vx-underground
46.2K subscribers
3.96K photos
421 videos
83 files
1.45K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
ITS FREE BTW
❀71πŸ™9πŸ”₯6🀣3πŸ‘1🀯1
Security Researcher ValdikSS discovered German law enforcement have been MITM-ing XMPP data from jabber-dot-ru for the past 90 days. ValdikSS believes the MITM on jabber-dot-ru could have been persistent for atleast 6 months.

https://notes.valdikss.org.ru/jabber.ru-mitm/
🀯51πŸ‘10❀‍πŸ”₯8🀣6🫑6😁3😱3πŸ€”2πŸ€“2
Today an individual known online as "Tongue" was sentenced to 13.3 years in prison for advertising (and carrying out) Violence-as-a-Service on Telegram and Discord.

He is 22 years old. He will be released when he is 35 in 2037.

More information: https://krebsonsecurity.com/2023/10/nj-man-hired-online-to-firebomb-shoot-at-homes-gets-13-years-in-prison/
🀣80🀯11😱10❀4🫑4πŸ˜‡3😁1😍1
Yesterday 1Password released an Incident Response Report believing that when Okta was breached (again) the Threat Actor(s) tried to pivot to them.

They noted they used MalwareBytesβ„’ FREE AV
🀣107😁15πŸ€”8❀‍πŸ”₯2😒2❀1πŸ‘1
We'd like to note there isn't anything necessarily wrong with an enterprise environment using MalwareBytes, but it just seemed kind of odd to specifically note the usage of the free version... or even the specific AV itself.
πŸ€“53πŸ‘13🀣3πŸ”₯2❀‍πŸ”₯1
October 20th security researcher rivitna2 noted the return of HIVE ransomware rebranded as Hunters International. Additionally, BushidoToken noted a 60% code overlap between Hunters International and HIVE.

Hunters International denies the allegations Β―\_(ツ)_/Β―
😁38πŸ‘3😱1
tl;dr "we are not HIVE, but we have their code"
😁60🫑6πŸ€“5πŸ‘2❀‍πŸ”₯1
We've updated the vx-underground Windows malware paper collection

- 2022-03-11 - AV and EDR Evasion Using Direct System Calls
- 2023-04-18 - Process injection in 2023 - evading leading EDRs
- 2023-07-25 - Prefetch - The Little Snitch That Tells on You

https://vx-underground.org/
🫑35❀‍πŸ”₯8πŸ‘4❀2πŸ”₯2
Yeah, we got compromised by APT29, but luckily MalwareBytesβ„’ FREE AV stopped the Kremlin in their tracks! To be extra safe, we swung by the local Hilton Hotel and used their WiFi to install it
🀣121😁10❀8πŸ”₯2πŸ€“2
Everyone knows Russians can't visit Hilton Hotels. They're too decadent. They instantly explode and turn into sand.
🀣87😁8πŸ€”5❀‍πŸ”₯3πŸ’―3πŸ‘1😒1πŸŽ‰1πŸ€“1
🀣120πŸ”₯38😱10❀7🫑6❀‍πŸ”₯5πŸ€“4πŸ˜‡4😎4πŸ‘1😒1
The vx-underground podcast - but instead of discussing anything technical or meaningful we mumble incomprehensible nonsense for an hour and express our misanthropy in form of creative dance
πŸ‘55😁13❀5πŸ₯°3🀝2πŸ”₯1
Media is too big
VIEW IN TELEGRAM
vx-underground staff for the entire podcast:
πŸ”₯34🀣20❀5πŸ‘2
Windows has 3 different types of boolean values.

typedef int BOOL
typedef BYTE BOOLEAN
typedef short VARIANT_BOOL

*BYTE is defined as an unsigned char

When setting VARIANT_BOOL you cannot use TRUE or FALSE. You need to use VARIANT_TRUE or VARIANT_FALSE

Have a nice day.
πŸ€“88🀣25πŸ”₯13🀯11❀10πŸ‘8🫑8😱6😒5πŸ€”3😁2
We are actively working on a guide for enterprise environments. It is titled: Prevention, Extortion, 'n' Information Security.

Here is a preview:
🀣49😁14πŸ”₯10❀‍πŸ”₯5🫑3❀2πŸ‘2🀯1😱1😒1
It's 2023. What the hell is going on over there in Australia?
🀣121😱8πŸ‘4😁4🀯4❀3πŸ€”3
Ccleaner was compromised and (limited) user data was exfiltrated. Luckily they're offering BreachGuard for 6 months! That's good, right?

... right?

Image via troyhunt
🀣89😱8πŸŽ‰5πŸ‘3
July 19th, 2010: Siemens PCS forum discussing Stuxnet
πŸŽ‰53πŸ€“23πŸ”₯5😱4πŸ‘2πŸ‘2
Another 116,024 malware samples queued and ready for upload into the VXDB 🫑

*Our VXDB is free for everyone to use
*You can download and search samples
*Bulk download coming (eventually)

https://virus.exchange
πŸ‘26❀12πŸ™3πŸ₯°2🫑2
Sometime in 2021 we were contacted by an incredibly angry person. He was upset we did not 'defang' our malware samples.

He informed us he executed ransomware on his host machine and all of his data was locked.
🀣241😁37😒13🫑11πŸ”₯7πŸ‘5πŸ‘5🀯4❀2πŸ€”2
We were just informed that a member of vx-underground lost two family members in Maine yesterday. A cousin and a nephew were the victims of a very sick person.

We will be inactive for the next couple of days.
😒369🫑71❀48πŸ™30😱7😁5🀣5πŸŽ‰3πŸ€”2🀯2πŸ˜‡1