vx-underground – Telegram
vx-underground
45.7K subscribers
3.93K photos
418 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
vx-underground
If we had to guess, we assume famous American rapper Meek Mill is conveying his frustration with ransomware groups. Unfortunately, what MeekMill does not know, is it is going to take more than a private detective (or 100's) to dismantle ransomware groups.…
Update: the is not about ransomware, or cyber attacks in the traditional sense, Mr. Meek Mill's frustration derives from a recent leak which some people allege him to be a homosexual

¯\_(ツ)_/¯
🤣172😘13👏4😇2
We have a lot of updates for vx-underground.

Unfortunately, these updates have not been pushed because we're in the middle of a galactic war (for democracy) and are actively trying to liberate Meridia from Terminids
🫡76🤣105👍4👏2
Good morning, and welcome to your daily dose of internet-true-crime-drama

tl;dr nerds think ALPHV is doing exit scam, ALPHV blames FBI

March 3rd an ALPHV affiliate went onto RAMP and claimed that ALPHV administrative staff scammed them. They alleged they were responsible for the attack against Change Healthcare and, when trying to log into their panel, noticed their ALPHV affiliate account was suspended. To show proof of this they shared an alleged ALPHV wallet. Researchers believe Change Healthcare paid $22,000,000. Change Healthcare has not publicly confirmed or denied paying the ransom. ALPHV administration displayed a status online saying "Everything is off, we decide". Shortly after it was changed to "GG" - 'Good Game'.

Later on, on March 4th, "Affiliate Plus" ALPHV account holders expressed frustration that their accounts were suddenly closed - unable to perform their ransomware attacks. They claimed ALPHV administrative staff was ignoring them.

Later, later, later on March 4th, ALPHV administrative staff relayed an ambiguous message. They stated that the United States Federal Bureau of Investigation was responsible (for ???). We are not sure if they are saying the RAMP post was the FBI, trying to damage their reputation, or if ALPHV administrative staff is claiming the FBI intentionally attacked American critical infrastructure.

Later, later, later, later on March 4th, ALPHV put the source code to ALPHV ransomware for sale for $5,000,000.

Today, March 5th, the ALPHV domain shows an FBI seizure message. However, researchers have indicated that the HTML source code looks suspicious and they believe this is a phony FBI seizure page. There has not been any official announcement from the United States Department of Justice to confirm or deny this seizure notice on the ALPHV domain.
🤓71🤣27🤔158🤯7😁4👍3😱2🤝2
We have seen the rise and fall of REvil, HIVE, Conti, and ALPHV. Will Lockbit ransomware group be able to deter law enforcement agencies? Will a new ransomware group arrive to fill the vaccuum left by the other Titan's falling?

Find out on the next episode of Dragon Ball Z
🤣174😁27👏15😢98🤩1
There are rumors of a DDoS attack against social media giant Meta (formerly Facebook). We don't know if it's true. However, as is tradition, we just assume it to be a DNS issue.

Cheers
🤣190👍21😁7❤‍🔥6🫡6💯3😎1
Just saw a large group of people, probably age 55+, on Twitter angrily tagging Joe Biden and blaming him for Facebook and Instagram having connectivity issues.

The internet is cool and badass
🤣221😁13👍97🫡7👏3😘3😢2🔥1
We've made some updates to vx-underground

- The Old New Thing for February, 2024
- MyloBot
- Stealc
- Truebot
- zgRAT
- Remcos
- QakBot
- RedLine
- Pikabot
- LilithBot
- ParadiseRansomware
- Bandook
- Android.HookBot
- Atharvan
- AgentTesla
- Android.Coper
👍32🔥94🎉2😍1
Woke up this morning to an individual informing us they compromised a penis medical implant website
🤣181🔥32😁21🎉63🤔3🤩3😍2👍1🙏1😇1
We've updated the VXUG malware collection

- Bazaar.2024.02
- Virussign.2024.02.28
- Virussign.2024.02.29
- Virussign.2024.03.01
- Virussign.2024.03.02
- Virussign.2024.03.03
- Virussign.2024.03.04
- Virussign.2024.03.05
- InTheWild.0112
- InTheWild.0113

71,000+ new samples
28😘16👍9🤝1
Microsoft has discovered nobody actually wanted to install Uber Eats and micro-transaction-pay-to-win mobile games on their desktop computer

RIP Windows Subsystem for Android
2021-10-20 - 2025-03-05
🤣136😁56😢21👍8😱65🎉4🫡4🤔1🤓1
whoever decided to implement SecureBoot for Windows OS' should be thrown out of a helicopter while they're kicking and screaming
💯127🤣559🤓8🔥4😢4🤔2😁1
We continue to receive hateful remarks from individuals because of the vx-uwu logo - most notably we are called 'trannies' and are told to 'kys'.

Dorks terrified of vx-uwu colors and anime
🤣242❤‍🔥15😁8🫡76😢6🤔5🔥4👍2🤓1
Russia-based Cyber Threat Intelligence firms have an APT name designated for the United States government: Sand Eagle
🔥72🤣28😎14👍53👏3😱3❤‍🔥2🥰1
Russia-based Cyber Threat Intelligence firms do not list Lockbit or Babuk ransomware group as financially motivated or state-sponsored Threat Actors - they're tools. See attached image #3 for list of known ransomware groups 🤔🤔🤔🤔
🤔73😁9🥰5👍32❤‍🔥2😱2
In the entire document Lockbit is noted 7 times, Conti is listed 4 times, ALPHV is never mentioned. There references to Lockbit are often looked over as a note, not really described in detail. They're seen as 'encryption programs'.
🤣45🤔251