Hello, how are you?
Today is the day of rest. We hope all of you have had a good week and a good weekend thus far.
Next week we will be updating the archives, adding more papers, and adding more samples.
We'll see you Monday.
Love you ♥️
Today is the day of rest. We hope all of you have had a good week and a good weekend thus far.
Next week we will be updating the archives, adding more papers, and adding more samples.
We'll see you Monday.
Love you ♥️
❤101👍7🤓4🔥1😢1🫡1
Today was not a good day for the day of the rest.
tl;dr
> wake up
> over 9,000 notifications
> wtf.exe
> vx-underground flagged by cloudflare
> wtf we use cloudflare
> cry on xitter
> cloudflare fixes and says sorry
> open the door
> get on the floor
> walk the dinosaur
tl;dr
> wake up
> over 9,000 notifications
> wtf.exe
> vx-underground flagged by cloudflare
> wtf we use cloudflare
> cry on xitter
> cloudflare fixes and says sorry
> open the door
> get on the floor
> walk the dinosaur
❤86😢17🤣16👍8😁6🫡5😎4🤓3🥰1🤔1
vx-underground
Today was not a good day for the day of the rest. tl;dr > wake up > over 9,000 notifications > wtf.exe > vx-underground flagged by cloudflare > wtf we use cloudflare > cry on xitter > cloudflare fixes and says sorry > open the door > get on the floor > walk…
People who understand the meme
🤓37🤣18👏4😁4🔥3👍2🤔1😢1
vx-underground
vx-uwu is back
We do vx-uwu every so often because a few years ago a joke surfaced of a vx-underground member saying "I'm gay". It bothered some people, for whatever reason, so we decided it would be funny to roll with it – be extra gay, cute, anime-uwu, etc, to antagonize them.
tl;dr uwu
tl;dr uwu
❤189🤣25👍17🔥9🤓9🤔8😢6🫡5😱4❤🔥2
Updates to vx-underground
Archives:
- The One New Thing, May 2024
- Builder.Win32.DarkGateLoader.a (unknown variant)
Malware collections:
- Bazaar.2024.05
- InTheWild.0125
- Virussign.2024.06.01
- Virussign.2024.05.31
- Virussign.2024.05.30
- Virussign.2024.05.29
- Virussign.2024.05.28
Papers:
- 2023-02-03 - Threat Actors Abuse AI-Generated Youtube Videos to Spread Stealer Malware
- 2023-05-13 - Mallox affiliate leverages PureCrypter in MS-SQL exploitation campaigns
- 2023-04-26 - Unpacking BellaCiao: A Closer Look at Iran’s Latest Malware
- 2024-01-05 - Tomb Crypter and ChrGetPdsi Stealer Analysis Report (INT00011701)
- 2024-05-13 - Exploring the Depths of SolarMarker's Multi-tiered Infrastructure
- 2024-05-14 - Breaking new ground: Uncovering Akira's privilege escalation techniques
Archives:
- The One New Thing, May 2024
- Builder.Win32.DarkGateLoader.a (unknown variant)
Malware collections:
- Bazaar.2024.05
- InTheWild.0125
- Virussign.2024.06.01
- Virussign.2024.05.31
- Virussign.2024.05.30
- Virussign.2024.05.29
- Virussign.2024.05.28
Papers:
- 2023-02-03 - Threat Actors Abuse AI-Generated Youtube Videos to Spread Stealer Malware
- 2023-05-13 - Mallox affiliate leverages PureCrypter in MS-SQL exploitation campaigns
- 2023-04-26 - Unpacking BellaCiao: A Closer Look at Iran’s Latest Malware
- 2024-01-05 - Tomb Crypter and ChrGetPdsi Stealer Analysis Report (INT00011701)
- 2024-05-13 - Exploring the Depths of SolarMarker's Multi-tiered Infrastructure
- 2024-05-14 - Breaking new ground: Uncovering Akira's privilege escalation techniques
👍34❤12😢1
Administrative announcement:
vx-underground telegram chatroom now has 'vx-underground kitty cat' sticker pack to ensure cat image spamming.
Thanks,
vx-underground telegram chatroom now has 'vx-underground kitty cat' sticker pack to ensure cat image spamming.
Thanks,
❤89❤🔥15👏8🫡5😁4😢4👍2🤝2🤔1
Today on 4chan someone leaked internal documents from Club Penguin.
It is 137 documents which include product planning, proof-of-concepts, internal e-mails, and some documents on other projects such as Tron.
All of the material appears dated, it is probably valuable to lost media nerds.
It is 137 documents which include product planning, proof-of-concepts, internal e-mails, and some documents on other projects such as Tron.
All of the material appears dated, it is probably valuable to lost media nerds.
❤104🤣24🔥18🙏8😁2👍1
Yesterday it was announced that IKEA is launching a virtual Roblox store. They're seeking Roblox players to work in the Roblox IKEA store. Must be 18+
Location: Fully remote
Schedule: Flexible
Pay: £13.15 / €14.80
Employment type: Contract
Details: https://thecoworker.co.uk/
Location: Fully remote
Schedule: Flexible
Pay: £13.15 / €14.80
Employment type: Contract
Details: https://thecoworker.co.uk/
🤣100🤔8🤓4👍3❤2😢1
This media is not supported in your browser
VIEW IN TELEGRAM
🤣147😁12❤5❤🔥4👍3😢2😎1
tl;dr don't read TikTok dms ¯\_(ツ)_/¯
Today is was announced an unknown Threat Actor(s) had discovered an exploit in TikTok which allows users to hijack accounts.
Details are scarce – however it has been noted that the payload (as it is being described) is delivered through TikTok direct messages. The payload is executed when the direct message is read. However, it does not require any external files be executed, the user does not need to respond to the message, etc.
No details have been unveiled on whether or not this is platform specific (i.e. Android or iOS).
The unknown Threat Actor(s) have compromised Paris Hilton, CNN, and Sony. It is claimed other high-profile and/or celebrity accounts have been compromised, but no other 'high-profile' accounts have been disclosed other than the ones previously noted. The TikTok security team is aware of the issue and has confirmed the legitimacy of the exploit with Forbes.
TikTok representatives stated to Forbes that a small number of users were compromised. No exact numbers were given. TikTok representatives have not stated if the exploit is still valid, how users can protect themselves, or what the attackers have done with the compromised accounts.
Today is was announced an unknown Threat Actor(s) had discovered an exploit in TikTok which allows users to hijack accounts.
Details are scarce – however it has been noted that the payload (as it is being described) is delivered through TikTok direct messages. The payload is executed when the direct message is read. However, it does not require any external files be executed, the user does not need to respond to the message, etc.
No details have been unveiled on whether or not this is platform specific (i.e. Android or iOS).
The unknown Threat Actor(s) have compromised Paris Hilton, CNN, and Sony. It is claimed other high-profile and/or celebrity accounts have been compromised, but no other 'high-profile' accounts have been disclosed other than the ones previously noted. The TikTok security team is aware of the issue and has confirmed the legitimacy of the exploit with Forbes.
TikTok representatives stated to Forbes that a small number of users were compromised. No exact numbers were given. TikTok representatives have not stated if the exploit is still valid, how users can protect themselves, or what the attackers have done with the compromised accounts.
💯49❤9👍8👏4🤣4🔥3🤯1
vx-underground
tl;dr don't read TikTok dms ¯\_(ツ)_/¯ Today is was announced an unknown Threat Actor(s) had discovered an exploit in TikTok which allows users to hijack accounts. Details are scarce – however it has been noted that the payload (as it is being described)…
Full article and source: https://www.forbes.com/sites/emilybaker-white/2024/06/04/a-zero-day-tiktok-hack-is-taking-over-celebrity-and-brand-accounts/?sh=621c6d4c6060
Forbes
A Zero Day TikTok Hack Is Taking Over Celebrity And Brand Accounts
The compromised accounts include CNN and Paris Hilton — and all users have to do to be hacked is open a DM.
❤31👍5👏4🤔1
May 31st the United States Marine corp released information on a new program to improve Cyber Security Specialist and Signals Intelligence enlistments.
The Marine corp can now enroll someone up to an E-7 rank, with the highest being E-9, based on education and experience.
Interested participants must still pass basic training and meet standard fitness requirements.
The pay for an E-7 rank is $43,500 annually.
Alternatively, individuals with backgrounds in cyber security can apply for jobs in the private sector and make $150,000 - $750,000 based on education and experience, while also being able to work remotely, not wear a uniform, not have to do basic training, and not be stationed on a base.
The Marine corp can now enroll someone up to an E-7 rank, with the highest being E-9, based on education and experience.
Interested participants must still pass basic training and meet standard fitness requirements.
The pay for an E-7 rank is $43,500 annually.
Alternatively, individuals with backgrounds in cyber security can apply for jobs in the private sector and make $150,000 - $750,000 based on education and experience, while also being able to work remotely, not wear a uniform, not have to do basic training, and not be stationed on a base.
🤓87🤣70🫡14❤🔥9👍4😁3💯3❤2🥰2😢2😎1
> wake up
> check news
> more ransomware attacks against critical infra
> more problems found in microsoft recall
> more malware campaign findings shared
> more company databases leak
> more twitter dm spam
> check news
> more ransomware attacks against critical infra
> more problems found in microsoft recall
> more malware campaign findings shared
> more company databases leak
> more twitter dm spam
💯97🫡19❤10🤣6🔥4🤓4👍2👏1😢1
