vx-underground – Telegram
vx-underground
45.6K subscribers
3.92K photos
416 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
After what feels like an eternity, we have finally identified, repaired, and re-deployed our corrupted batch of malware samples from the MalwareIngestion feed for June, 2024.

It's over 600,000 malware samples. Download them.

https://vx-underground.org/Samples/MalwareIngestion
45👍14❤‍🔥5😢1💯1
We have a large quantity of malware samples and papers to add. These will all be pushed in bulk in a very large update coming soon-ish.

Until that times comes (finishing collecting the stuff) we're just gonna play Crab Champions

Have a nice day
39🫡8👍4😢1🤣1
Some controversy today as YouTube tech reviewer Marques Brownlee 'Panels' app is getting pretty substantial backlash.

tl;dr Marques Brownlee app, 'Panels', offers high-definition wallpapers from Digital Artists for $49.99/year. People criticized the app for an array of reasons, beside the idea of paying $49.99/year for wallpapers on your cell phone, the app requests tracking information, and contains ads.

Unsurprisingly, and as is tradition, internet nerds quickly began inspecting the app under the metaphorical microscope. Security researcher I_Am_Jakoby discovered the apps API is wildly insecure. He wrote a simple noscript which programmatically scrapes every high-definition wallpaper.

Attached image is the noscript he shared. If you want to experiment with it, just OCR it or something.
🤣16836👍10🤓5❤‍🔥3😢3
There's some noise in the infosec vulnerability and blue team space about an alleged 9.9 CVE score impacting all GNU/Linux systems.

Due to lack of details, some users have expressed criticism on the severity of the exploit — with the infamous Heartbleed being a 7.5 CVE. Some expressed concern that the exploit is overhyped, or acting as marketing material for the researcher.

Others have noted that they believe the exploit is real and possess a genuine score of 9.9 but question the impact of effecting all GNU/Linux systems.

From what we've seen, nobody knows anything and everyone is just yappin. We'll see what happens when the details are released.
👍83🔥17🤯10💯7🤣7🤓6🤔1😢1
Today in internet stuff

- Sanctions against more TAs
- KIAs can get hacked somehow
- Linux RCE discussions everywhere
- More botnet tracking from people

We didn't read any of it
🤣9520😎11🔥10👍6❤‍🔥4🤯3😢3😁2🙏2🤓2
Summary of the Linux RCE 9.9 CVE

The vulnerability write up and disclosure is confusing. Initially the write up was scheduled for release in October. However, the write up and proof-of-concept was leaked onto Breached (???) which then resulted in the researcher / author to do an official write up (maybe?).

- Self described as 9.9, not officially declared 9.9
- Attacks CUPS

We haven't looked at it because we don't do exploit stuff and also Linux is for nerds
🤣130🤓36😁9😎43❤‍🔥2🤔2😢2
vx-underground
Summary of the Linux RCE 9.9 CVE The vulnerability write up and disclosure is confusing. Initially the write up was scheduled for release in October. However, the write up and proof-of-concept was leaked onto Breached (???) which then resulted in the researcher…
Edit: we're being told EvilSocket didn't define the vulnerability as a 9.9, someone else did (RedHat) and they went with it. No idea if that's true, we don't know whats real anymore because everyone is yappin.

We're going back to bed
🤣108👍12💯9🤓7🤯53👏1😢1🫡1
ye I use Linux
❤‍🔥179😎31🔥17🤣14👍97🤓7😱5🫡2😁1🤔1
Hello,

We're aware of a long standing issue where trying to extract vx-underground files with the default MacOS tooling fails.

We don't remember why, but it does.

Our proposed solution is introducing your device to thermite, or trying to a different tool.

Thanks,
😁56🤣11🔥9👍5🫡54😱4🤓4🤝2👏1
This is misinformation.

This is actually Kitten Tempest. A financially motivated Threat Actor being monitored by Microsoft Threat Intelligence.
🤣87❤‍🔥6👍53😱3👏2😁2🤔1😢1🤓1
🚨BREAKING 🚨

Kitten Tempest has been observed enhancing it's TTPs.
84😱20🤣15👍4🥰4🫡3🔥1👏1😢1🤩1🤓1
🤣172🤓36👍6🤝3👏2😁21😢1
> see cups vulnerability trending on xitter
> *click*
> nothing but arguing and name calling
> *scroll*
> printers not working on linux memes
> *scroll*
😁105🤣18👍8😢3👏1🤓1😎1
vx-underground
> see cups vulnerability trending on xitter > *click* > nothing but arguing and name calling > *scroll* > printers not working on linux memes > *scroll*
Anyway, we've got a large update coming soon. It's gonna be another big one, so hold onto your horses, or whatever they say.
49🔥6👏3😎3👍1😢1🤓1🤝1
Hacking is boring.

Wanna know what's fun? Browsing MSDN documentation at 2 o'clock in the morning, looking for APIs to potentially abuse in malware. It'll also probably never go in the wild and it'll go unappreciated for several months or even years.

That's where the fun is
108😁29🫡19🤣10👍5😱4🤓4❤‍🔥3😢2🤔1😇1
vx-underground
Hacking is boring. Wanna know what's fun? Browsing MSDN documentation at 2 o'clock in the morning, looking for APIs to potentially abuse in malware. It'll also probably never go in the wild and it'll go unappreciated for several months or even years. That's…
x2 fun multiplied!

Bonus points is when someone heavily borrows from your code, or copy pastas, but markets it heavily on LinkedIn and gets nominated for an award and wins it.

It's about doing it for the love of the game — not the money, fame, and anime.
🔥7813😢11🤓6🤯5😎3😇2❤‍🔥1
This media is not supported in your browser
VIEW IN TELEGRAM
relaxing with some games on the new setup
😁110🤩21🔥18🤣15👍6❤‍🔥5🥰5😱4🫡3🤯2😢2
A few years ago there was a person who got a scholarship for their contributions to open source software.

This person spent a majority of their time changing indentations and correcting typos. The university never reviewed the contributions.

We still think about it sometimes.
🔥140🤣81🤓22💯12👍53😢2
Our upcoming update to vx-underground is so large it may require a text file upload on Telegram, and an article written on Xitter.

Just writing all the additions will take time 😭😭😭
💯62🤓13🔥3🎉2😢1🤣1