) reverse engineering and analysis. It is extremely ghetto, has lots of filler photos with pictures of cats I have saved on my desktop as I explain some concepts. I also don't have a fancy mic, a fancy machineβ¦
And if it sucks, and we all hate it and think to focus on something else, it's all good too. It's fun to fuck around and try new things.
Video editing is so god damn boring though bro, holy cannoli
Anyway, let's see what happens.
Video editing is so god damn boring though bro, holy cannoli
Anyway, let's see what happens.
β€105π₯°11π―7β€βπ₯3π’1
For several months now I've been slowly, but surely, working behind the scenes to dramatically enhance vx-underground.
I still don't have a definitive timeline, but I would like to share some stuff coming.
1. All source code will be moved from GitHub to vx-underground. The new vx-underground will have functionality to search through code bases by keywords for research, filter by language type, yada yada yada.
2. Enhanced malware paper searching. It'll be easier to search for stuff now.
3. API access to verified individuals. This is designed for researchers, or organizations, who may want the ability to perform large downloads programmatically.
4. Paid tier. vx-underground will remain free for everyone. However, if you're an organization which makes more than $1,000,000/year you will have to pay for some functionality (malware sample API downloads). I will not charge thousands of dollars, I'm not greedy, but some of you large companies are jerks and need to pay up for scraping the site for AI and samples. API access will be free for individual researchers, small businesses, students, non-profits, and government institutions. Unfortunately, I've learned the hard way large for-profit organizations will not donate.
5. I've heard your complaints for YEARS. We are looking for a HTML-only vx-underground implementation, probably as a subdomain or something. I'm well aware you hardcore nerds hate JavaScript. I will continue investigating this.
6. We're working on our 4th book, Black Mass Volume IV.
I have more to announce, but some details are still up in the air. These changes likely won't appear until ... I don't know, bro. I've got a full time job and a family. I'm thinking probably late 2026, early 2027.
Thank you to our donors and sponsors that make this possible. I'm not as speedy as I used to be with updates, but I'm still cooking.
Cheers
-smelly
I still don't have a definitive timeline, but I would like to share some stuff coming.
1. All source code will be moved from GitHub to vx-underground. The new vx-underground will have functionality to search through code bases by keywords for research, filter by language type, yada yada yada.
2. Enhanced malware paper searching. It'll be easier to search for stuff now.
3. API access to verified individuals. This is designed for researchers, or organizations, who may want the ability to perform large downloads programmatically.
4. Paid tier. vx-underground will remain free for everyone. However, if you're an organization which makes more than $1,000,000/year you will have to pay for some functionality (malware sample API downloads). I will not charge thousands of dollars, I'm not greedy, but some of you large companies are jerks and need to pay up for scraping the site for AI and samples. API access will be free for individual researchers, small businesses, students, non-profits, and government institutions. Unfortunately, I've learned the hard way large for-profit organizations will not donate.
5. I've heard your complaints for YEARS. We are looking for a HTML-only vx-underground implementation, probably as a subdomain or something. I'm well aware you hardcore nerds hate JavaScript. I will continue investigating this.
6. We're working on our 4th book, Black Mass Volume IV.
I have more to announce, but some details are still up in the air. These changes likely won't appear until ... I don't know, bro. I've got a full time job and a family. I'm thinking probably late 2026, early 2027.
Thank you to our donors and sponsors that make this possible. I'm not as speedy as I used to be with updates, but I'm still cooking.
Cheers
-smelly
β€71β€βπ₯18π«‘7π₯6π4π€―1π’1