We've broken 300,000 followers on Xitter
Thank you for the love and support.
Cheers to 400,000
Love you♥️
Thank you for the love and support.
Cheers to 400,000
Love you♥️
❤116❤🔥18🤓11🎉6🥰5👏3👍2🤣2🔥1
Good morning,
Several people have asked about an account named 'vxugsupp'. We are not vxugsupp. We do not know who that is. The only staff members from vx-underground on Telegram are @smellyvx (hi, it's me, smelly) and @BradleyVX
Have a nice day. Enjoy the rest of your weekend.
Several people have asked about an account named 'vxugsupp'. We are not vxugsupp. We do not know who that is. The only staff members from vx-underground on Telegram are @smellyvx (hi, it's me, smelly) and @BradleyVX
Have a nice day. Enjoy the rest of your weekend.
👍63😁25🫡11❤8😢3
Comments are disabled again. Channel removed. We underestimated the degeneracy. Nerds flooded the channel faster than we anticipated. It was the great vx-underground temp chat civil war of 2024.
😢172🤣98😁19👍13🫡11🤓9❤3❤🔥3😇3🔥1😎1
Chat has returned with rules in place. Hopefully it works. Comments are also enabled.
Have a nice day.
*Discussion: https://news.1rj.ru/str/+-5FR6GWKqgZhMjMx
Have a nice day.
*Discussion: https://news.1rj.ru/str/+-5FR6GWKqgZhMjMx
❤🔥48🫡19👍5🤣4❤3🤝2
Today RansomHub ransomware group claimed to ransom Frontier Communications. Frontier Communications is a large Internet Service Provider based out of Dallas, Texas.
Frontier Communications confirmed this by submitting a form 8-K to the SEC.
Information via Dominic Alvieri
Frontier Communications confirmed this by submitting a form 8-K to the SEC.
Information via Dominic Alvieri
🤝38🎉9🤣8👍4❤1😢1
April 8th, 2024, a Threat Actor operating under the moniker "USDoD" placed a large database up for sale on Breached noscriptd: "National Public Data". They claimed it contained 2,900,000,000 records on United States citizens. They put the data up for sale for $3,500,000.
National Public Data is a background check and person lookup and verification company located in Coral Springs, Florida. The company offers API data lookups to other companies. In summary – they're a lowkey databroker.
Last week we were informed USDoD intends on leaking the database. We requested a copy in advance to confirm the validity of the data.
We reviewed the massive file – 277.1GB uncompressed, and can confirm the data present in it is real and accurate. We searched up several individuals who consented to having their information looked up.
1. The database DOES NOT contain information from individuals who use data opt-out services. Every person who used some sort of data opt-out service was not present.
2. People who did not use data opt-out services and resided in the United States were immediately found. It showed their:
- First name
- Last name
- Address
- Address history (3 decades+)
- Social security number
It also allowed us to find their parents, and nearest siblings. We were able to identify someones parents, deceased relatives, Uncles, Aunts, and Cousins. Additionally, we can confirm this database also contains information on individuals who are deceased. Some individuals located had been deceased for nearly 2 decades.
National Public Data is a background check and person lookup and verification company located in Coral Springs, Florida. The company offers API data lookups to other companies. In summary – they're a lowkey databroker.
Last week we were informed USDoD intends on leaking the database. We requested a copy in advance to confirm the validity of the data.
We reviewed the massive file – 277.1GB uncompressed, and can confirm the data present in it is real and accurate. We searched up several individuals who consented to having their information looked up.
1. The database DOES NOT contain information from individuals who use data opt-out services. Every person who used some sort of data opt-out service was not present.
2. People who did not use data opt-out services and resided in the United States were immediately found. It showed their:
- First name
- Last name
- Address
- Address history (3 decades+)
- Social security number
It also allowed us to find their parents, and nearest siblings. We were able to identify someones parents, deceased relatives, Uncles, Aunts, and Cousins. Additionally, we can confirm this database also contains information on individuals who are deceased. Some individuals located had been deceased for nearly 2 decades.
❤63🤯40😁7🤓4👍2
vx-underground
April 8th, 2024, a Threat Actor operating under the moniker "USDoD" placed a large database up for sale on Breached noscriptd: "National Public Data". They claimed it contained 2,900,000,000 records on United States citizens. They put the data up for sale for…
Correction: USDoD was a broker and/or middleman for the initial posting. We were instructed to explicitly state that credit for the compromise is to be given to an individual operating under the moniker "SXUL".
👍34🤓11❤9
Today Snowflake, a digital storage provider who was recently surrounded in controversy from the TicketMaster breach, put out a joint statement with both Mandiant and Crowdstrike.
tl;dr Snowflake was not breached
Mandiant and Crowdstrike are both heavy-hitters in the DFIR industry and have worked the largest network compromises on the planet – from ransomware incidents to state sponsored threat actors. So, we applaud Snowflake for hiring not one but two DFIR consulting firms. That is a pretty penny spent and it appears Snowflake took the rumors and speculation very serious. That is cool and badass.
Per the report – although Snowflake was not breached, customers of Snowflake have been a 'trending' target, and some customers failed to follow the recommended best security practices written by Snowflake.
Snowflake, in conjunction with Mandiant and Crowdstrike, identified various customers who may have also been targeted and have notified the customers.
Official statement and more information: https://community.snowflake.com/s/question/0D5VI00000Emyl00AB/detecting-and-preventing-unauthorized-user-access
tl;dr Snowflake was not breached
Mandiant and Crowdstrike are both heavy-hitters in the DFIR industry and have worked the largest network compromises on the planet – from ransomware incidents to state sponsored threat actors. So, we applaud Snowflake for hiring not one but two DFIR consulting firms. That is a pretty penny spent and it appears Snowflake took the rumors and speculation very serious. That is cool and badass.
Per the report – although Snowflake was not breached, customers of Snowflake have been a 'trending' target, and some customers failed to follow the recommended best security practices written by Snowflake.
Snowflake, in conjunction with Mandiant and Crowdstrike, identified various customers who may have also been targeted and have notified the customers.
Official statement and more information: https://community.snowflake.com/s/question/0D5VI00000Emyl00AB/detecting-and-preventing-unauthorized-user-access
Snowflake
Snowflake Community
Join our community of data professionals to learn, connect, share and innovate together
🤝34👍6👏4🤓4❤1🔥1
Hello, how are you?
Today is the day of rest. We hope all of you have had a good week and a good weekend thus far.
Next week we will be updating the archives, adding more papers, and adding more samples.
We'll see you Monday.
Love you ♥️
Today is the day of rest. We hope all of you have had a good week and a good weekend thus far.
Next week we will be updating the archives, adding more papers, and adding more samples.
We'll see you Monday.
Love you ♥️
❤101👍7🤓4🔥1😢1🫡1
Today was not a good day for the day of the rest.
tl;dr
> wake up
> over 9,000 notifications
> wtf.exe
> vx-underground flagged by cloudflare
> wtf we use cloudflare
> cry on xitter
> cloudflare fixes and says sorry
> open the door
> get on the floor
> walk the dinosaur
tl;dr
> wake up
> over 9,000 notifications
> wtf.exe
> vx-underground flagged by cloudflare
> wtf we use cloudflare
> cry on xitter
> cloudflare fixes and says sorry
> open the door
> get on the floor
> walk the dinosaur
❤86😢17🤣16👍8😁6🫡5😎4🤓3🥰1🤔1
vx-underground
Today was not a good day for the day of the rest. tl;dr > wake up > over 9,000 notifications > wtf.exe > vx-underground flagged by cloudflare > wtf we use cloudflare > cry on xitter > cloudflare fixes and says sorry > open the door > get on the floor > walk…
People who understand the meme
🤓37🤣18👏4😁4🔥3👍2🤔1😢1
vx-underground
vx-uwu is back
We do vx-uwu every so often because a few years ago a joke surfaced of a vx-underground member saying "I'm gay". It bothered some people, for whatever reason, so we decided it would be funny to roll with it – be extra gay, cute, anime-uwu, etc, to antagonize them.
tl;dr uwu
tl;dr uwu
❤189🤣25👍17🔥9🤓9🤔8😢6🫡5😱4❤🔥2
Updates to vx-underground
Archives:
- The One New Thing, May 2024
- Builder.Win32.DarkGateLoader.a (unknown variant)
Malware collections:
- Bazaar.2024.05
- InTheWild.0125
- Virussign.2024.06.01
- Virussign.2024.05.31
- Virussign.2024.05.30
- Virussign.2024.05.29
- Virussign.2024.05.28
Papers:
- 2023-02-03 - Threat Actors Abuse AI-Generated Youtube Videos to Spread Stealer Malware
- 2023-05-13 - Mallox affiliate leverages PureCrypter in MS-SQL exploitation campaigns
- 2023-04-26 - Unpacking BellaCiao: A Closer Look at Iran’s Latest Malware
- 2024-01-05 - Tomb Crypter and ChrGetPdsi Stealer Analysis Report (INT00011701)
- 2024-05-13 - Exploring the Depths of SolarMarker's Multi-tiered Infrastructure
- 2024-05-14 - Breaking new ground: Uncovering Akira's privilege escalation techniques
Archives:
- The One New Thing, May 2024
- Builder.Win32.DarkGateLoader.a (unknown variant)
Malware collections:
- Bazaar.2024.05
- InTheWild.0125
- Virussign.2024.06.01
- Virussign.2024.05.31
- Virussign.2024.05.30
- Virussign.2024.05.29
- Virussign.2024.05.28
Papers:
- 2023-02-03 - Threat Actors Abuse AI-Generated Youtube Videos to Spread Stealer Malware
- 2023-05-13 - Mallox affiliate leverages PureCrypter in MS-SQL exploitation campaigns
- 2023-04-26 - Unpacking BellaCiao: A Closer Look at Iran’s Latest Malware
- 2024-01-05 - Tomb Crypter and ChrGetPdsi Stealer Analysis Report (INT00011701)
- 2024-05-13 - Exploring the Depths of SolarMarker's Multi-tiered Infrastructure
- 2024-05-14 - Breaking new ground: Uncovering Akira's privilege escalation techniques
👍34❤12😢1
Administrative announcement:
vx-underground telegram chatroom now has 'vx-underground kitty cat' sticker pack to ensure cat image spamming.
Thanks,
vx-underground telegram chatroom now has 'vx-underground kitty cat' sticker pack to ensure cat image spamming.
Thanks,
❤89❤🔥15👏8🫡5😁4😢4👍2🤝2🤔1
