vx-underground – Telegram
vx-underground
45.1K subscribers
3.89K photos
412 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
2021.12.01.rar
2.7 MB
APT Gamaredon:)
calloffduty.zip
44 MB
Call of Duty symbol dump:)
LockerGoga.rar
14.1 MB
LockerGoga samples:)
2021.11.29(1).rar
3.6 MB
APT scarcruft (APT37) samples:)
We're happy to announce that our friends over at XSS have given us approval to archive materials from their domain and import it into the vx-underground collection.

* Materials will be English and Russian
* Authors will receive complete credit for work

More info coming soon..
We've updated the vx-underground malware source code collection on GitHub:

Leaks:
Win32.PredatorTheThief (beta)
Win32.Module.Startup.Amadey
Unknown.Incomplete.Eb0la
Unknown.Incomplete.DarkRadiation

+ 2 Win32 Stealers added.

Check it out here: https://github.com/vxunderground/MalwareSourceCode
blackByte.7z
1.2 MB
Blackbyte ransomware samples:)
psiphone android malware samples:) + paper
2021.11.30.rar
1.4 MB
ewdoor campaign samples + paper:)
CobaltStrike.rar
37 MB
93 cobalt strike beacons:)
2021.12.06.rar
3 MB
apt37 chinotto samples:)
2021.11.07.rar
591.1 KB
apt 27 samples:)
👍1
Android.CleaningService.rar
5.7 MB
android.cleaningservice:) , malware campaign targetng malaysia
2021.12.03.rar
2.9 MB
apt 38 samples + paper:)
Magnat.rar
462.5 MB
magnat samples:)
2021.12.07.rar
959.1 KB
FIN13; Mandiant: FIN13, a Cybercriminal Threat Actor Focused on Mexico
We've updated our paper collection

-XLLPOC, code execution via Excel by, Excel DLL loader (XLL files), being sold on various forums
-ZipExec, executing password protected zip files by, a technique currently used by Emotet

Check it out: https://vx-underground.org
3
BlackCatRansomware.7z
1.3 MB
blackcat ransomware sample:) (rust ransomware)
1