vx-underground
49.4K subscribers
4.33K photos
469 videos
84 files
1.53K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
We've had people contact us who have read nearly every single paper in the vx-underground corpus - thousands upon thousands of malware papers.

vx-underground is a malware monastery and we are producing next-generation malware monks.
❀56πŸ™4πŸ‘2😱2❀‍πŸ”₯1
There has been some updates to the Pompompurin court case.

The United States Magistrate Judge John F. Anderson has authorized the usage of mass victim notification via a case-specific web page on the Eastern District of Virginia website.

tl;dr getting his own webpage😎
πŸ₯°26❀7😒4πŸ‘2πŸ€”2πŸ”₯1
This media is not supported in your browser
VIEW IN TELEGRAM
POV: you're talking to someone obsessed with privacy and online anonymity
🀣69❀7πŸ’―4πŸ₯°2😁1
Lockbit ransomware group has created their first MacOS-based payload. We believe this is the first time a large ransomware threat group has developed a payload for Apple products.

We have samples.

Intel via malwrhunterteam & BrettCallow

Download: https://samples.vx-underground.org/samples/Families/LockBitRansomware/Samples/
πŸŽ‰23❀9🫑5😒4πŸ”₯2πŸ€ͺ2❀‍πŸ”₯1πŸ‘1
It appears we are late to the game. The MacOS variant has been available since November 11th, 2022.
🫑55🀣21πŸ‘7😱3😒3❀1
Based on the tsunami of information we received:

1. The Lockbit MacOS ransomware is real. Lockbit has confirmed this.

2. People speculate it is incomplete. The MacOS payload is riddled with bugs - including a good ol' buffer overflow.

3. It is Sunday. We'll see you nerds later
πŸ‘45🫑15❀4πŸ”₯3
Unable to bypass UAC? Spam UAC prompt until the user presses 'Yes'.
🀣134πŸ₯°17🫑10🀩7❀2😁2
ALPHV ransomware group appears frustrated with Western Digital
πŸ”₯66😁16πŸ€ͺ4πŸ‘3🀣3🫑3πŸ€”2πŸ‘1😱1😒1
Today Microsoft announced they're changing the way they name and label threat groups. The new naming convention now aligns with "the theme of weather"

The new names are absolutely ridiculous and we are having a difficult time taking it seriously

See attached images for examples
🀣88πŸ‘7πŸ€”7
TA505, the group believed to be behind the Dridex Banking Trojan, Locky ransomware, and GlobeImposter ransomware, has been renamed internally at Microsoft Threat Intelligence.

TA505 is now known as Spandex Tempest
🀣85🀯6🫑6❀5😍3πŸ€”2
We've updated the vx-underground malware collection.

- Virusshare.00466
- Updates to the Redline family
- Updates to the Magniber family
- Updates to the xLoader family
- New family added: Mmon

Check it out here: https://www.vx-underground.org/malware.html
❀21πŸ‘1
πŸ₯°141🫑20πŸ”₯18❀‍πŸ”₯8πŸ€”8πŸ‘4😁2πŸ’―2❀1πŸŽ‰1
No major updates today. We are busy.

Please accept this image of a cat as a token of an apology.
🀩580πŸ‘381πŸ‘335❀333πŸ”₯148πŸ₯°144🫑11🀣7❀‍πŸ”₯5πŸ€ͺ3😍1
The 3CX supply chain attack was the result of previously undiscovered X-Trader supply chain attack

The 3CX CEO wasn't lying about an upstream vendor being the result of the compromise.

tl;dr supply chain attack to supply chain attack

More information: https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise
😱12πŸ‘7❀2😍2πŸ’―1
February 21st, 2023, ALPHV ransomware group informed their affiliates of a new 'product' update.

Their new ransomware variant is named Sphynx.
πŸ‘14🫑7πŸ”₯2❀1
We've updated the vx-underground malware sample collection. We have added new samples for the following families:

- Nanocore
- AsyncRAT
- NetwireRAT
- AgentTesla
- LokiBot
- Formbook
- CobaltStrike
- NjRat
- Chaos Ransomware

Check it out here: https://samples.vx-underground.org/samples/Families/
❀14πŸ”₯7πŸ‘2
You can subscribe to vx-underground Blueβ„’ for only $5.99/month.

Nothing is different, but you get a wear a dunce hat
πŸ’―41🀣29πŸ”₯4🀩4πŸ‘1πŸŽ‰1
Today someone stole 3,600lbs (1632kg) of Gold from the Toronto Pearson Airport. It is valued at roughly $100,000,000.

The police currently have no suspects. Unrelated to malware of course, but such a ballsy heist is impressive.

More information:
https://www.cbc.ca/news/canada/toronto/gold-heist-pearson-airport-toronto-1.6817345
🫑43πŸ₯°18❀5πŸ‘4πŸ‘2😁1🀩1😘1
An unknown Threat Actor has compromised the European Union's web domain and is using it to distribute Fortnite V-Bucks scams...

They've also compromised 15 other high-profile websites. See full list in attached image below.

Information via g0njxa and Gi7w0rm
🀣66πŸ‘3❀2πŸ‘2