vx-underground
47.7K subscribers
4.14K photos
441 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Microsoft has announced it intends on modernizing Windows Explorer

This is a preview image that has been released.
๐Ÿคฎ141๐Ÿ—ฟ20๐Ÿคก12๐Ÿ‘4๐Ÿ˜3๐Ÿค”1๐Ÿ˜ˆ1
Why does vx-underground archive The Old New Thing? This is why:
๐Ÿ‘39๐Ÿ˜11๐Ÿ˜ˆ1
Yesterday Yandex's Git repository was leaked. It has resulted in dozens of hardcoded credentials being exposed.
๐Ÿ”ฅ78๐Ÿ˜18๐Ÿ‘3๐Ÿ‘Ž3๐Ÿ˜1๐Ÿ˜ˆ1
Since we shared news on the Riot games breach we have seen a flood of League of Legends players. They are funny.
๐Ÿ˜60๐Ÿ”ฅ12๐Ÿ‘2๐Ÿ˜ˆ2
HIVE ransomware group's Tor domain has been seized by EUROPOL

*No official announcement yet from United States Department of Justice or EUROPOL
๐Ÿคฌ33โค9๐Ÿ˜6๐Ÿ˜ข2๐Ÿ’ฉ1๐Ÿคก1๐Ÿ˜ˆ1
The United States Department of Justice has stated in their official press conference, regarding the disruption of HIVE ransomware group infrastructure, that they "hacked the hackers" to disrupt their operations and infrastructure. They state they have decrypted 1,500 companies.
โคโ€๐Ÿ”ฅ18๐Ÿคช8๐Ÿ–•6๐Ÿ‘5๐Ÿ˜3๐Ÿคก3๐Ÿ˜ˆ1
This is the 2nd time, that we are aware of, that the United States Department of Justice, has admitted to using offensive operations to take down, or disrupt, ransomware groups.

The DoJ has announced that they are now focusing their efforts on HIVE affiliates and developers.
๐Ÿคก5๐Ÿ‘2๐Ÿฅฐ1๐Ÿ˜ˆ1
The United States government has admitted, for the 2nd time, to utilizing offensive operations against ransomware groups

tl;dr ransomware group with 24/7 SOC
๐Ÿ’ฉ32๐Ÿคฃ20๐Ÿ”ฅ4๐Ÿคก4๐Ÿ‘2โค1๐Ÿ˜1๐Ÿ˜ˆ1
Conspiracy theories galore online right now as people speculate that the NSA used a 0day exploit to compromise HIVE. Others suggest it was an inside job - an admin at HIVE leaked information to EUROPOL agents.

Reality: Phishing (probably)
๐Ÿ‘24๐Ÿค”9โค6๐Ÿ˜4๐Ÿ”ฅ3๐Ÿ˜ˆ2
Ransomware group comment to the HIVE take down:

ALPHV: This would not work on us, we have too strong security and we do not store anything on our servers

BianLian: Too bad. I think they will be restored under a new name

Lockbit: Nice news. I love when FBI pwn my competitors
๐Ÿคฃ66๐Ÿ”ฅ12๐Ÿ˜ˆ5๐Ÿ‘3๐Ÿ’ฉ3๐Ÿ‘1
The Yandex leak has shown that Yandex uses racial slurs as variable names.

Text translation:

Github: We renamed Master to Main so it is not associated with racism

Yandex:
๐Ÿ˜81๐Ÿฅฐ13๐Ÿ‘7๐Ÿ‘Ž5๐Ÿฅด5๐Ÿคฃ4๐Ÿ‘2๐ŸŒญ2๐Ÿ˜ˆ1
Lockbit ransomware group has informed us they have acquired a 3rd ransomware variant.

- Lockbit Red
- Lockbit Black
- Lockbit Green

They also have modified their ESXI ransomware variant.

Yes, they actually wrote "TLP:RED" in the image.
๐Ÿ‘19โคโ€๐Ÿ”ฅ7๐Ÿคก6๐Ÿ˜ˆ3
What the hell is wrong with you nerds?
๐Ÿคฃ66๐Ÿ”ฅ6๐Ÿคก6๐ŸŽ‰4โคโ€๐Ÿ”ฅ3๐Ÿ’‹2๐Ÿ˜ˆ1
This media is not supported in your browser
VIEW IN TELEGRAM
It is of the utmost importance we relay this information to all of you:
๐Ÿ”ฅ27๐Ÿฅฐ11๐Ÿ’ฉ10๐Ÿคฏ5๐Ÿคก5๐Ÿ˜3๐Ÿณ3โ˜ƒ2๐ŸŒš2๐Ÿ˜ˆ2๐Ÿ˜1
Yandex confirms usage of racial slurs in company source code. Yandex states the code which uses racial slurs did not affect company services (?), and was only used internally. They stated the racial slurs violate company policy and have apologized

https://cyberscoop.com/racial-slurs-discovered-in-leaked-yandex-source-code/
๐Ÿ˜46๐Ÿ‘4๐Ÿฅฐ2๐Ÿ”ฅ1๐Ÿ‘1๐Ÿคฌ1๐Ÿ˜ข1๐Ÿ†1๐Ÿ˜ˆ1
We've updated the vx-underground malware sample collection

- Virusshare.00456
- Virusshare.Android.APK.2022
- 36,260 new malicious binaries added
- All named using Kaspersky naming convention

Check it out here: https://samples.vx-underground.org/samples/Blocks/
๐Ÿซก19๐Ÿ‘4โค2๐Ÿฅฐ1๐Ÿ˜ฑ1๐Ÿ˜ˆ1
General updates:

- 45TB+ of data delivered in the past 28 days
- 95% completion of The Old New Thing archive
- 15% of malware collection synced with Tria.ge
- ???
๐Ÿ‘21๐Ÿคก3๐Ÿฅฑ1๐Ÿ˜ˆ1
Sebastien Raoult, an alleged member of ShinyHunters group, has been extradited from Morocco following a request from the United States government. He is currently in Seattle, Washington.

He is facing 116 years in prison. He has plead not guilty.

https://www.justice.gov/usao-wdwa/pr/alleged-french-cybercriminal-appear-seattle-indictment-conspiracy-computer-intrusion
๐Ÿคฏ19๐Ÿ‘3๐Ÿ”ฅ2๐Ÿ˜ข2๐Ÿ˜1๐Ÿคก1๐Ÿ˜ˆ1
There is a very real possibility that sometime in the future, your children, or grandchildren, will ask if you've ever heard of vx-underground.

You can happily tell them you followed us from our beginnings on Telegram.

They will respond with: "what the hell is a Telegram?"
๐Ÿคฃ105โค23๐Ÿ‘6๐Ÿ”ฅ6๐Ÿคก4๐Ÿฅฐ3๐Ÿ’ฉ2๐Ÿ˜ˆ2๐Ÿ™1๐Ÿ–•1๐Ÿ†’1