vx-underground
46.2K subscribers
3.96K photos
421 videos
83 files
1.45K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
The United States government is investigating a spy-balloon which has been in its airspace for several days. Senior defense officials at the Pentagon have stated with "very high confidence" it is Chinese

The United States Airforce has been deployed.

Unrelated to malware, of course. However, this plays into the geopolitical and espionage subject we typically explore with state sponsored activity.

More information: https://apnews.com/article/chinese-surveillance-balloon-united-states-montana-47248b0ef2b085620fcd866c105054be
๐Ÿ˜34๐Ÿ˜8๐Ÿ‘6๐Ÿคก5๐Ÿ˜ฑ3โค2๐Ÿฆ„1
Good morning Telegram
Good morning NSA
Good morning Chinese spy balloon
๐Ÿคฃ81๐Ÿ”ฅ24๐Ÿคก14โค7๐Ÿ˜4๐Ÿฆ„1
We need a volunteer - a volunteer full-stack developer who is motivated and has sufficient time to assist us.

We do not have much money. We have the budget of 1 slice of pizza. We also have pseudo-Twitter clout and some crappy clothes.
๐Ÿฅฐ31๐Ÿ˜11๐Ÿคก3๐Ÿ‘2๐Ÿฆ„1
๐Ÿšจ BREAKING๐Ÿšจ

vx-underground has obtained exclusive images of the Chinese spy balloon currently in United States airspace. An official source from the Pentagon has told vx-underground these images are authentic
๐Ÿคฃ99๐Ÿคก7๐Ÿ˜5๐Ÿ˜ญ3โค1๐Ÿ”ฅ1๐Ÿฆ„1
Tallahassee Memorial hospital, in Tallahassee, Florida, is redirecting patients to other healthcare facilities and cancelling and/or rescheduling medical appointments due to a "cyber attack".

Something needs to be done - this cannot be tolerated any longer.
๐Ÿคฌ24๐Ÿ˜ข7๐Ÿ‘4๐Ÿคก2๐Ÿฆ„2
IKOULA is reporting their clients are experiencing semi-automated ransomware attacks targeting ESXi versions 6.5 and 6.7.

Speculation: CVE-2021โ€“21974

Intel via ValeryMarchive & S0ufi4n3

Edit:

OVHcloud has released a blog post about it. They believe it is large scale and primarily affecting Europe

More information: https://blog.ovhcloud.com/ransomware-targeting-vmware-esxi/
๐Ÿ”ฅ10๐Ÿ‘4๐Ÿคก2๐Ÿฆ„1
It appears Microsoft accidentally published some dev code to prod. It unveiled Bing plans on soon implementing ChatGPT into their search engine. Microsoft has reverted the push, however Owen_Yin managed to take some images of the new search engine.

tl;dr Bing coming for Google
๐Ÿ”ฅ34๐Ÿฅด6๐Ÿคฉ3๐Ÿฆ„2
vx-underground
It appears Microsoft accidentally published some dev code to prod. It unveiled Bing plans on soon implementing ChatGPT into their search engine. Microsoft has reverted the push, however Owen_Yin managed to take some images of the new search engine. tl;drโ€ฆ
Reminder Microsoft laid off 10,000 people and invested $10,000,000,000 into ChatGPT just a few days later

tl;dr tl;dr Microsoft making power moves
๐Ÿคฃ46๐Ÿ”ฅ5๐Ÿฆ„2๐Ÿพ1
New vx-underground art by deinacrida_art
๐Ÿ”ฅ80โคโ€๐Ÿ”ฅ10๐Ÿ‘9โค6๐Ÿ–•2๐Ÿฆ„2๐Ÿคก1
This media is not supported in your browser
VIEW IN TELEGRAM
The United States Air Force has deployed a Lockheed Martin F-22 Raptor and shot down the Chinese spy balloon.

R.I.P Chinese spy balloon. Gone but not forgotten.

Footage via some random dude in South Carolina who has received no credit from CNN or Twitter
๐Ÿคฃ53๐Ÿซก21๐Ÿ‘4๐Ÿฆ„3
๐Ÿ•Š65๐Ÿซก36๐Ÿ˜9๐Ÿคช6๐Ÿ‘3๐Ÿคก2๐Ÿคฃ2๐Ÿฆ„2๐Ÿ˜ข1๐ŸŒš1
โค57๐Ÿคก13๐Ÿ˜4๐Ÿฆ„3๐Ÿ‘1๐Ÿ–•1
We are nearly finished with our second large scale project.

We have assigned a date-of-release to every paper in the vx-underground collection (with the exception of the Archive section). Ideally, this will be completed in the following week.

tl;dr you can see find newer papers
๐Ÿ”ฅ13๐Ÿ‘4๐Ÿฆ„1
๐Ÿ˜38๐Ÿคฃ17๐Ÿฆ„3๐Ÿ˜ข2
Julius Kivimรคki, a member of Lizard Squad, has been arrested (again). He was previously arrested in 2015 on 50,000 counts of computer crimes

He has been arrested in France and is soon to be extradited to Finland for extorting a therapist center in 2020

Intel via RecordedFuture
๐Ÿคก60โšก4๐Ÿ‘จโ€๐Ÿ’ป4๐Ÿ‘2๐Ÿฆ„2
The recently identified ESXiArgs ransomware group has infected hundreds of ESXi hosts across the globe with a CVE-2021-21974 spray-and-pray.

Numbers vary, but Shodan queries from various researchers show an est. 300 - 500 ransomed entities this weekend.

tl;dr TA like:
๐Ÿ‘14๐Ÿ˜6๐Ÿ˜2๐Ÿฆ„2๐Ÿ˜ฑ1
This media is not supported in your browser
VIEW IN TELEGRAM
"VXUG gives a voice to Threat Actors"

"VXUG has sold out, they charge for access to the MWDB"

"VXUG tweets too many memes"

"VXUG swears too much in their tweets, its unprofessional"

"VXUG made a Threat Intel feed, they're helping White Hats"
๐Ÿ”ฅ26๐Ÿคฃ19๐Ÿฆ„2