vx-underground – Telegram
vx-underground
45.8K subscribers
3.93K photos
418 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
> write malware
> compile binary
> need to think of sneaky name
> svchost.exe (never been done before)
> (thats a lie, everyone does that)
> tfw av vendors find the svchost.exe
😁94🤣47💯85👍2😢1
Some people want us to start saying 'hackers' instead of Threat Actors. We'll say hackers again when people stop calling toothpaste saving tips 'pro hacks' or 'life hacks'.

It's not 1996 anymore, sorry.
110🤣51😁26👍8😢5👏4🥰3
TeamViewer disclosed a security breach today**

https://www.teamviewer.com/en/resources/trust-center/statement/
😱56🤓30🔥13🤣12🥰3😎21
This media is not supported in your browser
VIEW IN TELEGRAM
More ransomware, more arrests, more breaches, more malware – same ol' same ol'
❤‍🔥60😁25🤣12💯7👍54😢1😎1
Today an unknown individual shared a photo of their new pillow. It is the official Alexandria Sheriff's Office mugshot of ex-Breached administrator Pompompurin

tl;dr don't do crime or you'll end up on a pillow
🤣160😁9🔥83👏2😢2👍1💯1
Large update to vx-underground:

Samples:
- VirusSign.2024.06.20
- VirusSign.2024.06.21
- VirusSign.2024.06.22
- VirusSign.2024.06.23
- VirusSign.2024.06.24
- VirusSign.2024.06.25
- VirusSign.2024.06.26
- VirusSign.2024.06.27
- VirusSign.2024.06.28
- InTheWild.0127

Papers:
- 2015-01-22 - Malvertising Leading To Flash Zero Day Via Angler Exploit Kit
- 2018-10-22 - Chalubo botnet wants to DDoS from your server or IoT device
- 2022-07-18 - Trident Ursa
- 2023-06-10 - IcedID Brings ScreenConnect and CSharp Streamer to ALPHV Ransomware Deployment
- 2023-06-13 - VMware ESXi Zero-Day Used by Chinese Espionage Actor to Perform Privileged Guest Operations on Compromised Hypervisors
- 2024-01-06 - Understanding Internals of SmokeLoader
- 2024-01-19 - Chinese Espionage Group UNC3886 Found Exploiting CVE-2023-34048 Since Late 2021
- 2024-04-09 - BlueShell: Four Years On, Still A Formidable Threat
- 2024-04-09 - Unpacking the Blackjack Group's Fuxnet Malware
- 2024-04-24 - Analysis of Ongoing FROZENSHADOW Attack Campaign Leveraging SSLoad Malware and RMM Software for Domain Takeover
- 2024-05-06 - HijackLoader Updates
- 2024-05-08 - From OSINT to Disk: Wave Stealer Analysis
- 2024-05-13 - Wavestealer Spotted In The Wild
- 2024-05-23 - Tracking APT SideWinder With DNS Records
- 2024-05-26 - QakBOT v5 Deep Malware Analysis
- 2024-05-28 - BlackSuit Attack Analysis
- 2024-05-30 - The Pumpkin Eclipse
- 2024-06-04 - Muhstik Malware Targets Message Queuing Services Applications
- 2024-06-05 - DarkGate switches up its tactics with new payload, email templates
- 2024-06-05 - ExMatter malware levels up: S-RM observes new variant with simultaneous remote code execution and data targeting
- 2024-06-06 - DarkGate: Make AutoIt Great Again
- 2024-06-06 - EMBERSim: A Large-Scale Databank for Boosting Similarity Search in Malware Analysis
🔥32🤓53👍2❤‍🔥1😢1
Nerds are reporting Lockbit ransomware group's blog now requires a blog access key to visit it.

The blog access key: NDWZ3NXU66EWUFBMJWQOC2FXIIHFZFKZRULHBGAYFYX4HEIDRF5Q

Have a nice day
🤣126👍5616💯6🫡4🔥2😁2😢1
Today Linus Tech Tips released a video about the vx-underground harddrive and our collection.

First, thank you for using an image of a shadowy person with odors radiating off of them to describe smelly. 11/10.

Secondly, Linus and his group did an EXCELLENT job discussing the harddrive and the collection. We believe they accurately describe it, its use case, and the basic reasoning why this entire collection exists.

Some portions of the video are very watered down – but this high-level beginner perspective is perfect for people who are unfamiliar with malware. Additionally, in some places the nomenclature is wrong, but the general idea and principles are still 100% correct.

We also enjoy the enthusiasm Mr. Linus shows with the malware, he reminds us of our first time experimenting with a malware builder.

The end review saying we're the darker side of grey is a little disheartening, but ¯\_(ツ)_/¯

https://www.youtube.com/watch?v=7inhRWxQMFk
136🤣45🫡18🔥10👍5💯4👏2😢1
😁134🤣81🤓20💯12👍11😢3🎉21🤔1
Every week nerds ask us "do you know {ransomware_groups} onion?".

Every ransomware group's domains are archived, past and present, as well as their post history by Josh Highet on his website ransomwatch telemetry.

Now stop asking us >:(

Link: https://ransomwatch.telemetry.ltd/
👍66🔥2815🤣8😁2🤯2😢2💯2😱1
> yesterday ltt posts about vxug hdd
> cool_beans.jpeg.exe
> go sleep
> wake up
> check emails
> dozens of inquiries on the vxug hdd
> ???

tl;dr video with 1,000,000+ views gets lots of attention
👍66🔥299🤓8🤯7❤‍🔥2😢2
It appears security researchers, not just sim swappers and fraudsters, follow us on Telegram. It's truly a Christmas miracle

(we don't know who did this talk or what it's about)
🤣152❤‍🔥29🔥1613😇8🎉2🤓2😢1
"i'm a noob, whats the best language to start maldev?"

Buy a dartboard, put stickie notes on it, write programming languages on them, cover your eyes, spin around 10 times, then throw the dart.

Whatever it lands on, learn that language and get good. If you miss, give up.
🔥141🤣7515😁14👍10👏3😱2🤩2🤔1😢1
Lockbit ransomware group administrative staff agreed to go onto a livestream with us (us screensharing a Tox screen) and doing a live Q&A and allow the audience to ask questions.

Questions would be filtered, but maybe it'll be fun.

¯\_(ツ)_/¯
186🔥64😱27🤣17🫡12🤯8👍7🎉3🤩3😎3😢1
Updates to vx-underground:

- 2024-06-10 - Technical Analysis of the Latest Variant of ValleyRAT
- 2024-06-11 - A Brief History of SmokeLoader, Part 1
- 2024-06-12 - Dipping into Danger: The WARMCOOKIE backdoor
- 2024-06-12 - New backdoor BadSpace delivered by high-ranking infected websites
- 2024-06-12 - Nova Stealer, le malware made in France
- 2024-06-12 - Ransomware Attackers May Have Used Privilege Escalation Vulnerability as Zero-day
- 2024-06-13 - DISGOMOJI Malware Used to Target Indian Government
- 2024-06-13 - Inside LATRODECTUS: A Dive into Malware Tactics and Mitigation
- 2024-06-15 - Malware Analysis: FormBook
- 2024-06-17 - From Clipboard to Compromise: A PowerShell Self-Pwn
- 2024-06-17 - Latrodectus, are you coming back?
- 2024-06-17 - Malvertising Campaign Leads to Execution of Oyster Backdoor
- 2024-06-18 - Cloaked and Covert: Uncovering UNC3886 Espionage Operations
- 2024-06-19 - LevelBlue Labs Discovers Highly Evasive, New Loader Targeting Chinese Organizations
- 2024-06-19 - New North Korean based backdoor packs a punch
- 2024-06-19 - Spectre (SPC) v9 Campaigns and Updates
- 2024-06-20 - Caught in the Act: Uncovering SpyNote in Unexpected Places
- 2024-06-20 - Medusa Reborn: A New Compact Variant Discovered
- 2024-06-21 - GrimResource: Microsoft Management Console for initial access and evasion
- 2024-06-24 - Gootloader’s New Hideout Revealed: The Malware Hunt in WordPress’ Shadows
- 2024-06-24 - Latrodectus Affiliate Resumes Operations Using Brute Ratel C4 Post Operation Endgame
- 2024-06-25 - From Dormant to Dangerous: P2Pinfect Evolves to Deploy New Ransomware and Cryptominer
- 2024-06-25 - How to detect the modular RAT CSHARP-STREAMER
33❤‍🔥10🔥5🎉4👍3😢3🫡3🤓1
We caused some confusion about our RansomHub interview post because it was worded similarly to our Lockbit ransomware interview post.

It's a new interview – nothing is being cancelled. We'll mentioned it again later on so we don't confuse people.
🤝319😁6😢2👍1
Yes, we're aware of the OpenSSH exploit – "regreSSHion".

Everyone and their grandmother is discussing it, it'd be difficult to miss it. We didn't have anything meaningful to contribute to the conversation, so we didn't mention it.

tl;dr exploit bad, its monday, nerd stuff
65😁16❤‍🔥8👍4🔥4🤝4🤣2😢1
stupid ai meme is kind of funny
🤣138💯17👍3🤝3😢2
vx-underground
stupid ai meme is kind of funny
"I'm not hurting anyone" — Ruins countless lives

^ audibly laughed out loud
👍58🔥31