vx-underground – Telegram
vx-underground
45.8K subscribers
3.93K photos
419 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
We're currently pushing approx. 300,000 malware samples a day. Our goal is to have over 26,000,000 unique malware samples by early 2022.
We've made updates to the vx-underground "Malware Builders and Tools" collection:

- NjRat Builder + Panel

https://vx-underground.org
🤔
Updates:

-We are aware some samples have become corrupted post migration. All have been repaired. Go live is October 22, 2021

-18,000+ PDBs & symbols in queue for our reverse engineer friends
Monday, October 18th, 2021 a Turkish individual leaked source code to Cerberus Android Banking Trojan. This appears to a variant of a previously leaked version we possess.

You can download Android.Cerberus.d here: https://github.com/vxunderground/MalwareSourceCode/tree/main/Leaks/Android
Additions to the VXUG papers collection:

-SmashEx: Smashing SGX Enclaves Using Exceptions by Jinhua Cui, Jason Yu, Shweta Shinde, Prateek Saxena, Zhiping Cai

-Analyzing ransomware negotiations with CONTI: An in-depth analysis by DIFR Research Group

https://vx-underground.org/papers
Groove ransomware groups asks ransomware operators to unite to attack the United States. Groove asks operators to stop attacking Chinese organizations and warns of a possible race war in the United States.

Image 1: EN
Image 2: RU
Conti ransomware group has put out a statement regarding the recent REvil activities. We have archived it and placed it on Pastebin.

Title: Announcement. ReviLives.
Subject: Own opinion.

You can read it here: https://pastebin.com/kMQAbcFa
Following the recent fallout of REvil, the new spokesperson of REvil, 0_neday, has been banned from XSS.
Espector.7z
101.6 KB
I will share something on Telegram before it goes live on vx-underground. Here are samples to APT Espector, a Chinese UEFI Bootkit and FiveSYS, a Microsoft signed Windows Rootkit. :) Have a good weekend:)

-smelly
We have another ransomware toolkit leak. We will share it soon.

Happy weekend, Blue Teams.
Updates to the vx-underground APT collection:

- FiveSYS, Microsoft signed Rootkit
- TinyVNC from Kimsuky Group
- APT Harvester campaign
and more...

Check it out here: https://vx-underground.org/apts

*Samples includes
Total malware samples in the vx-underground malware collection: 2,348,257

Goal: 26,000,000
We've made updates to the vx-underground APT collection:

- FontOnLake, linux malware
- APT InSideCopy

Samples and papers included.

Check it out here: https://vx-underground.org/apts
We've updated the vx-underground malware source code repository. We have added Android.GhostBot. An Android spyware proof-of-concept capable of surveillance on the target, functionality similar to Pegasus

You can check it out here (under Android section): https://github.com/vxunderground/MalwareSourceCode
Grief ransomware group has ransomed the National Rifle Association (NRA).

Link: http://griefcameifmv4hfr3auozmovz5yi6m3h3dwbuqw7baomfxoxz4qteid.onion
👍1