vx-underground – Telegram
vx-underground
45.8K subscribers
3.93K photos
419 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
In other news, today Lockbit ransomware group posted that someone is conducting a Denial of Service attack via Friend Request's on Tox.

They've allegedly received 200,000 Friend Requests

Neat
👏64😁38🤣14🫡8🤔32
One time we saw a group of people arguing about different ways to perform variable initialization in C vs C++ vs Rust and which language was superior... for 3.5 hours.

All of them had anime profile pictures.
🤣137🔥10😁9👍4👏3😢3🫡1
This media is not supported in your browser
VIEW IN TELEGRAM
Denial of Service via Trebuchet

hashtag red team tips
66👍8❤‍🔥2😢2
This media is not supported in your browser
VIEW IN TELEGRAM
5 years ago we never would have believed we would corrupt the mind, body, and souls of people by nothing but malware and shit posting.

Here we are.
😍102🤣5711👍4🤓2🫡2🤔1😢1💯1😎1
Yesterday evening a website was launched noscript: EpicDB. EpicDB is a hobby project created from a user named "MixV2". The EpicDB website is designed to act similar to SteamDB.

Gaming nerds quickly discovered the EpicDB website began leaking information on games (listed on the site under code names) which are scheduled to arrive on Epic games platform. To the best of our knowledge, no information has been disclosed on how EpicDB gathered these code names.

Confirmed noscripts:
- Dragon Age: The Veilguard
- Helldivers 2 (never released onto Epic)
- Last of Us Part 2
- Apex Legends
- Battlefield 2042
- Tomb Raider Bundle
- Final Fantasy XVI
- Final Fantasy IX
- Remnant 3
- BioShock 4
- Growtopia

Speculated noscripts:
- Rise of the Ronin
- Spider-Man Miles Morales
- Streets of Rage
- Crazy Taxi
- Max Payne 1+2 Remake
- Red Dead Redemption
- DOOM: The Dark Ages
- Doom Eternal
- Bloodlines 2
- Europa Universalis V
- Warhammer: Vermintide 3
- Civilization VI
- Civilization IV
- AtomFall
- Among Us 2

There are nearly 100 code names for unreleased content. We aren't going to list them all. Here are some highlights:

- LaserLemon
- GreenSheen
- Debussy
- Project Wiseguy
- Burger
- Puffpastry
- CurlyWurly
- Croquembouche
🤓379👍6🤣6
This week Xitter will make likes private.

They're being made private for privacy, or something. We don't trust it. No social media platform cares about privacy.
🤓51💯29🤣18👍6🤯2
This media is not supported in your browser
VIEW IN TELEGRAM
Today the Ukrainian National Police arrested a 28 year old man who is suspected to have worked with Conti ransomware group and Lockbit ransomware group.
😢83👍29🫡16😁97🤓4
Happy Birthday to herm1t.

herm1t was the creator and administrator for vxHeaven. vxHeaven was our inspiration — we try to act a successor for.

We hope you have a wonderful day.
😎8934🎉25❤‍🔥8🔥6👍2😢1🤓1🤝1
This media is not supported in your browser
VIEW IN TELEGRAM
A sitcom that follows a group of friends, the up's and down's in the Russian ransomware cyber crime ecosystem, and their ultimate pursuit of love
🔥73🤣52😁5👏32🥰1😢1🤓1😎1
Breached is back, again, again, again, again
🤣137👍13🔥119😁6🤔1😢1
Breached after being taken down multiple times from law enforcement agencies
🤣12511👍2🔥2😢1
People are paying thousands of dollars for educational courses on initial access vectors. We'll provide you a step-by-step guide on how to get initial access to companies with a budget of $0. All it requires is some time, effort, and the ability to grep

1. Go to Telegram
2. Get free stealer logs
3. Look for VPN creds
4. Hope no MFA
4.a If MFA, spam requests
4.b If fails, go back to Step 1.
5. Log into VPN
6. Go to Jira / Kanban board
7. Scrape everything when people are sleeping
8. Log out
9. ???
10. Profit!!!11

Congratulations, you're now the most dangerous hacker on the planet

Does this sound absurd? Of course it does. Does it work? Yes, literally every single day. Infostealers are a giant problem. They don't need to target enterprise environments with top-notch security – they only need to target lazy home users, with security settings probably disabled, downloading junk binaries.
👍11335😁24🥰7🔥3❤‍🔥2👏2🤓2😢1🎉1🤣1
The current state of the vx-underground Telegram chatroom
🤣14037💯7😁4🎉3🔥2😢2
Media is too big
VIEW IN TELEGRAM
😭😭😭😭
🤣59🫡8😢3🤓21
Updates to vx-underground

Samples:
- AcidRain
- AgentTesla
- Android.SoumniBot
- AveMaria
- GuLoader
- LummaStealer
- NjRat
- PikaBot
- QakBot
- Rawdoor
- Remcos
- SystemBC
- Upstyle
- Vultur
- zLoader

Papers:
- 2024-06-06 - Remcos RAT Analysis
- 2024-06-06 - Agent Tesla Analysis
- 2024-06-03 - Wineloader – Analysis of the Infection Chain
- 2024-06-03 - PikaBot: a Guide to its Deep Secrets and Operations
- 2024-05-30 - A DNS Investigation of the Phobos Ransomware 8Base Attack
- 2024-05-29 - Fake Browser Updates delivering BitRAT and Lumma Stealer
❤‍🔥25👍5😘53😢1
This media is not supported in your browser
VIEW IN TELEGRAM
🤣131🤯26🫡9😱54👍4💯4🔥3🤔2😢1
Good morning,

People are not seeding the vx-underground torrents. You nerds asked for torrents, so you better seed.

>:(

https://vx-underground.org/Torrents
😁51😢29💯8🫡63🤔3👍2
BSides Colorado Springs is looking for people to submit papers and talks – especially beginner and/or intermediate malware talks.

They're trying to grow. Go to BSides Colorado Springs, submit a talk, do stuff, and fight bears
👍5616🔥9🫡4😢1
Updates to vx-underground

- 2021-12-23 - Threat Report: Echelon Malware Detected in Mobile Chat Forums
- 2023-01-22 - BadBazaar: iOS and Android Surveillanceware by China’s APT15 Used to Target Tibetans and Uyghurs
- 2023-02-23 - Berbew Backdoor Spotted In The Wild
- 2023-09-26 - Analyzing Lu0Bot: A Node.js Malware with Near-Unlimited Capabilities
- 2023-12-01 - New Tool Set Found Used Against Organizations in the Middle East, Africa and the US
- 2024-03-01 - NoName057(16)’s DDoSia project: 2024 updates and behavioural shifts
- 2024-03-09 - New Backdoor Activity Socks5Systemz
- 2024-03-18 - Mirai Nomi: A Botnet Leveraging DGA
- 2024-04-01 - Passive DNS For Phishing Link Analysis - Identifying 36 Latrodectus Domains With Historical Records and 302 Redirects
- 2024-05-13 - Gootloader Isn’t Broken
- 2024-05-16 - Grandoreiro banking trojan unleashed: X-Force observing emerging global campaigns
🔥168👍2😢2