vx-underground
47.7K subscribers
4.14K photos
442 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
This is the 2nd time, that we are aware of, that the United States Department of Justice, has admitted to using offensive operations to take down, or disrupt, ransomware groups.

The DoJ has announced that they are now focusing their efforts on HIVE affiliates and developers.
๐Ÿคก5๐Ÿ‘2๐Ÿฅฐ1๐Ÿ˜ˆ1
The United States government has admitted, for the 2nd time, to utilizing offensive operations against ransomware groups

tl;dr ransomware group with 24/7 SOC
๐Ÿ’ฉ32๐Ÿคฃ20๐Ÿ”ฅ4๐Ÿคก4๐Ÿ‘2โค1๐Ÿ˜1๐Ÿ˜ˆ1
Conspiracy theories galore online right now as people speculate that the NSA used a 0day exploit to compromise HIVE. Others suggest it was an inside job - an admin at HIVE leaked information to EUROPOL agents.

Reality: Phishing (probably)
๐Ÿ‘24๐Ÿค”9โค6๐Ÿ˜4๐Ÿ”ฅ3๐Ÿ˜ˆ2
Ransomware group comment to the HIVE take down:

ALPHV: This would not work on us, we have too strong security and we do not store anything on our servers

BianLian: Too bad. I think they will be restored under a new name

Lockbit: Nice news. I love when FBI pwn my competitors
๐Ÿคฃ66๐Ÿ”ฅ12๐Ÿ˜ˆ5๐Ÿ‘3๐Ÿ’ฉ3๐Ÿ‘1
The Yandex leak has shown that Yandex uses racial slurs as variable names.

Text translation:

Github: We renamed Master to Main so it is not associated with racism

Yandex:
๐Ÿ˜81๐Ÿฅฐ13๐Ÿ‘7๐Ÿ‘Ž5๐Ÿฅด5๐Ÿคฃ4๐Ÿ‘2๐ŸŒญ2๐Ÿ˜ˆ1
Lockbit ransomware group has informed us they have acquired a 3rd ransomware variant.

- Lockbit Red
- Lockbit Black
- Lockbit Green

They also have modified their ESXI ransomware variant.

Yes, they actually wrote "TLP:RED" in the image.
๐Ÿ‘19โคโ€๐Ÿ”ฅ7๐Ÿคก6๐Ÿ˜ˆ3
What the hell is wrong with you nerds?
๐Ÿคฃ66๐Ÿ”ฅ6๐Ÿคก6๐ŸŽ‰4โคโ€๐Ÿ”ฅ3๐Ÿ’‹2๐Ÿ˜ˆ1
This media is not supported in your browser
VIEW IN TELEGRAM
It is of the utmost importance we relay this information to all of you:
๐Ÿ”ฅ27๐Ÿฅฐ11๐Ÿ’ฉ10๐Ÿคฏ5๐Ÿคก5๐Ÿ˜3๐Ÿณ3โ˜ƒ2๐ŸŒš2๐Ÿ˜ˆ2๐Ÿ˜1
Yandex confirms usage of racial slurs in company source code. Yandex states the code which uses racial slurs did not affect company services (?), and was only used internally. They stated the racial slurs violate company policy and have apologized

https://cyberscoop.com/racial-slurs-discovered-in-leaked-yandex-source-code/
๐Ÿ˜46๐Ÿ‘4๐Ÿฅฐ2๐Ÿ”ฅ1๐Ÿ‘1๐Ÿคฌ1๐Ÿ˜ข1๐Ÿ†1๐Ÿ˜ˆ1
We've updated the vx-underground malware sample collection

- Virusshare.00456
- Virusshare.Android.APK.2022
- 36,260 new malicious binaries added
- All named using Kaspersky naming convention

Check it out here: https://samples.vx-underground.org/samples/Blocks/
๐Ÿซก19๐Ÿ‘4โค2๐Ÿฅฐ1๐Ÿ˜ฑ1๐Ÿ˜ˆ1
General updates:

- 45TB+ of data delivered in the past 28 days
- 95% completion of The Old New Thing archive
- 15% of malware collection synced with Tria.ge
- ???
๐Ÿ‘21๐Ÿคก3๐Ÿฅฑ1๐Ÿ˜ˆ1
Sebastien Raoult, an alleged member of ShinyHunters group, has been extradited from Morocco following a request from the United States government. He is currently in Seattle, Washington.

He is facing 116 years in prison. He has plead not guilty.

https://www.justice.gov/usao-wdwa/pr/alleged-french-cybercriminal-appear-seattle-indictment-conspiracy-computer-intrusion
๐Ÿคฏ19๐Ÿ‘3๐Ÿ”ฅ2๐Ÿ˜ข2๐Ÿ˜1๐Ÿคก1๐Ÿ˜ˆ1
There is a very real possibility that sometime in the future, your children, or grandchildren, will ask if you've ever heard of vx-underground.

You can happily tell them you followed us from our beginnings on Telegram.

They will respond with: "what the hell is a Telegram?"
๐Ÿคฃ105โค23๐Ÿ‘6๐Ÿ”ฅ6๐Ÿคก4๐Ÿฅฐ3๐Ÿ’ฉ2๐Ÿ˜ˆ2๐Ÿ™1๐Ÿ–•1๐Ÿ†’1
We've updated the vx-underground malware collection. We have added 40,000 new malware samples to our "In The Wild" collection.

- Volume 0035
- Volume 0036

Check it out here: https://samples.vx-underground.org/samples/Blocks/
๐Ÿ‘9๐Ÿ”ฅ5๐Ÿ˜ˆ1
This media is not supported in your browser
VIEW IN TELEGRAM
This video has millions of views and is appearing on Facebook, Instagram, and TikTok.

Key points:

- Don't check Facebook with your microwave
- Every product on the planet is based out of the United States, duh
- FBI agents glow in the dark
- The Matrix song goes hard
๐Ÿคฃ69๐Ÿคก15๐Ÿ‘9๐Ÿค“3โค2๐Ÿ˜ˆ1
We have finished archiving The Old New Thing blog from Raymond Chen. It is nearly 3 decades of articles - dates ranging from July, 2003 to December, 2022.

We will now begin our next large project.

Check it out here: https://www.vx-underground.org/the_old_new_thing.html
๐Ÿ”ฅ21โค3๐Ÿ‘2๐Ÿคก1๐Ÿ˜ˆ1
We've updated the vx-underground APT collection. We have added samples and papers from December 2022 and January 2023.

Special thanks to f0wlsec for the papers, samples, and aggregating the content as always

Check it out here: https://www.vx-underground.org/malware.html#2023
โค6๐Ÿคก1๐Ÿ˜ˆ1
We've updated the vx-underground InTheWild collection. We've added volumes 0037, 0038, 0039, and 0040. It is 80,000 new unique malicious binaries.

Special thanks to petikvx for aggregating the malware samples.

Check it out here: https://samples.vx-underground.org/samples/Blocks/
๐Ÿ‘8๐Ÿ˜ˆ2๐Ÿ‘1
Updating and aggregating content on Industrial Control System malware is a nightmare
๐Ÿคก32โค12๐Ÿ‘2๐Ÿ‘1๐Ÿ˜ˆ1
Kaspersky performed analysis on job postings on crime forums from January 2020 - June 2022.

- 200,000 advertisements
- 61% looking for programmers
- 45% offered remote work (?)
- 8% offered paid vacation and sick leave

https://securelist.com/darknet-it-headhunting/108526/
๐Ÿ”ฅ26๐Ÿคก9๐Ÿ‘5โคโ€๐Ÿ”ฅ1๐Ÿ˜1๐Ÿ˜ˆ1