vx-underground
46.5K subscribers
4.01K photos
430 videos
84 files
1.46K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Health tip of the day
🤣99😁147👏1🤝1
Some important updates for vx-underground for the remainder of 2023:

- More giveaways of educational content coming. Unfortunately, we are relatively busy and we are having a difficult time giving away so much material so fast. Be patient! We have 4 more remaining! This totals roughly $55,000 in educational content given away for free to you beautiful bastards.

- Harddrive pre-orders are being cloned. New purchases will begin cloning in January, 2024

- Updates to vx-underground content will be slow, if even at all, for the remainder of 2023 as we enjoy the holiday season and vacation time 😎

Important updates to vx-underground in 2024:

- Improve site search functionality
- Improve site scrapability for degenerates
- Give away educational content once per month
- December, 2024 will be giveaways all month (again)
- Black Mass Vol 3 will be released
- Black Mass Vol 4 ¯\_(ツ)_/¯
- Allow API querying and downloading in VXDB
- Add 'recent additions' feed to website
- Reactivate Twitter ransomware bot
- New merchandise? ¯\_(ツ)_/¯

Thank you for everyone who sponsors, donates, purchases things from us, and interacts with our posts. All of these things allow growth which brings in revenue. This increases the sites performance and materials without charging money to people and without us worshipping corporate overlords.

We look forward to serving all of you in 2024.

I love you
49🔥7👍3🥰2
vx-underground talking with vendors and CERTs trying to get free stuff
🤣13313😁7🤓1
When we asked a vendor for free stuff and they asked us what our 4th quarter social media strategy is

(we don't have strategies)
😁94🤣59🫡5
POV: Cybersecurity companies seeing a small to medium sized business being hit by ransomware after declining to pay $150,000/month for their product
🤣14830🔥10💯6😁1😢1🤓1
Comcast has reported a security breach impacting 35,879,455 Xfinity customers. It is reported the breach was discovered December 6th, 2023 with a suspected initial breach date of mid-October, 2023.

Information via BrettCallow
🤣474🔥3😢3👍1🤓1
ALPHV ransomware groups website has been seized

Information via AlvieriD
🤯60🫡32😢14👏11🤓3👍2🤣1
vx-underground
ALPHV ransomware groups website has been seized Information via AlvieriD
Previously ALPHV ransomware group reported to us that their website was offline due to hardware failure. This has happened to them in the past, so the excuse was plausible. However, as you can see from the image above, it was not hardware failure.
🤣75😢54🔥3
ALPHV ransomware group administrative group has contacted us to inform us they have moved their servers and blogs.

*Image translated from Russian to English
🤓58😱158🔥5🤝3🤣2
Today the United States government released an official statement regarding ALPHV ransomware group.

They unveiled they have a decryption tool for ALPHV and, with cooperation with international partners, decrypted over 500 companies

More information: https://www.justice.gov/opa/pr/justice-department-disrupts-prolific-alphvblackcat-ransomware-variant
😱43👍18🔥13😢12👏9🫡8❤‍🔥33🤣3
The FBI ALPHV search warrant states that a confidential informant got access to the ALPHV panel.

Then the FBI did an ... 'investigation' on the ALPHV panel, managed to get visibility into the ALPHV network, got 946 private/public keys and access to other affiliate panels (???)
🤔59🤯28👏11😢9🤣8👍6🤓2😁1
Welp, today Kingdom Market was seized by German authorities. The German authorities also notified individuals of the domain seizure on Dread ... with Kingdom Marketplaces administrators PGP key ...

😭😭oh my god
😁56😢16🤣14🤯8👍4👏4😘4🤓1🫡1
ALPHV has ... unseized their domain?

They claim the FBI compromised one of their data centers. Additionally, they state they are removing all rules from their affiliate program (omit the rule on targetting the CIS) - allowing affiliates to target critical infrastructure
🤣126💯13🔥115❤‍🔥4🥰2👍1😁1
tl;dr summary of United States government (and associated entities) vs ALPHV ransomware group

December 10th, 2023: ALPHV primary domain goes offline, administration saying it is hardware failure

December 10th, 2023: Rumors circulate that is it LE taking down ALPHV

December 11th, 2023: ALPHV denies allegations

December 19th, 2023, 7:26AM EST: ALPHV domain seized

December 19th, 2023, 7:42AM EST: ALPHV states this is the old domain and it doesn't matter

December 19th, 2023, 9:56AM EST, United States Department of Justice releases official statement on the seizure of ALPHV as well as compromising of their servers

December 19th, 2023: 12:34PM EST, ALPHV unseizes domain and threatens retaliation against United States (and associated entities) by allowing attacks against critical infrastructure
😎123🤣26👏12🔥10😁9🤯7👍6😱53🤔1
🤣149😁3211🔥6👍3🤓2😎2🤯1
Updated United States government vs ALPHV ransomware group

The FBI has re-seized ALPHV's old website, ALPHV would then take it back. It has been seized and then 'unseized' roughly 4 times today.

Lockbit ransomware group is now trying to poach ALPHV developers and affiliates
🤣148🔥7😎65👍1