vx-underground – Telegram
vx-underground
45.8K subscribers
3.93K photos
418 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Total malware samples in the vx-underground malware collection: 4,045,956

Goal: 26,000,000
InterviewWithKajit.pdf
5.5 MB
Notes from UG Vol. 1 has been released

We interviewed Kajit, a former REvil and DarkSide operator & the admin of the Ransomware Marketplace forum (RAMP)

In this interview we allowed members of our Discord to ask him anything
We've updated the vx-underground APT sample collection:

- WinDealer
- SQUIRRELWAFFLE
- WsLink

Have a nice day.

https://vx-underground.org/apts
ExMatter.rar
2.1 MB
Today Symantec released a paper on BlackMatters new exfiltration tool dubbed 'ExMatter'.

Samples attached:)
Morphisec announced a new ransomware variant written in GoLang dubbed 'Decaf ransomware'. More samples:)
MacOS.XLoader.rar
798.3 KB
Old samples - SentinelOne wrote a paper on MacOS.XLoader. Here are the samples:)
2021.11.02.rar
49.4 MB
APT-C-59 paper + samples released today.
We've made an addition to the vx-underground WINAPI Tricks GitHub repository:

- Correct implementation of URLDownloadFileW using IBindStatusCallback callbacks to ensure remote file download was completed successfully

Check it out here: https://github.com/vxunderground/WinAPI-Tricks
New Babuk samples && new Mekotio Banker samples. Have a nice day.
The United States government is offering a reward up to $10,000,000 for information on DarkSide ransomware group and/or affiliates.
Conti ransomware group has released a statement and apologized to "members of Saudi Arabia, UAE, and Qatar families ... to His Royal Highness Prince Mohammed bin Salman and any other members of the Royal Families"

We have archived it here: https://pastebin.com/eeLNnAG0
The long-term goal of vx-underground is to develop:

- Reliable front-end, doesnt concede dark art aesthetic, easy to navigate, works on mobile devices
- Ability for individual sample retrievable
- Enhanced papers library

Ideally completion date is sometime 2023.
In 1996 a virus writer, suspected to be from either France or the United Kingdom, released the Tentacle virus. Tentacle II was the first virus to use EPO (Entry-Point Obscuring) infection for Windows 3.x systems.

This was the icon associated with the binary.
New video added to our YouTube archives:

Iranian news reports the Tehran subway disruption. Iranian authorities attributed the issue to 'overcrowding' and unidentified 'computer problem'.

This follows the cyber attack against Iranian gas stations.
https://www.youtube.com/watch?v=Vejsd_wYcO0