vx-underground
49.4K subscribers
4.33K photos
469 videos
84 files
1.53K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Today the US Senate Committee of the Judiciary sat down with Directors from the NSA, CIA, FBI, and DoJ.

The committee unveiled last month, May 2023, the FBI conducted over 278,000 warrantless searches on United States citizens - accessing phone calls, text messages, and e-mails.

Only 19,000 were valid. The Senate Committee believes the remaining 259,000 were violations of the 4th amendment.

The FBI allegedly monitored individuals tied to Russia, ISIS, ransomware groups, China, and Black Lives Matter.
😱51👍9🔥9🤣6🤔5🫡4🎉1
We've updated the vx-underground Windows malware paper collection

- 2023-06-05 - Demonstrating how to kill EDR processes using a driver
- 2019-08-12 - Windows Process Injection via KnownDlls Cache Poisoning

Check it out here: https://www.vx-underground.org/windows.html
19👍3🤩2🎉1
Sometime in 2019 Lockbit ransomware group began referring to themselves as "post-paid-pentesters". They claimed they are beneficial to companies because they illustrate flaws in their security posture.

The new rapidly evolving 8Base ransomware group makes this same argument.
🤣67👍6🤔4🫡4👏1😢1🎉1💯1
Thank you, random woman on the internet, for the Hello Kitty / large collection of girly weaponry, vx-underground fan sign.
🔥105🤣35❤‍🔥1510🫡6😍4🎉2👍1😱1
Topor Live, a large Telegram-based news outlet based out of Russia, with over 3.9M followers, reported that REvil, Anonymous Sudan, and Killnet are going to take down the European banking system in 48 hours.

Following this attack, Linus Torvalds will switch to Windows.
🤣184😁14🤪11🎉8🔥4❤‍🔥3👍1🤔1
Pizza Hut's website in 1994.

Image via catalinmpit
❤‍🔥76🤩1911🤯7🫡5🔥4😁4👍2🎉1
This media is not supported in your browser
VIEW IN TELEGRAM
Here is footage released by "REvil" and Killnet about taking down the European banking system.

Since when did REvil ransomware group go on camera and publicly disclose their plans prior to attack? And why is "REvil" wearing a Slipknot mask?
🤣193👍12🤯12🫡11🤪75🎉4🤔2
Omnipotent, the previous administrator of the infamous RaidForums, delivered a message today. It was PGP signed thus confirming it is actually him.

It is an interesting message. We recommend everyone read it. It is attached below.
👍56🫡4311👏1😁1🎉1
Unrelated to malware, several individuals have been charged with trafficking stolen human body parts from Harvard Medical University.

The schools morgue manager received paypal memos with titles such as "head number 7" and "braiiiins".
🤪68🤣31🤯16👍8😱73🎉2🫡2
tl;dr if you're going to commit serious crimes, such as trafficking human organs, practice better opsec and do not blatantly admit your crimes on PayPal.

You can read the full indictment here: https://whdh.com/wp-content/uploads/sites/3/2023/06/CR.-NO.-4.23-CR-159-US-V.-CEDRIC-LODGE-KATRINA-MACLEAN-JOSHUA-TAYLOR-AND-DENISE-LODGE.pdf
🎉39🫡13🤣9👍4👏1😁1🤩1💯1
Today the United States Federal Bureau of Investigation announced the arrest of Ruslan Magomedovich Astamirov.

Astamirov is allegedly a long time member of Lockbit ransomware group with his attacks taking place between August, 2020 and March, 2023.

He is 20 years old.
🔥43😢27🫡16🤔8🤣6👍3👏2😱21🤯1
vx-underground
Unrelated to malware, several individuals have been charged with trafficking stolen human body parts from Harvard Medical University. The schools morgue manager received paypal memos with titles such as "head number 7" and "braiiiins".
Jeremy Pauley, 41, purchased human organs, bones, and he purchased two stillborn babies for ... collection?

The attached photo is of him. via WGAL8 TV
🤯62🤣18😱10🤪43👍2🫡2🔥1👏1😢1
This media is not supported in your browser
VIEW IN TELEGRAM
Killnet, the ghost of REvil past, and Anonymous Sudan announced in the 48 hours they would go 110% Mr. Robot and take down the European banking system, or something

24 hours are remaining. We're half way there.
🤣20312😁9🎉9🫡8👍5🤔4🙏4😱1💯1
Ernst & Young, a member of the CISA assembled RTF (Ransomware Task Force) has been a victim of cl0p ransomware group from the MoveIT 0day exploit.

Information via Brett Callow
🤣113😁9🤯8🫡6👏5👍42🎉2🤩2💯1
Today Polish authorities announced they made several arrests. The arrested people are allegedly connected to DdoS attack providers.

They released footage of the arrests. These are two images from the video.

The "Do not disturb" is the cherry on top.
🤣113🫡13🤯74🤔4🥰1😢1🎉1
Media is too big
VIEW IN TELEGRAM
Here is the full video of the Polish CBZC (Central Bureau for Combating Cybercrime) arresting individuals associated with DDoS as a Service providers.

Viewer discretion is advised. The levels of dorkiness are off of the charts.
😁58🫡25🤪14🤣11😢9🔥21👍1🎉1
👍10.1K🤣134😁27💯9🤩5🫡5🔥3😱2🎉1
We asked Lockbit ransomware group administrative staff their thoughts on the recent arrest of their affiliate Ruslan Magomedovich Astamirov.

Lockbit staff replied: "he should have practiced better opsec."
🤣87😁56🫡9🤪8👍6👏5🤯2💯2🎉1
Google has sold Google Domains to SquareSpace for $180,000,000.

Reminder that any product Google produces, they will kill off and send to the infamous Google graveyard.
🤔58😁14🫡14👍72🥰2🎉1
The United States government has put a $10,000,000 bounty on any individual associated with cl0p ransomware group.
🤣89😁19🫡16🥰7👍6😱4🤪4❤‍🔥3🔥2👏1🤔1