vx-underground – Telegram
vx-underground
45.8K subscribers
3.93K photos
418 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
We've received a lot of messages today regarding Lockbit ransomware groups Telegram.

We've been in contact with Lockbit ransomware group and several of their affiliates and subgroups since 2019. Lockbit ransomware group does not have a Telegram.

Lockbit is so paranoid he uses his own onion-based file sharing service. He thinks Telegram, Twitter, virtually all social media, is controlled by governments and refuses to use them.

Also, the account some of you send us named FbiSupp is not the real FBI. We have no idea what or who this account is — but the real FBI Telegram accounts are listed on the United States Department of Justice and Justice for Rewards (operated by the United States Department of State) website. These are imposters.

tl;dr being scammed by fake FBI because ??? and scammed by fake Lockbit because ???
🤣1037🔥5😎4👍2😁2😢1
ShinyHunters, the group (person?) responsible for administrating Breached has disappeared. Breached is offline on both clearnet and Tor

Additionally, Shiny's Telegram and Telegram Channel have been deleted

People are speculating they've been arrested

¯\_(ツ)_/¯
😢63🔥10🤔10🤣53👍2👏2
Meanwhile in the non-cyber security world: graphic design nerds are foaming out the mouth as Adobe slip steams 'your work is now ours' into their agreement checkbox (that you probably don't read)

tl;dr they own whatever you make in their software
🤣92🤯134🤔2
This media is not supported in your browser
VIEW IN TELEGRAM
David Fincher's 1999 cult-classic 'Fight Club', based on the novel written by Charles Palahniuk, has a scene which philosophically reminds us of what we witness every single day in the cyber-ecosystem
56🤣6👍4😢3
Updates to vx-underground:

Samples:
VirusSign.2024.06.02
VirusSign.2024.06.03
VirusSign.2024.06.04
VirusSign.2024.06.05
VirusSign.2024.06.06
VirusSign.2024.06.07
VirusSign.2024.06.08
VirusSign.2024.06.09

Papers:
- 2024-05-10 - Ongoing Social Engineering Campaign Linked to Black Basta Ransomware Operators
- 2024-05-14 - Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain
- 2024-05-14 - QakBot attacks with Windows zero-day (CVE-2024-30051)
- 2024-05-15 - Revealing Spammer Infrastructure With Passive DNS - 226 Toll-Themed Domains Targeting Australia
- 2024-05-15 - Black Basta overview and detection rules
- 2024-05-15 - Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
- 2024-05-15 - To the Moon and back(doors)- Lunar landing in diplomatic missions
- 2024-05-16 - Spring Cleaning with LATRODECTUS: A Potential Replacement for ICEDID
- 2024-05-16 - Springtail: New Linux Backdoor Added to Toolkit
- 2024-05-20 - Tiny BackDoor Goes Undetected: Suspected Turla leveraging MSBuild to Evade detection
- 2024-05-21 - Master of Puppets: Uncovering the DoppelGänger pro-Russian influence campaign
25❤‍🔥9💯5👍3🤯3🤓1
Cybersecurity Among Us sponsored by keepitcloaked this Wednesday, 7 PM EST with h313n_0f_t0r repping vx-underground! We will be unable to stream it ourselves that day, so please enjoy by tuning in to your favorite participating streamer.
🤣619🔥5😢3😱1
vx-underground
Cybersecurity Among Us sponsored by keepitcloaked this Wednesday, 7 PM EST with h313n_0f_t0r repping vx-underground! We will be unable to stream it ourselves that day, so please enjoy by tuning in to your favorite participating streamer.
I was told to tweet this.

I forgot it was a thing because I've been busy downloading malware and staring into the void (Telegram).

Everyone is cool though. Watch it. If you don't you'll be bonked.

- smelly smellington
49🤣8🤓5👍2🔥2😢1🤝1
Thank you to our friends at MDSec Labs for the cool and badass stickers and merch.
76🥰11🔥7👍3👏2😢1🤝1🫡1
In other news, today Lockbit ransomware group posted that someone is conducting a Denial of Service attack via Friend Request's on Tox.

They've allegedly received 200,000 Friend Requests

Neat
👏64😁38🤣14🫡8🤔32
One time we saw a group of people arguing about different ways to perform variable initialization in C vs C++ vs Rust and which language was superior... for 3.5 hours.

All of them had anime profile pictures.
🤣137🔥10😁9👍4👏3😢3🫡1
This media is not supported in your browser
VIEW IN TELEGRAM
Denial of Service via Trebuchet

hashtag red team tips
66👍8❤‍🔥2😢2
This media is not supported in your browser
VIEW IN TELEGRAM
5 years ago we never would have believed we would corrupt the mind, body, and souls of people by nothing but malware and shit posting.

Here we are.
😍102🤣5711👍4🤓2🫡2🤔1😢1💯1😎1
Yesterday evening a website was launched noscript: EpicDB. EpicDB is a hobby project created from a user named "MixV2". The EpicDB website is designed to act similar to SteamDB.

Gaming nerds quickly discovered the EpicDB website began leaking information on games (listed on the site under code names) which are scheduled to arrive on Epic games platform. To the best of our knowledge, no information has been disclosed on how EpicDB gathered these code names.

Confirmed noscripts:
- Dragon Age: The Veilguard
- Helldivers 2 (never released onto Epic)
- Last of Us Part 2
- Apex Legends
- Battlefield 2042
- Tomb Raider Bundle
- Final Fantasy XVI
- Final Fantasy IX
- Remnant 3
- BioShock 4
- Growtopia

Speculated noscripts:
- Rise of the Ronin
- Spider-Man Miles Morales
- Streets of Rage
- Crazy Taxi
- Max Payne 1+2 Remake
- Red Dead Redemption
- DOOM: The Dark Ages
- Doom Eternal
- Bloodlines 2
- Europa Universalis V
- Warhammer: Vermintide 3
- Civilization VI
- Civilization IV
- AtomFall
- Among Us 2

There are nearly 100 code names for unreleased content. We aren't going to list them all. Here are some highlights:

- LaserLemon
- GreenSheen
- Debussy
- Project Wiseguy
- Burger
- Puffpastry
- CurlyWurly
- Croquembouche
🤓379👍6🤣6
This week Xitter will make likes private.

They're being made private for privacy, or something. We don't trust it. No social media platform cares about privacy.
🤓51💯29🤣18👍6🤯2
This media is not supported in your browser
VIEW IN TELEGRAM
Today the Ukrainian National Police arrested a 28 year old man who is suspected to have worked with Conti ransomware group and Lockbit ransomware group.
😢83👍29🫡16😁97🤓4
Happy Birthday to herm1t.

herm1t was the creator and administrator for vxHeaven. vxHeaven was our inspiration — we try to act a successor for.

We hope you have a wonderful day.
😎8934🎉25❤‍🔥8🔥6👍2😢1🤓1🤝1
This media is not supported in your browser
VIEW IN TELEGRAM
A sitcom that follows a group of friends, the up's and down's in the Russian ransomware cyber crime ecosystem, and their ultimate pursuit of love
🔥73🤣52😁5👏32🥰1😢1🤓1😎1
Breached is back, again, again, again, again
🤣137👍13🔥119😁6🤔1😢1
Breached after being taken down multiple times from law enforcement agencies
🤣12511👍2🔥2😢1