vx-underground
46.1K subscribers
3.96K photos
420 videos
83 files
1.45K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
We found NATO's Jira access portal online. It said you can request access via the form URL. We have requested access to NATO.
😁175🀣94🫑26πŸ‘7πŸ”₯7πŸ’―6πŸ€“4❀3❀‍πŸ”₯1
News outlets are now describing ransomware attacks by mattress size
🀣108😁10🫑6πŸ’―5❀2πŸ”₯2
This media is not supported in your browser
VIEW IN TELEGRAM
NATO has shutdown access requests forms for their Jira board.
😒159😁35🀣30❀8πŸ’―5πŸ‘2πŸ₯°2πŸ”₯1😱1
ALPHV has lost their god damn mind
🀣75🀯22πŸ”₯9😎7😱5πŸ‘3πŸ’―2
NATO Jira creds stolen from an Infostealer 😭😭
🀣126😱8🫑7πŸ‘3πŸ‘2πŸŽ‰2🀩2
We've updated the Windows malware paper collection

- 2023-12-24 - Arbitrary Command Execution Via Windows Kit's StandaloneRunner
- 2024-02-12 - Hypervisor enforced security policies for NTOS secure kernel and a child partition
- 2024-02-12 - Why Windows cant follow WSL symlinks
❀29πŸ‘7
We are going to create a new section of vx-underground specifically for archiving criminal activity documentation (rather than technical details).

This portion will archive legal proceedings, court rulings, Threat Intel write ups, etc.
πŸ”₯106πŸ‘21❀12πŸŽ‰5🫑5❀‍πŸ”₯3
Lockbit ransomware group terms-of-service states "no healthcare". Then they proceed to allow their affiliates to target healthcare... repeatedly.

Today they decided to ransom a cancer treatment center with locations in Florida and Puerto Rico
😒129πŸ‘10🀣7🀩5🀯4πŸ’―2πŸ€“2😁1
"Did you guys see my message?"

Want to know how good we are at seeing messages? It took us almost 2 years to reply to someone.

Also, thank you for the sample, RussianPanda. Apologies it only took us 2 years.
🀣110❀7😒3πŸ‘2
tl;dr if we don't reply in like, 3 or 4 days, don't be afraid to try messaging us again. We get a ton of e-mails, DMs, and messages every single day about all sorts of stuff (including people asking for the password, still)
🀣86πŸ€“17πŸ‘6🫑3πŸ‘2
The first VXUG APT exclusive! πŸ₯°

2024-02-09, the Kazakhstan government reported state-sponsored Threat Actors targeting government officials with sugargh0st malware

Thanks to our friends in Kazakhstan we are the first to share them:)

Check it out here: https://vx-underground.org/APTs/2024/2024.02.09%20-%20SugarGh0st%20RAT%20attacks%20Kazakhstan%20%E2%80%93%20State%20Technical%20Service
❀‍πŸ”₯88😎10πŸ”₯8πŸ‘6
vx-underground
The first VXUG APT exclusive! πŸ₯° 2024-02-09, the Kazakhstan government reported state-sponsored Threat Actors targeting government officials with sugargh0st malware Thanks to our friends in Kazakhstan we are the first to share them:) Check it out here: https://vx…
No but seriously, this is the first time we've beaten VirusTotal and other AV vendors to a malware sample.

feels_good_man.exe
πŸŽ‰150πŸ‘15πŸ”₯10❀7🫑4😁3πŸ’―3🀝2πŸ‘1
will you be our valentine?
❀307πŸ₯°41❀‍πŸ”₯18πŸ‘17πŸ€“14😒12😘8😱6πŸ”₯5πŸ€”5🀝5
The crime section is now public. It's pretty empty, but it's a work in progress.

Have a nice day

https://vx-underground.org/Crime
πŸ‘47❀17πŸ”₯10😎10πŸ‘3🀝1
Mozilla has laid off 60 people and announces they want to incorporate AI into Firefox

It's over

https://arstechnica.com/gadgets/2024/02/mozilla-lays-off-60-people-wants-to-build-ai-into-firefox/
😒188🫑66🀣34πŸ€”13πŸ‘6🀯5πŸ’―2πŸ‘1
This media is not supported in your browser
VIEW IN TELEGRAM
Today the United Kingdom's National Crime Agency released an advert reminding YOU about the Computer Misuse Act

Ditch the script, it's a crime.
πŸ€“106🀣64😱8πŸ˜‡7πŸ’―6🀯3❀2😁2😒1
vx-underground
Today the United Kingdom's National Crime Agency released an advert reminding YOU about the Computer Misuse Act Ditch the script, it's a crime.
you're all a bunch of god damn criminals and you're going to jail forever and ever and ever
😱98😁32πŸ€“14🫑10😒7πŸ‘5πŸ’―5❀‍πŸ”₯4🀯4πŸ€”3πŸ™3
Hello, how are you?

Selling merchandise has been an extremely painful task. We profit almost nothing from merchandise, roughly $5 per item sold, because it is all handled by an external manufacturer

When individuals are upset over merchandise, and request a refund, we lose A LOT of money which we already do not have.

We will be closing the merch store soon due to frequent refunds. We are losing money right now.
😒183🀣10❀9🫑9😁5πŸ‘3
vx-underground
Hello, how are you? Selling merchandise has been an extremely painful task. We profit almost nothing from merchandise, roughly $5 per item sold, because it is all handled by an external manufacturer When individuals are upset over merchandise, and request…
A few notes:

1. The store will come back at a later time. We need to assess our ability to sell merchandise, at a reasonable price, and doesn't financially hurt us.

2. We will still be selling harddrives on the store (when they're back in stock)

tl;dr customer support is dumb
❀75🫑17❀‍πŸ”₯4
The United States government has placed a $10,000,000 bounty on the leaders of ALPHV.

Additionally, any individual conspiring to participate in or attempting to participate with ALPHV has a bounty of $5,000,000.

https://www.state.gov/reward-for-information-alphv-blackcat-ransomware-as-a-service/
🀯74🀣20😱18πŸ‘9πŸ₯°7πŸ”₯6❀4😒3πŸŽ‰2
Today the United States Department of Justice was busy.

1. Vyacheslav Igorevich Penchukov a/k/a Tank was arrested. He was allegedly involved in the Zeus botnet and IcedId banking trojan

2. Mark Sokolovsky, developer of Raccoon Stealer, is scheduled to be extradited to the United States from the Netherlands

3. The Department of Justice announces the disruption of a botnet operated by the Russian GRU a/k/a APT28
🫑83🀣28😒17😱14❀3πŸ‘2πŸ‘1πŸ€“1