vx-underground
47.6K subscribers
4.12K photos
440 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
If you follow GuidedHacking on Twitter you can watch the owner, Rake, slowly descend into lunacy.
๐Ÿ‘11๐Ÿ˜ข8๐Ÿคก4๐Ÿฅด1๐Ÿ˜ˆ1
We've updated the vx-underground InTheWild collection. We've added volumes 0029, 0030, and 0031. Thsi is 60,000 unique malicious binaries.

Special thanks to petikvx for the hard work and staying on top of sample aggregation for us.

Have a nice day.

https://www.vx-underground.org/malware.html
๐Ÿ”ฅ7๐Ÿ˜ˆ1
Earlier today Jon DiMaggio released an article titled: "Ransomware Diaries: Part 1". This article is one of the most comprehensive papers on Lockbit ransomware group we have ever seen.

Our personal 2-extra-cents on the paper: the article states the Lockbit Black source code was leaked - this is incorrect. Additionally, the author cites John Hammond for releasing a tweet on the Lockbit Black leak - although the truth is John Hammond archived a tweet we deleted. The image posted in the article is directly from us - we typically use HasteBin to display text-images.

For those questioning why we deleted the tweet: Lockbit is notorious for chasing individuals down, and is sometimes bloodthirsty. We will spare the details - but we decided it would be best to not involve ourselves in ransomware conflict which directly impacts their operations.

We spoke with LB0, the individual who we believe is the troll of LockbitSupp. vx-underground staff and LB0 spoke - we came to a mutual agreement to not leak the Lockbit Black builder until someone else did (if it did). We did not want drama. We are a library, not a battlestation.

Finally, and in conclusion, Jon DiMaggio's paper is wonderful and spot on. Thank you, Jon, for detailing the history and evolution of this group.

Link: https://analyst1.com/ransomware-diaries-volume-1/
๐Ÿ”ฅ21๐Ÿ‘13๐Ÿ˜ˆ1
We've updated the vx-underground The Old New Thing archive. We have completed archiving years 2012 and 2011.

We have successfully archived over 10 years of blog posts from Raymond Chen. 7 years are remaining!

Check it out here: https://www.vx-underground.org/the_old_new_thing.html
๐Ÿ‘11โค2๐Ÿ”ฅ1๐Ÿคก1๐Ÿฅฑ1๐Ÿ˜ˆ1
Shoutout to the person impersonating us on Telegram.

It's a ballsy move trying to scam malware researchers... with your... *checks notes* ... crypto scam?

https://assetssecuritybackup[.]com
๐Ÿคฃ29๐Ÿ˜16๐Ÿคก5๐Ÿ˜ˆ1
Reminder: vx-underground will never individually message all 14,000 people that follow this Telegram account ... because we could just send a post a message to relay "crucial information" on our "chan-nel".
๐Ÿ‘25๐Ÿ‘8๐Ÿฅฐ8๐Ÿคฏ3๐Ÿคก3๐Ÿ’ฉ2๐Ÿ˜1๐Ÿ˜ˆ1
As Microsoft tightens loose ends and macro-based malware droppers become more difficult for Threat Actors to leverage - data traffickers are increasingly abusing SEO poisoning and/or malvertising.

Intel via malwrhunterteam & wdormann
๐Ÿ‘27๐Ÿคก6๐Ÿ˜ˆ2
We are happy to announce the latest sponsor to vx-underground: GuidedHacking.

GuidedHacking is a game hacking educational website - they're the individuals who published the "Game Hacking Bible"

GuidedHacking would like to note that they are the best penis enhancement pills.
๐Ÿ”ฅ43๐Ÿ†’8๐Ÿคก2๐Ÿ‘1๐Ÿ˜ˆ1
The United States Department of Justice is scheduled to make an announcement at 12PM EST regarding an International Cryptocurrency Enforcement Action

The broadcast will begin in 55 minutes.

https://www.justice.gov/live
๐Ÿคก2๐Ÿ˜ˆ2๐Ÿคช2
Someone sent us an image of their IDE. They said they believed the contrasting colors helped their vision.
๐Ÿฅด49๐Ÿคฎ29๐ŸŒš7๐Ÿ”ฅ6๐Ÿคก5๐Ÿ‘4๐Ÿฅฐ3๐Ÿ˜2๐Ÿคฏ2๐Ÿ˜ˆ1๐Ÿ—ฟ1
The Department of Justice has announced the arrest of Anatoly Legkodymov. Legkodymov, the Founder and Majority Owner of Bitzlato Ltd, is accused of laundering more than $700,000,000 in illicit funds from ransomware groups and Hydra Marketplace

More info: https://www.justice.gov/usao-edny/pr/founder-and-majority-owner-bitzlato-cryptocurrency-exchange-charged-unlicensed-money
๐Ÿซก18โšก4๐Ÿคก3๐Ÿ‘2๐Ÿ˜2๐Ÿคฌ1๐Ÿ˜ˆ1
Multiple Threat Intelligence and Anti-virus vendors have noted the rise of the MaaS Rhadamanthys Stealer. Rhadamanthys is noted as trafficking itself through malicious Google ads targeting AnyDesk, Zoom, Bluestacks, Notepad++, OBS, and more.

It also has a hard to remember name
๐Ÿ˜22๐Ÿคก8๐Ÿคฃ4๐Ÿ‘3๐Ÿ˜ˆ1
This media is not supported in your browser
VIEW IN TELEGRAM
Interview with a Russian ransomware operator arrested in Russia for attacking Western organizations
๐Ÿคก26๐Ÿ˜17๐Ÿ‘5๐Ÿ”ฅ5๐Ÿ‘Œ4๐Ÿ‘1๐Ÿณ1๐Ÿ˜ˆ1
2023 is going to be a big year for vx-underground. Besides the continual increase in malware samples, source code, and papers, we also intend on publishing 2 (maybe even 3!) books.

Also, as a reminder, we offer free malware database access to students of all ages

We are also discussing changing the website (again) to accommodate it's growth. Pages are too big and have too long of lists. The website will remain as grungy HTML, no flashy BS, WordPress, whatever. We just need to be better organized.

Have a nice day.
๐Ÿ‘36๐Ÿ”ฅ7โค5๐Ÿฅฑ3๐Ÿคก1๐Ÿ˜ˆ1
T mobile confirms it was breached (again) for the 6th.. or 8th time? Since 2018? We've lost count.
๐Ÿ”ฅ31๐Ÿคก11๐Ÿ‘4๐Ÿคฃ1๐Ÿ˜ˆ1
As Threat Actors continue utilizing Google-based malvertising campaigns - vx-underground has decided to step up to the plate and unveil a 1 of a kind solution to stop these nerds. Introducing ... an adblocker!

tl;dr we've done it, we've stopped cyber crime and saved the planet
๐Ÿ˜32๐Ÿคฃ15๐Ÿ‘7๐Ÿ‘2๐Ÿคก2๐Ÿ˜ˆ2๐Ÿคฏ1
Threat Actors when they see Google has laid off 12,000 employees, some of which are probably responsible for Google adwords
๐Ÿคฃ23๐Ÿ‘18๐Ÿ”ฅ2๐Ÿ˜ˆ2๐Ÿคก1๐Ÿฅฑ1