vx-underground – Telegram
vx-underground
45.8K subscribers
3.93K photos
418 videos
83 files
1.43K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Uploading more malwares.

It's a lot, it takes a long time.

While we wait for this to finish (8 hours+), please look at this cat.

Have a nice weekend.
96🥰9👍4🤔1😢1🤩1
On April 1st, 2025 (No April Fools), the Russian FSB (Federal Security Service of the Russian Federation, Федеральная служба безопасности Российской Федерации), conducted a raid in St. Petersburg, Russia, on an IT facility named "Aeza Group".

Aeza Group is (rumored) to provide network infrastructure for Russia's Doppelgänger propaganda network. The location raided was once the home for Yevgeny Prigozhin's Wagner Center (tl;dr no idea who is stating these rumors, it's just news articles and Telegram).

Law enforcement agents allege the CEO, Yuri Bozoyan, and two employees of the organization, Maxim Orel and Tatyana Zubova, were arrested for aiding, abetting, or facilitating criminals groups. More specifically, the FSB asserts Mr. Bozoyan and his co-conspirators trafficked narcotics at large scale.

Additionally, it was (rumored) Aeza Group provided infrastructure for "darknet" groups and malware groups. However, we have been unable to find substantial evidence to support these claims other than various news articles (tl;dr who the fuck is saying this?).

Edit: Commenters suggested "arrest" photo was AI generated. That is the photo that was shared. We agree it looks suspicious, so we've removed it. Instead have a nice photo of Mr. Bozoyan
🤣5512👍7😎5😢3🔥2🤓2
😱113🤣42😢9🔥7👍5🤔4🙏2🤓2🤝21
You know what does well in a recession?

Cybercrime.

Threat Intel, Threat Actors, Defenders, Attackers — chat, we're so back. High 5s all around.
109🔥25👍6😢1
vx-underground
You know what does well in a recession? Cybercrime. Threat Intel, Threat Actors, Defenders, Attackers — chat, we're so back. High 5s all around.
Rest in pepperoni to our software engineers though. They're absolutely cooked. They're facing AI and a recession — they're fighting a war on both fronts.
50🫡45🤣10😁2😢1
We could probably hire someone to do nothing except reply to people all day.

We don't have the money for it, but we have the volume of e-mails and DMs for it.

Sorry we don't reply, but we do appreciate the information shared, or kitty cat pictures shared.

-smelly smellington
66🫡16👍8🥰5
vx-underground
We could probably hire someone to do nothing except reply to people all day. We don't have the money for it, but we have the volume of e-mails and DMs for it. Sorry we don't reply, but we do appreciate the information shared, or kitty cat pictures shared.…
We also appreciate all our "sleeper agents".

Anytime we make a post about: an arrest, breach, or Threat Actor, we always have at least 1 or 2 people who contact us who are familiar with the situation unfolding.

I love you so much.

tl;dr vx-underground hive mind
77❤‍🔥29🤓11👍1👏1😢1
In July, 2022 we created "VX Feed" — a Discord server which provides updates in-near-real-time from various websites and ransomware blogs.

We forgot it existed.

We checked on it today, it's still running. It's got several thousand members.
🔥101🥰20😁19💯7🤓2👍1😢1
April 4th Noah Urban a/k/a "King Bob", an alleged member of the infamous "Scattered Spider" group, plead guilty to all charges in all cases.

Mr. Urban has two cases. One case is in Florida, United States. One case in California, United States.

Per court documents Mr. Urban, as a member of what Threat Intelligence defined as "Scattered Spider", was responsible for:
- Social engineering company targets by posing as IT staff or Help Desk. Mr. Urban often used SMS or telephone calls to impersonate employees.
- Social engineer company targets, by posing as IT staff or Help Desk, toward remote access tools to provide access to other individuals within "Scattered Spider"
- Social engineer company targets to share one-time passwords used for MFA
- Monetized access to victim networks by extortion enabled by ransomware and data theft

Mr. Urban plead guilty to the following charges in Florida:
- One (1) count of Conspiracy to Commit Wire Fraud
- One (1) count of Wire Fraud
- One (1) count of Aggravated Identity Theft

Mr. Urban plead guilty to the following charges in California:
- One (1) count of Conspiracy to Commit Wire Fraud

Per court records, Mr. Urban took a plea deal which states Mr. Urban must forfeit stolen money to each victim individually (restitution) with the sum being in excess of $13,000,000 between 59 individuals. Additionally, Mr. Urban waived his right to pay restitution to victims not listed in official court paperwork — meaning he may have to pay more at a later period of time if more victims are identified.

Mr. Urban has agreed to forfeit the following toward victims: "Dai", "Ethereum", "Monero", "Bitcoin", "Ripple", as well as any cash in Mr. Urban's possession and any physical item worth sufficient value (undefined).

Mr. Urban, despite taking a plea deal and agreeing to restitution, is still subject to sentencing. Mr. Urban official sentencing is expected to take place on or around Friday, June 20th, 2025.

Mr. Urban is facing a maximum sentencing of 82 years in prison. However, per standard sentencing guidelines and because Mr. Urban has taken a plea deal, he will receive a much lighter sentence. The Aggravated Identity Theft charge in Florida carries a mandatory two (2) years in prison.
🤣57🥰8😢8👍73😱3
vx-underground
April 4th Noah Urban a/k/a "King Bob", an alleged member of the infamous "Scattered Spider" group, plead guilty to all charges in all cases. Mr. Urban has two cases. One case is in Florida, United States. One case in California, United States. Per court…
For those who stated Mr. Urban may have spent his stolen money: (un)fortunately, because Mr. Urban has agreed to restitution, it is mandatory under federal law he repay the stolen money. If Mr. Urban does not have the full $13,000,000 he will have to do the following:

1. Establish a payment plan with the court system
2. Begin making payments while serving jail time (Inmate Financial Responsibility Program)
3. Payment toward victims continue even when sentencing is completed.

While Mr. Urban is in prison he will be "employed" in federal prison and earn money for his work — generally $0.40/hr. Although, Mr. Urban is capable of receiving a $30 bonus at the end of each month for good work.

Any money Mr. Urban receives from friends, family, or general employment will be seized and returned to victims until the total amount is returned. He cannot declare bankruptcy to avoid restitution. It does not "fall off" like traditional debts in the United States.

It is in Mr. Urban's best interest he has the full $13,000,000. Otherwise he will be paying restitution for the majority of his life.
🤣89😢14🎉11👍81🤝1
About 2 weeks ago privacy nerds on Reddit began reporting they're unable to watch YouTube videos when using a VPN. YouTube displays a "VPN/Proxy Detected" warning.

Initially it was displayed on desktop computers, however it is now being displayed on mobile devices too.
🤔70😢35😁16🔥5🤓5🤣3👍2😇21🎉1
vx-underground
About 2 weeks ago privacy nerds on Reddit began reporting they're unable to watch YouTube videos when using a VPN. YouTube displays a "VPN/Proxy Detected" warning. Initially it was displayed on desktop computers, however it is now being displayed on mobile…
Note: this was from the ProtonPrivacy Reddit. The cell phone image was shared on "Tech Crimes" on Telegram.

Some users have speculated it is from "too many people using the same VPN server" (?). Others reported they had the same issue when using Mullvad

Users reported it only impacts specific YouTube channels — other state the error is across all YouTube channels. Some users stated they were able to evade the flag when using "Stealth Protocol" with Proton.
👍28🫡14🤣7😢1
After the FBI and NCA UK took down Lockbit ransomware group servers, arrested their lead developer, sanctioned the group, and listed the "leader" of the group on the FBI's Most Wanted, we assumed Lockbit ransomware group would either rebrand or die.

Well, they died for a little. But we are beginning to see signs of Lockbit ransomware group again. The past few weeks we have seen more and more reports surface of their attacks. Although they are no longer near where they used to be (30+ ransoms a day), the fact they're making a comeback is both impressive and scary.

Lockbit ransomware group is like a cockroach. He is immune to virtually everything — we thought he was dead, but he is alive still.
🔥7810🫡6👍4😢4🤔2❤‍🔥1🥰1🤓1
American social media and politics is absolutely amazing and is x10 better than any other country.

Two dorks got into a Twitter argument over tariff impact on clothing and have mutually agreed to settle there differences with physical violence.

America 🤝 Violence
🔥73😁22🤣13👍5❤‍🔥21😢1💯1🫡1
Scott Presler, American conservative political activist, shared details today on social media regarding unusual activity on his Xitter account.

What could it mean?
🤣122😱10🔥6😁63🎉3🥰2👍1
We've updated our malware builders collection.

It's beautiful. Thank you so much to Cryakl for assembling this MASSIVE collection. We have 545 malware builders!

*Please exercise caution if you decide to experiment with them

https://vx-underground.org/Builders
🔥44🫡123👍2👏1😢1
In these trying times the one thing which remains constant is the value of kitty cat pictures.

Please take a copy of our kitty cat picture collection. It is 159.9GB (111,429 files) of kitty cat pictures.

Economic problems 🤝Kitty cats

https://vx-underground.org/tmp
74🥰14😍7🤓5🤝5🔥3🫡2👍1