vx-underground – Telegram
vx-underground
45.7K subscribers
3.93K photos
418 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Hello,

We've finished correcting the colossal oopsie we created. We're in the process of correcting the MalwareIngestion bulk releases.

Files are being synced on VirusTotal again.

tl;dr back to getting millions of malwares
🔥62👍11👏4😢2🤣2
Today the United States Department of Justice announced the conviction of Remy St. Felix. St. Felix is accused of being the mastermind behind a string of violent home invasions targeting individuals possessing large quantities of cryptocurrency.

Prosecutors state St. Felix targeted crypto holders in North Carolina, Florida, Texas, and New York.

Due to the violence of the actions — including assaulting victims, zip-tying them, holding them at a gunpoint, and threatening to murder their family, St. Felix is facing charges for; conspiracy, kidnapping, Hobbs Act robbery, wirefraud, and brandishing a firearm in furtherance of a crime of violence. He is facing a maximum sentence of life in prison.

More information: https://www.justice.gov/opa/pr/man-convicted-violent-home-invasion-robberies-steal-cryptocurrency
👏82👍24🤓24😢11🤣95🫡4🔥2🎉2🤔1
how to write cool malware

1. come up with idea
2. write basic shit code, hurts eyes
3. refine it, make less ugly
4. slowly increase complexity
5. refine it, make it beautiful
6. release it, pretend to understand it
👍86🤣59😎23💯107🤓7🔥5😁3❤‍🔥1🤔1😢1
"They're putting infostealers in the water, they're making the frogs rich" - Alex Jones if he worked in Cyber Threat Intelligence
😁87🤣46💯13❤‍🔥5👍2🔥1🤔1😢1
The United Kingdom's National Crime Agency released a statement today.

On September 5th, the individual believed to be responsible for compromising TfL (Transport for London) has been apprehended.

More information:
https://www.nationalcrimeagency.gov.uk/news/arrest-made-in-nca-investigation-into-transport-for-london-cyber-attack
👍26🫡10😢9🤯8🎉4🔥1🤣1
Today Mastercard bought Cyber Threat Intelligence company RecordedFuture.

Why did a payment service provider acquire a threat intelligence company? Well, it's very simple — we don't understand it at all, but we assure you it's very simple, probably.
🤔87🤣34😱6🤝6🔥4😁4😎3😢2
Today a Threat Actor operating under the moniker 'Fortibitch' released 440GB of exfiltrated Fortinet data. The Threat Actor claims the leaked data is a result of a failed extortion attempt. 'Fortibitch' wrote Fortinet allegedly wrote to them they'd rather 'eat poop than pay a ransom'.

Fortinet later confirmed the validity of the compromise to BleepinComputer — writing that customer data was stolen from a "third-party cloud-based shared file drive."

Additionally, 'Fortibitch' gave me a shoutout, referencing a previous vx-underground post debating the correct pronunciation of VXUG, by writing "smelly from Vi-Eks-Yu-Gee".

Subsequently, they addressed me as "-2 IQ degenerate nerd", referencing me mocking myself and my many failures I have apologized for.

Finally, they called me the "Texas Femboy Kisser". While I do not kiss femboys, or people from Texas, this conversation piece is indicative of a group of people I am familiar with.

Hello to you too, 'Fortibitch'.
🤣203🤓23🥰13🔥10👍5🫡54🤯4❤‍🔥3😁2🤔1
We're experimenting with a vx-underground Windows Desktop e-reader. It's a simple .NET application that connects to vx-underground, lists papers, and allows you to view them without having to visit the website.

Why? ¯\_(ツ)_/¯

Seems kinda cool. Also, slightly easier to explore
🤓8627🤔14❤‍🔥3👍2🤩2🤣2😢1
vx-underground
We're experimenting with a vx-underground Windows Desktop e-reader. It's a simple .NET application that connects to vx-underground, lists papers, and allows you to view them without having to visit the website. Why? ¯\_(ツ)_/¯ Seems kinda cool. Also, slightly…
Unironically, 90% of core viewing demographic would (in some shape or form) prefer it to be malware just so they could rip it apart and throw tomatoes at us.
😁87👍15💯14🤣13❤‍🔥21😢1🤓1
New vx-underground artwork

Image 1. Drowning in SPAM
Image 2. Malware compression
180🔥67❤‍🔥9😢3👍1
🚨BREAKING 🚨

The CEO of RecordedFuture confirms to us that they cannot wipe $400,000 of debt off our Mastercard credit card. Also, Triage will remain free.
😢143🤣47🫡96💯5❤‍🔥2👍1
We making it to Prod with this one gang 🙏
🤣68🔥17❤‍🔥8👍2👏1😢1🤝1
We decided to test OpenAI's image creation functionality by requesting it produce a meme about malware authors

The image it created is funny — although not in the classical sense. It's such a catastrophic failure it has become funny

The longer you look at it, the funnier it is
🤣140😢74👍4🤓4💯3🫡3🔥2🤔2😱1🤝1
vx-underground
We decided to test OpenAI's image creation functionality by requesting it produce a meme about malware authors The image it created is funny — although not in the classical sense. It's such a catastrophic failure it has become funny The longer you look at…
Details:

1. Keyboard with 1,000 keys
2. Warped fingers
3. Desk is backwards
4. Keyboard not plugged in
5. Anon mask out the matrix .. holding the coffee by it's smoke? The Police officers coffee?
6. THAT VIRUS VIRUNG ALOING
7. Cop waving little American flag? (yay! cybercrime!)
55🤣17😎13😁8🤓5👍4❤‍🔥3🔥2😢2🤔1
Thank you to the people who continue to send us strange things

Our collection includes stickers, shirts, pants, smashed network equipment, pins, autographs from FBI's most wanted, artwork, and pet pictures.

We appreciate the pet photos. We love animals.
93👍14🤝5🤓3😱2😢2
Large update coming. Due to the size of additions, if you have notifications enabled you will likely receive multiple notifications.

Prepare yourself.
👍32🤣16😎7👏3🤯3🤓3🤝2😢1🫡1
Large update. Read the papers, download the malware, reverse the malware, whatever. Even writing about all the additions is a lot of work.

Note: Assume all builder binaries are malicious, explore them with caution. APT paper noscripts truncated or modified in this post.

Administrative updates:
- VXDB is still syncing with VirusTotal. All corrupt files have been repaired. We are currently refining our malware ingestion process.
- MalwareIngestion collection has been purged due to fears of binaries being corrupted. MalwareIngestion will be repaired and redeployed at a later time.
- New vx-underground merch scheduled to be added to merch store. This will be done at a later time.
- New vx-underground harddrives will be available for sale later.

Builders:
- Builder-Android.Phoenix
- Builder.CraxsRat
- Builder.Ransomware.Slam
- Builder.RobinHoodRansomware.Leak

Families:
- Blackmoon
- CobaltStrike
- DarkCloud
- DCRat
- Mirai
- NetTraveler
- QuasarRAT
- RedLine
- Rekoobe
- Remcos
- Sliver
- Stealc
- Tidepool
- Tofsee
- XMRig
42👍7🤓7🔥1😢1