vx-underground – Telegram
vx-underground
45.7K subscribers
3.93K photos
418 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
We will be offline for a few days.

BRB
We have released Notes from UG Volume 2: XOPALEHA.

Xopaleha is a blackmarket exploit dealer. We allowed members of our Discord to ask him anything.

You can check it out here: https://papers.vx-underground.org/papers/VXUG/Exclusive/Interviews/InterviewWithXopaleha.pdf
For our RE and Threat Intel friends:

We've added the Qakbot debugger leak. This debugger was accidentally dropped onto an infected machine in early November.

You can download it here: https://papers.vx-underground.org/archive/Builders/Qakbot%20Debugger.7z
We've updated the vx-underground leaked source code collection on our GitHub repository. We've added Android.Cerberus.K (advertised as v10).

* Potentially incomplete source code

You can check it out here: https://github.com/vxunderground/MalwareSourceCode/tree/main/Leaks
ATW (AgainstTheWest), a NATO based Threat Actor, has claimed to have breached and hijacked a Chinese TV station. They have scheduled a live television broadcast in approx. 53 minutes.
We've re-uploaded, re-indexed, and expanded our Conti ransomware group leak collection.

- Training material
- Operator leak
- TeamTNT tool leak

You can check it out here: https://share.vx-underground.org/
👍3
We've made updates to vx-underground

-All new additions are displayed on the homepage
-New papers added to AV Tech section
-Notes from UG is now named Threat Intel
-Threat Intel page lists ransomware group leaks and domains
and more...

Check it out here: http://vx-underground.org
New additions:

-MacOS.Macma samples
-Moses Staff samples
-North Korean TA406 samples
-Emotet samples
-Conti Ransomware Group analysis paper added
-Finding Beacons in the Dark: A Guide to Cyber Threat Intelligence by Blackberry added

Check it out here: https://www.vx-underground.org/
2021.11.22.7z
4.1 MB
APT Tardigrade:) Paper + sample
winamp source code still present on webarchive
botenaGo.7z
1.5 MB
BotenaGo IOT malware:)