vx-underground
51K subscribers
4.48K photos
484 videos
84 files
1.56K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
The FBI after I keep sending them e-mails with pictures of cats for literally no reason (they hate my guts)
πŸ₯°87🀣25❀23😁7😎5❀‍πŸ”₯2😒1πŸŽ‰1
This media is not supported in your browser
VIEW IN TELEGRAM
Welcome to my DMs
❀145πŸ₯°50🀣26πŸ”₯11😁8❀‍πŸ”₯3πŸ‘3😍3🀯1😒1
> be UK
> post racism memes
> say schizo stuff
> 2 years in prison
> ransom critical infrastructure
> make millions from cybercrime
> 5 years prison
> eligible for release in 2 years

I don't understand the UK
🀣256❀26😁12πŸ’―8😎6πŸ‘5πŸ€”4πŸ”₯3🫑3πŸ₯°2😱2
Malware
❀193😱120🀯47πŸ”₯19❀‍πŸ”₯16πŸ’―9πŸ‘8πŸ€“8πŸ™6πŸ₯°3😒2
Maybe a year ago, I don't remember, a game appeared on Steam called BlockBlasters. BlockBlasters was actually malware, and it gained recognition primarily because it was used to crypto drain a terminally ill cancer patient.

I was the first person (to the best of my knowledge) to reverse engineer BlockBlasters after people began notifying me about the game on Steam potentially being malware.

It ended up being a huge deal, primarily because BlockBlasters was used for targeted crypto draining campaigns.

Anyway, the FBI has begun arresting the people. The first person arrested was 21 year old Zyaire Dontaevious Zamarion Wilkins, based out of Florida. I assume more arrests are coming.

This person specifically made $220,000 from the malware campaign, with $32,000 coming from a terminally ill (now deceased) cancer patient.
😒144πŸ˜‡26πŸ‘18❀13😁7🀣3πŸ”₯1
vx-underground
Maybe a year ago, I don't remember, a game appeared on Steam called BlockBlasters. BlockBlasters was actually malware, and it gained recognition primarily because it was used to crypto drain a terminally ill cancer patient. I was the first person (to the…
tldr you sending me malware is good, sometimes really interesting things happen. Thank you for sending me malware.

Also, I really want to note I didn't do any investigative work or whatever, I just reverse engineered it, explained how it works, noted some IPs or crypto wallets, nothing else. I'm just the malware guy. I'm nothing else. There were a lot of people who came together after BlockBlasters appeared that did really cool stuff and helped a lot of people. Lots of people shared information publicly which identified people. I'm just bonking stuff with sticks and looking at cats
πŸ˜‡110❀26πŸ‘11πŸ‘3❀‍πŸ”₯1πŸ’―1
> x ad revenue sharing?
> down.
> monthly vx-underground donors?
> losing more.
> vx-underground sponsors?
> lost more.
> pictures of silly cats?
> up 8000%
πŸ‘153🀩25πŸŽ‰13😒10❀8πŸ₯°2❀‍πŸ”₯1🀣1πŸ˜‡1
Chat, big shenanigans are afoot. Zyaire Dontaevious Zamarion Wilkins, one of the individuals behind the "BlockBlasters" steam malware campaign, also social engineered people online by pretending to be a woman.

Wilkins, and a currently unlisted number of people, worked to spearphish people who owned cryptocurrency. They published a fake game on Steam named "BlockBlasters" which received international attention for crypto draining a terminally ill cancer patient.

It turns out Wilkins also impersonated a person named sibeleth

That girl who was flirting with you, asking about how much money you hold in crypto, was actually a 21 year old African American man
🀣150❀21🫑8πŸ”₯5πŸ₯°2🀯2❀‍πŸ”₯1😁1😱1
Was laying in bed this morning thinking of Satya Nadella (CEO of Microsoft).

He makes me feel warm and fuzzy inside.

I'm so excited to hear about the new additions to Windows next quarter. It's going to be more features we can use for malware. I'm so excited. He's awesome
🀣136❀24πŸ₯°8😁7😍3🀯2🫑1😘1
vx-underground
Was laying in bed this morning thinking of Satya Nadella (CEO of Microsoft). He makes me feel warm and fuzzy inside. I'm so excited to hear about the new additions to Windows next quarter. It's going to be more features we can use for malware. I'm so excited.…
Literally every 3 or 4 months Satya Nadella serves us up a big slop pot of abusable features. He's a malware factory
🀣110❀21πŸ’―7πŸ‘4πŸ₯°4😁3❀‍πŸ”₯2πŸ”₯2
This media is not supported in your browser
VIEW IN TELEGRAM
The kids are making anti government surveillance memes and I love it.
❀149🀣62πŸ₯°5😁4πŸ’―3❀‍πŸ”₯1
vx-underground
The kids are making anti government surveillance memes and I love it.
If this were a meme made by someone in my age group it would be something like, "how I walk when I have hemorrhoids"
🀣123πŸ”₯10😁8❀7πŸ₯°4πŸ’―3😱2🀝2❀‍πŸ”₯1🀯1
Administrative update:

1. I am going to begin the process of thanking people for malware submissions and/or papers and/or recommendations. They will be placed somewhere on the website. You can exaggerate yourself on LinkedIn and say you're a collaborator.

2. I have a large volume of malware papers and malwares in queue. It is 175,000 malwares, 20 or so papers. As is tradition, malware analysis will be coupled with the papers too. That is expanded every month as new material comes in.

3. I have no plans to resurrect the virus exchange for the time being, unless someone (preferably a large company) is willing to bank roll the entire thing. I can provide the malware goopies, but computers are expensive.

4. Per request from OG vx-underground nerds, in more serious posts discussing technical topics, I will drop the silly cats and instead revive the classic edgy vx-underground dark. I will introduce a balance between seriousness, and edgy Hot Topic Goth, and generate kitty cat stuff.

Thank you everyone for the love and support. I see your messages and e-mails. I am enjoying the summer with my son and family, so I am simply less inside at the moment. I will (hopefully) do more malwares soon.
❀92πŸ₯°9πŸ”₯7😒6
vx-underground
Administrative update: 1. I am going to begin the process of thanking people for malware submissions and/or papers and/or recommendations. They will be placed somewhere on the website. You can exaggerate yourself on LinkedIn and say you're a collaborator.…
Oh, I forgot. One other thing.

I had a few people say I should focus more on news. People said using keywords like "breaking" can improve engagement and potentially bring more people to this social media account.

I appreciate the insight, feedback, and thoughtfulness. However, I am very much ... I don't know the word ... I guess I don't really give a fuck bro. Yes, people and monies and stuff is cool, but I don't want to be a slop account. I'm just going to continue doing what I'm doing.

Malware source code, samples, and papers for free, forever.

Cheers
πŸ₯°94❀29πŸ”₯10❀‍πŸ”₯5🀣3πŸ‘1πŸ˜‡1
Have you ever accidentally lost 50,000 malwares?

I downloaded 50,000 malwares and I don't know where it went.

No, I'm serious, I actually have no idea where the malware went. I'm confused and scared.

Have you seen my malware?
🀣175😱29❀16😁4🫑4🀯3πŸ™3πŸ₯°2πŸŽ‰2😎2
Hello, People Living Inside My Computer (PLIMC),

If you're someone who enjoys malware, I have good news.

If you're someone who dislikes malware, I have bad news.

I have uploaded 176,000 malwares and some malware papers. Please download it.

https://vx-underground.org/Updates
❀49πŸ”₯6πŸ‘4😱3πŸŽ‰1
> be me
> havent taken malware inventory in a long time
> lol how much malware do i actually have?
> usually estimate 32,000,000-ish
> look inside

Argus Collection (archived): 24,830
ATM Malware (archived): 285
Bazaar (actively collected): 733,985
Families (retired): 122,888
InTheWild (actively collected): 8,195,377
Malware Analysis (actively collected): 53,746
Malware Ingestion (retired): 7,511,822
OpenSourceMalware (archived): 40
Twitter IOC Collection (archived): 40,324
VirusShare (actively collected): 23,775,600
VirusSign (actively collected): 1,786,542

Total malwares: 42,225,439
Total archives (7z files): 128,786
Total size: 12.9TB (7z ultra compressed)
Time performed collecting malware: 2,618 days
❀39🫑21πŸ”₯8🀣8πŸ‘1
Found a compromised website with ClickFix that successfully bypasses uBlock. The ClickFix payload uses LOLBINs and uses a WebDAV server. It was promising.

The C2 is dead.

YOU LIED TO ME
πŸ₯°18😁4πŸ€”1😘1
vx-underground
Found a compromised website with ClickFix that successfully bypasses uBlock. The ClickFix payload uses LOLBINs and uses a WebDAV server. It was promising. The C2 is dead. YOU LIED TO ME
Wait, no. The C2 domain changed and the C2 blocked my IP.

Give me your goopies.
πŸ”₯21πŸ₯°7❀2😁1πŸ€”1🀯1πŸ’―1