vx-underground
47.7K subscribers
4.13K photos
441 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
The newest @nico_n_art swag is absolutely disgusting

*not vx-underground merchandise
*purchases of this merchandise DOES NOT support us
*purchases of this merchandise DOES support our friend

https://transi.store/
๐Ÿคก20๐Ÿ‘Ž8๐Ÿ”ฅ8๐Ÿคฃ4๐Ÿ‘3๐Ÿ’‹2๐Ÿ˜ˆ1
Due to the absurd volume of people DMing me - we have re-opened the chatroom. We are in search of moderators who will actively monitor chatroom and nuke nerds who disobey the rules.

Here, have your dumb chatroom back, please stop asking us about it: https://t.iss.one/+80U_oTH2thk3ZDYx
๐Ÿ˜28๐Ÿ‘6๐Ÿคก5๐Ÿ•Š3๐Ÿ˜ˆ1
APT groups do not need to commit espionage to monitor foreign military threats. All that is required is making a WarThunder forum account
๐Ÿ˜28โค4๐Ÿ‘1๐Ÿคก1๐Ÿ’‹1๐Ÿ˜ˆ1
January 18th: Microsoft announces 10,000 employees will be terminated

January 23rd: Microsoft to invest $10,000,000,000 into ChatGPT
๐Ÿคฃ101๐Ÿ—ฟ16โค10๐Ÿ’ฉ6๐Ÿคก3๐Ÿ‘2๐Ÿฅฐ1๐Ÿค”1๐Ÿคฏ1๐Ÿฅฑ1๐Ÿ˜ˆ1
Yesterday someone claimed to have successfully breached vx-underground.

They sent us footage of the attack. We have no idea what is going on in this footage.

Video link: https://streamable.com/6nnhd3
๐Ÿคก56๐Ÿฅฑ6๐Ÿคฃ6๐Ÿคช4๐Ÿ‘1๐Ÿ˜1๐Ÿ˜ฑ1๐Ÿณ1๐Ÿ˜ˆ1
Google malvertising campaigns are becoming an increasingly widespread (and seemingly effective) method of initial access.

Researchers 1ZRR4H and malwrhunterteam have identified malware campaigns for Ursnif, Redline, Cobalt Strike, and Rhadamanthy in Google ads.
๐Ÿ‘9๐Ÿ˜ˆ4
As we mentioned a few days ago, corg_e and Nico_n_art would result in some weird mixture of traditional vx-underground dark art with kawaii, or something weird, whatever

*Images via Nico_n_art inspired by corg_e
๐Ÿ”ฅ32โค12๐Ÿคก7๐Ÿ‘5๐Ÿ’ฉ5๐Ÿฅฐ3๐Ÿคฏ2๐Ÿ†’2๐Ÿฅฑ1๐Ÿ˜ˆ1
This media is not supported in your browser
VIEW IN TELEGRAM
As more and more people discuss malicious Google ads we have decided to produce a small video illustrating how malvertising campaigns deploy malware to steal user data
๐Ÿคฃ32๐Ÿ‘5๐Ÿ˜3๐Ÿคก3๐Ÿ˜ˆ1
We've updated the vx-underground "InTheWild" collection. We have added volumes 0030 - 0034. It is 100,000 new and unique malicious binaries.

Special thanks to petikvx and our mystery donor for the samples.

Check it out here: https://samples.vx-underground.org/samples/Blocks/
โค15๐Ÿ˜ˆ1
"someone is going to hack vx-underground and upload malware onto it"

lol sweet free malware
๐Ÿคฃ77๐Ÿฅฐ13๐Ÿ˜7๐Ÿคก3๐Ÿ‘2๐Ÿ”ฅ2๐ŸŒš2๐ŸŽƒ2๐Ÿคฉ1๐Ÿ˜ˆ1
Channel photo updated
Several days ago Riot Games announced they were victim to a "social engineering attack". They stated they were being extorted for $10,000,000. Riot Games refused to pay the ransom

The source code to League of Legends is now up for sale online
๐Ÿคช50๐Ÿ‘5๐Ÿ‘3๐Ÿ˜ˆ2
We are currently speaking with the individual responsible for the breach on Riot Games.

They have informed us they have also stole Riot Games anti-cheat, Packman. Packman is the anti-cheat for both Valorant and League of Legends.
๐Ÿ”ฅ65๐Ÿ˜5๐Ÿคฃ5๐Ÿ‘3๐Ÿ˜ˆ2โค1
The individual responsible for the Riot Games breach has given us more information

- Social engineered an employee via SMS
- Initial goal was stealing Vanguard
- They pivoted through the network, was unable to get Domain Controller
- SOC detected them in approx. 36 hours
๐Ÿ’…37๐Ÿ‘9๐Ÿ˜ˆ6
vx-underground
The individual responsible for the Riot Games breach has given us more information - Social engineered an employee via SMS - Initial goal was stealing Vanguard - They pivoted through the network, was unable to get Domain Controller - SOC detected them inโ€ฆ
- They did not deploy any malware to the network
- Managed to escalate privileges by social engineering a company director
- They stated they would not give us more information at this time, more information will be shared in the following days

There is your free DFIR report
โค41๐Ÿ‘6๐Ÿ’‹4๐Ÿ‘2โšก1๐Ÿ˜ˆ1
Last update for the Riot Games breach. Here is the file directory listing of (some) of the exfiltrated data.

Goodnight (or good morning to some of you).
๐Ÿ”ฅ30๐Ÿ‘9๐Ÿ†3๐Ÿ˜ˆ1
This media is not supported in your browser
VIEW IN TELEGRAM
Threat Intelligence the second a significant breach occurs
๐Ÿคฃ65๐Ÿคก8๐Ÿ˜ˆ3๐Ÿ˜2๐Ÿ‘1
Microsoft has announced it intends on modernizing Windows Explorer

This is a preview image that has been released.
๐Ÿคฎ141๐Ÿ—ฟ20๐Ÿคก12๐Ÿ‘4๐Ÿ˜3๐Ÿค”1๐Ÿ˜ˆ1