vx-underground – Telegram
vx-underground
45.6K subscribers
3.91K photos
414 videos
83 files
1.42K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Hello,

"Sean" has informed us that, somewhere in the midst of our kitty cat collection, is a photo of a cute doggie making homophobic remarks.

This is terrible news. The entire collection is contaminated.
😱200🤣190😢18👍1712😁11🤓6🫡4🔥2🤯2💯2
Hello,

Tomorrow we have a large update coming. Unsurprisingly, it is the same ol', same ol'. It is malware source code, samples, and papers.

-smelly smellington

P.S. glad so many of you liked the kitty cat collection. It's fun doing goofy stuff on the internet
👍98❤‍🔥4312🎉5💯5🔥1🥰1😁1
wtf python imports are tariffed
😁157🤣111🤯13😢10🙏5🤔4😱3🎉3🫡32💯2
gronk is this true
👍35🤣17🤔6😢2
vx-underground
gronk is this true
Also, unrelated to Gronk, we've updated vx-underground. We've added InTheWild 140 - 151. This is 275,000 new malware samples.

Additionally, we've updated TheOldNewThing archive for January, February, and March.

Large paper tsunami coming today.

Cheers,
40❤‍🔥8🤓5👍1😢1
Gone for the day and return to see the United States government doing schizo Boomer Facebook posting
🤣14910💯10😁7🎉1
out.txt
30 KB
Massive update to Malware Defense collection

Chat, we are cookin'. Thanks to Malpedia for letting us get the files. They're the best.
🔥455👏4👍2😢1
This media is not supported in your browser
VIEW IN TELEGRAM
me trying to have a rational conversation about computers with someone on twitter
😁69🤣27❤‍🔥1😱1😢1🎉1
doing some work in the backyard today, what kind of tree roots are these???
😁159🤓26🤣24🎉12🔥4🤩4🤯3👍2🥰2🤔2😢1
Nintendo ransomware group
🤣301😁15🔥6🤔6💯4👍32🥰1😢1
Someone contacted us and said they 0day'd their school, infected every machine with a custom RAT, and displayed a MessageBox to everyone in the school at the same time. After that, the school hired him to be in charge of cybersecurity

What the fuck are you talking about
🤣355❤‍🔥179🤓9🤯8👍6🙏6😁4🤔2😢1
"Nothing is certain except computer viruses and cat pictures" — Benjamin Franklin
👏72🤣29💯7🤓6🤔2😢1
uhhh ok
🤣253🔥18😁13🥰6🤔3🤯2😇2😢1
vx-underground
uhhh ok
> wants to add to blocklist
> tweets it
🤣111🤔38🔥7🙏21🎉1
This media is not supported in your browser
VIEW IN TELEGRAM
Windows 10 support ends October 14th, 2025. It is the calling of the Linux nerds.
😁151🤣48🥰18🤓109💯7👍4😢2
The National Police Agency (NPA) of Japan recent documentation of state-sponsored Threat Actors from China is interesting.

A group they believe to be a subset of APT10, abuses WSB (Windows Sandbox) by creating a .wsb configuration file and using it to spin up an instance of the Windows Sandbox.

This is interesting because Windows Defender cannot access the Windows Sandbox (image 1).

The payload enables folder sharing, network access, clipboard access, microphone access, and video access.

tl;dr abusing the sandbox, sandbox as a c2
👍81❤‍🔥24😱19🔥15🤯7🤝7🤔65😁1😢1
Congratulations to APT "Stately Taurus".

Throughout 2021 and 2022 Palo Alto was tracking their activity because they left debug symbols in their DLLs.

They've since learned to remove the debug symbols. Good job, buddy. It took a few years, but you're getting better!
😁72🤣21🥰6🎉6👍51🔥1😢1
vx-underground
Congratulations to APT "Stately Taurus". Throughout 2021 and 2022 Palo Alto was tracking their activity because they left debug symbols in their DLLs. They've since learned to remove the debug symbols. Good job, buddy. It took a few years, but you're getting…
Still not as oopsie-doopsie as when the Indian military left the PDB data present which displayed the developers first name and last name, but making the path "hack" is pretty oopsie too.
😁59👍4🤣3😢1
Malware 🤝Cat girls
❤‍🔥189😁26🤓20🔥174👍4🤝3🥰2😢2