vx-underground
46.1K subscribers
3.96K photos
421 videos
83 files
1.45K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Our account through Donorbox has been suspended citing that they believe we have violated their policy. We have not.

We have used DonorBox for several years now with no issue.

Without their services we will no longer be able to accept donations and survive:(
😒97🀯14😱8🀣8πŸ€”6🫑3😁2πŸŽ‰2πŸ₯°1
The big whoopsie has hit.

Earlier this morning nerds began informing us that equity traders were unable to place trades (or clear previous ones) through ICBC (Industrial and Commercial Bank of China).

An emergency notice was sent out stating:

"ICBC is currently unable to connect to DTCC/NSCC. This issue is impacting all of ICBC’s clearing customers, including [censored]. Because of this, [censored] is temporarily suspending all inbound FIX connections and not accepting orders at this time. We are in close touch with ICBC and will advise as soon as the issue is resolved. We are exploring all avenues to clear all 11/8 trades and will provide updates as they become available."

It was speculated that it was ransomware, however it was not confirmed and it was just rumors. If it was a technical issue it is bad. But, now that we know it is ransomware, it is much worse.

More information: https://www.ft.com/content/8dd2446b-c8da-4854-9edc-bf841069ccb8
🀣49😱5πŸ‘3❀1
CheckPoint Harmony EDR/XDR Agent 87.60.0273 for Windows, MacOS, and Linux leaked online today.

Leaker allegedly established a fake company to purchase the software Β―\_(ツ)_/Β―
πŸ‘38🀣35πŸ‘5πŸ€“3❀2
Per the request of many we are now selling physical copies of vx-underground.

- $500 (this includes shipping)
- Handwritten thank you letter
- 10TB Seagate external HDD
- Worldwide shipping
- Delivery times vary (location, queue, ???)

https://www.vx-underwear.org/products/vx-underground-collection-hdd
πŸ”₯86🀣19❀8πŸ‘1
Whats included?

- 37,745 APT papers and samples
- 7,147 archived materials (papers, old software, malware builders)
- 11,460 malware papers
- 36,000,000+ malware samples (5.06TB)
- 3,197 malware source code(s) file(s)
πŸ”₯61πŸ€“12πŸ‘1
Fuck you, Telegram, for placing ads on our posts. It gives the illusion like we're shilling bullshit.

Fuck ads.
πŸ‘229πŸ’―72🀣59🀯11🫑9😁7❀5😒5😱3πŸ₯°2😘1
November 10th, 2023 at approx. 6:35AM EST Poloniex cryptoexchange was 'drained' of over $30,000,000...

Information via AlvieriD- correction of sum by lcfr_eth

*Initial sum was $137,000, was off by $29,863,000 :)

Whoopsie proof: https://etherscan.io/address/0xa910f92acdaf488fa6ef02174fb86208ad7722ba
😱24🀣11❀5🀯3πŸ‘2😁1😒1
Fellow nerd RicardoJoseRF implemented our recent tweets about different 'whoami' methods in C#.NET. We initially wrote them in C++.

It's cool seeing stuff in other languages =D

You're corrupting all of us UK_Daniel_Card & HackingLZ

Link: https://github.com/ricardojoserf/WhoamiAlternatives/
πŸ”₯20❀4❀‍πŸ”₯3
vx-underground
November 10th, 2023 at approx. 6:35AM EST Poloniex cryptoexchange was 'drained' of over $30,000,000... Information via AlvieriD- correction of sum by lcfr_eth *Initial sum was $137,000, was off by $29,863,000 :) Whoopsie proof: https://etherscan.io/ad…
Correction made: it was $30,000,000 - blockchain nerds believe it is tied to APT Lazarus Group (North Korean government).
😁30🫑6😱4❀‍πŸ”₯2πŸ‘1
Questions we have been asked:

1. Will Boeing pay Lockbit ransomware group? No.

2. Was Lockbit responsible for the ransomware attack against ICBC? Yes

Source: Lockbit ransomware group administrative staff. They also want to explicitly state they are not Russian
🀣119πŸ‘16❀4πŸ’―3πŸ€“3
Butte School Districts shuts down computer network after system compromised.

Furthermore, as demonstrated in the image used by the news station, user xdolence tried using the ls command on Windows 😭
🀣125😁34🫑7πŸ”₯6😎5πŸ‘4πŸ€“3❀2πŸ₯°2πŸ˜‡1
This media is not supported in your browser
VIEW IN TELEGRAM
Nerds think having Lamborghinis, 'Iced out' watches, and wearing Balenciaga makes them look wealthy.

Wrong.

Real wealth and power is skating on GPUs.
πŸ”₯112🀣59🫑8😒7πŸ‘6😱5πŸ’―5❀4😁1
Malware is like an old can of peas.

It's been on the shelf for 20 years and it's still good
😁66🀣12❀‍πŸ”₯11πŸ‘9πŸ”₯3
This media is not supported in your browser
VIEW IN TELEGRAM
Company executives when they're asked if they've been compromised
🀣188😁16πŸ’―8🫑6πŸ‘2
Hello, how are you?

Due to increased sponsorships, donors, and nerds purchasing merchandise we are now increasing the volume of malware samples for nerds to reverse engineer, or build rules for, or something.

Have a nice day. Enjoy the rest of your weekend:)
❀137πŸ‘25🀣12❀‍πŸ”₯11πŸ₯°7πŸ”₯4
An unknown Threat Actor(s) claim to have compromised Coin Cloud.

They allege to have exfiltrated 70,000 customer selfies (via ATM cameras), and 300,000 customers PII which includes Social Security Number, Date of Birth, First Name, Last Name, e-mail address, Telephone Number, Current Occupation, Physical Address, and more. They allege to have data for individuals residing in the United States as well as Brazil.

They also claim to have stolen the source code to the entire backend of Coin Cloud.

Coin Cloud filed for Chapter 11 Bankruptcy in February, 2023.
🀣90❀9πŸ”₯9😒6πŸ‘5😱5🫑3πŸ₯°1😁1
Important updates:

1. We are establishing a 'schedule' to add some structure to our workflow (for the first time in 4+ years). Wednesday and Friday will be when updates are pushed to the website e.g. malware papers, archives, malware samples, etc. Monday, Tuesday, and Thursday will be dedicated to us aggregating content, posting nonsense, etc. Saturdays and Sundays we may or may not work, it depends entirely on our mood and what's happening.

2. Due to increased sponsorships, monthly donors, and people purchasing merchandise, we have successfully increased the volume of samples we are uploading to the VXDB. We are now aiming to upload 200,000+ malware samples a month.

3. We are still working on enhancing the website, making it scrapable, and allowing nerds to do mass downloads from the VXDB.

4. We are working on some limited edition merchandise for the holiday season for vx-underground. Additionally, all merchandise will be disconnected throughout the entire month of December.

5. We're going to be doing more giveaways this month. If you have a suggestion, let us know.

Have a nice day (night?). See you all tomorrow:)
πŸ”₯57❀19πŸ‘6πŸ™2
tl;dr schedule for adding stuff, more malware samples, still working on website, holiday merch and holiday sales, more giveaways
❀39🫑14πŸ‘5πŸ™1
We are doing another series of book giveaways on Twitter.

https://twitter.com/vxunderground/status/1724092349238693921
❀‍πŸ”₯20πŸ‘3πŸ”₯3❀2😒1🀣1