vx-underground – Telegram
vx-underground
45.7K subscribers
3.93K photos
417 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Today a group named 66slavs claimed to have breached the United States National Energy Research Scientific Computing Center (NERSC).

* We have not reviewed the data
* Yes, they watermarked a data breach
🤣140🎉17🔥10😁54❤‍🔥1
babe wake up mandiant just released artwork for sandworm aka apt44 (officially)
101🤓20🔥16🤣13👍3👏2😱2🫡2🤔1
hacking is illegal and for nerds
🤓205👍20🤣19😱1110🥰9🫡7😢6🔥3😁3🙏2
Yesterday Christopher Ahlberg, the CEO of RecordedFuture, shared information on an unidentified Threat Actor attempting to SMS phish employees at their organization

- This message was not sent to a Nikolas
- Who the hell is Nikolas
🤣113😁8👍6🔥2🤯21😢1
13-year-old Marco Liberale has created a proof-of-concept PasteBin C2 botnet in Go. Is it fully cross platform working on Windows, Linux, and Mac.

We are very happy to see such a young person contributing to this research space.

Check it out here: https://github.com/marco-liberale/PasteBomb
110🤓39🔥11🫡11👏10👍9😇4🤣3❤‍🔥2🤯1🤝1
This media is not supported in your browser
VIEW IN TELEGRAM
feege_ spotted a billboard advertisement on the i-95 in Philadelphia, near the Wells Fargo Center, that says:

"Hackers Suck"
"Protect your business. Cover your assets."
🤣113🤓16👍6😁4😢31🤔1
Hello, how are you? We've updated the vx-underground malware collection. We've added 68,000 new malware samples.

Download the malware.

- Virussign.2024.04.09
- Virussign.2024.04.10
- Virussign.2024.04.11
- Virussign.2024.04.12
- Virussign.2024.04.13
- Virussign.2024.04.14
- Virussign.2024.04.15
- Virussign.2024.04.16
- Virussign.2024.04.17
- InTheWild.0118
- InTheWild.0119

Check it out here: https://vx-underground.org/Samples
20🔥7💯2👍1
Nerds are reporting the new Team Fortress 2 64bit version is being flagged as malware from AV engines.
🤣75😁9🫡8👍1
17 AVs flag the newly released Team Fortress 2 64bit client as malware 😭

SHA256: 83fb94ef1accdc0071ef6221f8e5acf870a1df31ff26e04a8d58116402793911
🫡61😱18🤣7🤔5🎉4👍1
Thank you, Hasherezade for producing these cool and badass hoodies.

PE-BEAR ATE MY MALWAREZ
63🤣12🔥6👍5🤓2🫡1
Malware review:

2024-03-26 - Malware Disguised as Installer from Korean Public Institution (Kimsuky Group)

- Masquerades as installer (0 points)
- Masqueraded installer is not functional (-1 points)
- Dropper is signed (+1 points)
- Drops src.rar (-1 points)
- Password protected with "1q2w3e4r" (-1 points)
- Execution begins with command "installer" (0 points)
- Copies to %USERPROFILE% (0 points)
- Payload masquerades as svchost.exe (0 points)
- Registers itself in Task Scheduler (0 points)
- Masquerades in Task Scheduler as "Windows Backups" (0 points)
- Developed in Go (+1 points)
- Recycled code from previous malware campaign (-1 points)
- Used same signed certificate from previous malware campaign (-1 points)
- Has generic RAT functionality (0 points)
- TA pushed Mimikatz to infected machine (-2 points)
- Mimikatz masqueraded as cache.exe (0 points)
- TA used free Ngrok domain for C2 (-1 points)

We give Kimsuky Group's recent APT campaign an F.

Unoriginal, generic code, some code dependent on external applications (Winrar) which may not be present on victim machines. Password is hardcoded in payload and easily identifiable. Recycled code and recycled certificate is poor design and lazy. Masqueraded installer not working is lazy. Pushing Mimikatz is also a poor decision, this tool is heavily flagged and is a big red flag.
🤣81👏11👍72😢1💯1🫡1
Researcher crocodylii found Hunters International ransomware group left their Tor domain publicly indexable 😭😭😭😭
🤣106👏11🤯6🤔2🎉2🥰1
Someone made us this
❤‍🔥10521🔥16😎10👍9🤔3🤯3😁2🤣2👏1😍1
Following the return of HelloKitty ransomware group (now HelloGookie), the individuals behind HelloKitty ransomware group released more files from CD Projekt Red – the game studio behind The Witcher and Cyberpunk 2077.

Using the leaks nerds have compiled The Witcher III
🥰85🔥17😁9🤓5🎉32👍1
MITRE was compromised

Shout out Charles Clancy for full disclosure and his transparency.
👍82🤣37😱17🫡93👏1