vx-underground – Telegram
vx-underground
45.8K subscribers
3.93K photos
418 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Today following the CSS injection discovered by cloud11665, security researcher vmfunc discovered you can also create ReadMe files which force log people out of their GitHub profiles. Oh, and you can make IP grabbers!

GitHub has now become the wild west
🤩69🔥105🫡4😎4🥰1😢1
This media is not supported in your browser
VIEW IN TELEGRAM
GitHub employees chasing down the nerds who turned their website into nothing but anime, IP grabbers, thread hijacks, and goatse spam... on a Friday night 😂😂😂
🤣148🥰54❤‍🔥2😢2
GitHub has ruined Christmas. The CSS injection has been patched.
😢110🤓9😱71👍1😁1
GitHub CEO Thomas Dohmke realizing if they charged $9.99/month for customizable CSS on GitHub profiles their profit margins would go up %2000
🤣183🤝43👍2😢2
The GitHub CSS Injection which was patched a few hours ago has already been bypassed.

Internet nerds are returning with wrath as they resume anime backgrounds and anime banners

We were asked not to show the bypass code to 340,000 people so it's not patched instantly ¯\_(ツ)_/¯
❤‍🔥73🤣3112😁5😢3🤓1
This media is not supported in your browser
VIEW IN TELEGRAM
Leaked footage of Internet Degenerates and GitHub employees at the Battle of Anime Backgrounds (2024, colorized)
🤣152🫡8😁6🥰3👍2😱2😢2❤‍🔥1
The aftermath of Internet Degenerates vs. GitHub employees at the Battle of Anime Backgrounds.

Photo taken the 8th of June, 2024. Respect to all the anime photos lost in the battle 🙏
85😢19🤣16🫡10🔥7😁2👍1
🤣132❤‍🔥14👍127😁4🤓3💯2😢1
After over 5 years of work, we believe vx-underground is now approaching "maintenance mode" — our work will primarily be keeping content up to date.

tl;dr 1,825 days of work
117😢31🫡30🤯4😱4👍3🔥2🤓2👏1
Hello, we hope all of you had a good week and weekend

Today is the day of rest. We'll see you Monday

Also, to clear up some confusion, we are still going to work on vx-underground, the post about 5 years of work was regarding older material

tl;dr got lots of stuff, feels good
72🫡15👍5🔥4😱1😢1
We've received a lot of messages today regarding Lockbit ransomware groups Telegram.

We've been in contact with Lockbit ransomware group and several of their affiliates and subgroups since 2019. Lockbit ransomware group does not have a Telegram.

Lockbit is so paranoid he uses his own onion-based file sharing service. He thinks Telegram, Twitter, virtually all social media, is controlled by governments and refuses to use them.

Also, the account some of you send us named FbiSupp is not the real FBI. We have no idea what or who this account is — but the real FBI Telegram accounts are listed on the United States Department of Justice and Justice for Rewards (operated by the United States Department of State) website. These are imposters.

tl;dr being scammed by fake FBI because ??? and scammed by fake Lockbit because ???
🤣1037🔥5😎4👍2😁2😢1
ShinyHunters, the group (person?) responsible for administrating Breached has disappeared. Breached is offline on both clearnet and Tor

Additionally, Shiny's Telegram and Telegram Channel have been deleted

People are speculating they've been arrested

¯\_(ツ)_/¯
😢63🔥10🤔10🤣53👍2👏2
Meanwhile in the non-cyber security world: graphic design nerds are foaming out the mouth as Adobe slip steams 'your work is now ours' into their agreement checkbox (that you probably don't read)

tl;dr they own whatever you make in their software
🤣92🤯134🤔2
This media is not supported in your browser
VIEW IN TELEGRAM
David Fincher's 1999 cult-classic 'Fight Club', based on the novel written by Charles Palahniuk, has a scene which philosophically reminds us of what we witness every single day in the cyber-ecosystem
56🤣6👍4😢3
Updates to vx-underground:

Samples:
VirusSign.2024.06.02
VirusSign.2024.06.03
VirusSign.2024.06.04
VirusSign.2024.06.05
VirusSign.2024.06.06
VirusSign.2024.06.07
VirusSign.2024.06.08
VirusSign.2024.06.09

Papers:
- 2024-05-10 - Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators
- 2024-05-14 - Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain
- 2024-05-14 - QakBot attacks with Windows zero-day (CVE-2024-30051)
- 2024-05-15 - Revealing Spammer Infrastructure With Passive DNS - 226 Toll-Themed Domains Targeting Australia
- 2024-05-15 - Black Basta overview and detection rules
- 2024-05-15 - Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
- 2024-05-15 - To the Moon and back(doors)- Lunar landing in diplomatic missions
- 2024-05-16 - Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID
- 2024-05-16 - Springtail: New Linux Backdoor Added to Toolkit
- 2024-05-20 - Tiny BackDoor Goes Undetected: Suspected Turla leveraging MSBuild to Evade detection
- 2024-05-21 - Master of Puppets: Uncovering the DoppelGänger pro-Russian influence campaign
25❤‍🔥9💯5👍3🤯3🤓1
Cybersecurity Among Us sponsored by keepitcloaked this Wednesday, 7 PM EST with h313n_0f_t0r repping vx-underground! We will be unable to stream it ourselves that day, so please enjoy by tuning in to your favorite participating streamer.
🤣619🔥5😢3😱1
vx-underground
Cybersecurity Among Us sponsored by keepitcloaked this Wednesday, 7 PM EST with h313n_0f_t0r repping vx-underground! We will be unable to stream it ourselves that day, so please enjoy by tuning in to your favorite participating streamer.
I was told to tweet this.

I forgot it was a thing because I've been busy downloading malware and staring into the void (Telegram).

Everyone is cool though. Watch it. If you don't you'll be bonked.

- smelly smellington
49🤣8🤓5👍2🔥2😢1🤝1
Thank you to our friends at MDSec Labs for the cool and badass stickers and merch.
76🥰11🔥7👍3👏2😢1🤝1🫡1
In other news, today Lockbit ransomware group posted that someone is conducting a Denial of Service attack via Friend Request's on Tox.

They've allegedly received 200,000 Friend Requests

Neat
👏64😁38🤣14🫡8🤔32