vx-underground – Telegram
vx-underground
45.7K subscribers
3.92K photos
416 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Forwarded from Ransomware News (VX)
Group: 8base
Approx. Time: 22:38 11/02/24
Title: LILI'S BROWNIES
😎31🤯9😢92🔥1
We are deeply saddened to share that all of the Twitter bots and/or spam accounts sharing pseudo-pornography in their Twitter bio does NOT deliver malware :(

It just does a bunch of dumb redirects and eventually drops you off on some fake looking dating site
😢160🤣36😁11👍4😎4
We've updated the vx-underground Windows malware paper collection

- 2023-12-21 - InsightEngineering - Advanced Windows Debugging
- 2024-01-06 - Token stealing with Syscalls only
- 2024-01-15 - Undocumented DISM properties
29🔥6👍5😱1🤓1
ALPHV ransomware group has taken credit for attacks on critical infrastructure in the United States and Spain

- 2023-12-18 - Lower Valley Energy, an electricity provider in the United States
- 2024-02-12 - Sercide, an electricity provider in Spain
🔥36👍6🤓5😎53🫡3
We found NATO's Jira access portal online. It said you can request access via the form URL. We have requested access to NATO.
😁175🤣94🫡26👍7🔥7💯6🤓43❤‍🔥1
News outlets are now describing ransomware attacks by mattress size
🤣108😁10🫡6💯52🔥2
This media is not supported in your browser
VIEW IN TELEGRAM
NATO has shutdown access requests forms for their Jira board.
😢159😁35🤣308💯5👍2🥰2🔥1😱1
ALPHV has lost their god damn mind
🤣75🤯22🔥9😎7😱5👍3💯2
NATO Jira creds stolen from an Infostealer 😭😭
🤣126😱8🫡7👍3👏2🎉2🤩2
We've updated the Windows malware paper collection

- 2023-12-24 - Arbitrary Command Execution Via Windows Kit's StandaloneRunner
- 2024-02-12 - Hypervisor enforced security policies for NTOS secure kernel and a child partition
- 2024-02-12 - Why Windows cant follow WSL symlinks
29👍7
We are going to create a new section of vx-underground specifically for archiving criminal activity documentation (rather than technical details).

This portion will archive legal proceedings, court rulings, Threat Intel write ups, etc.
🔥106👍2112🎉5🫡5❤‍🔥3
Lockbit ransomware group terms-of-service states "no healthcare". Then they proceed to allow their affiliates to target healthcare... repeatedly.

Today they decided to ransom a cancer treatment center with locations in Florida and Puerto Rico
😢129👍10🤣7🤩5🤯4💯2🤓2😁1
"Did you guys see my message?"

Want to know how good we are at seeing messages? It took us almost 2 years to reply to someone.

Also, thank you for the sample, RussianPanda. Apologies it only took us 2 years.
🤣1107😢3👍2
tl;dr if we don't reply in like, 3 or 4 days, don't be afraid to try messaging us again. We get a ton of e-mails, DMs, and messages every single day about all sorts of stuff (including people asking for the password, still)
🤣86🤓17👏6🫡3👍2
The first VXUG APT exclusive! 🥰

2024-02-09, the Kazakhstan government reported state-sponsored Threat Actors targeting government officials with sugargh0st malware

Thanks to our friends in Kazakhstan we are the first to share them:)

Check it out here: https://vx-underground.org/APTs/2024/2024.02.09%20-%20SugarGh0st%20RAT%20attacks%20Kazakhstan%20%E2%80%93%20State%20Technical%20Service
❤‍🔥88😎10🔥8👍6
will you be our valentine?
307🥰41❤‍🔥18👍17🤓14😢12😘8😱6🔥5🤔5🤝5
The crime section is now public. It's pretty empty, but it's a work in progress.

Have a nice day

https://vx-underground.org/Crime
👍4717🔥10😎10👏3🤝1