vx-underground
46.1K subscribers
3.96K photos
420 videos
83 files
1.45K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
vx-underground
Breached, the infamous forum where individuals buy, sell, leak, and trade data, recently made some modifications to their rules. Breached now forbids ransomware sales, recruitment, development, and ransomware-adjacent extortion. See attached image for more…
It should be noted that modification of the rules was not exclusive to ransomware. Breached also forbids:

- Drug sales
- Weapon sales
- Violence-as-a-Service (VaaS)
- Selling credit card or debit cards
- Selling Real IDs or documentation
- Drainers or recruitment of drainers
🀯52😒17πŸ‘16❀1
Hello harddrive purchasers,

All remaining international harddrives have been mailed, except 2 in Germany because the "ß" letter angered the post office and we have to redo the label. Oopsies. We learned the "ß" has to be written as "ss". 😑

North American harddrives will be shipped the coming week.

We've also dramatically improved our process for cloning, packaging, and shipping. In the future delivery will be much faster. We bought a bunch of stuff to make labels, package stuff, etc =D
❀52🀣31😁14πŸ”₯5πŸŽ‰3πŸ‘2😱1😒1
We've updated the vx-underground Crime/Legal Ruling section. We've archived Department of Justice indictments for 2024 (so far), 2023, 2022, and 2021.

Cases are formatted as follows:

[date] - United States v [Person(s)] ( [Reason] )
❀32πŸ‘7πŸ‘4
Season 2 of FBI vs Lockbit ransomware group is scheduled to premier in roughly 1 hour.

Lockbit has restored their servers (new Tor domains) and is planning on making a statement to the FBI regarding last weeks takedown.

Stay tuned for the next episode of Dragon Ball Z
🀣139πŸ”₯22😁10❀8❀‍πŸ”₯3πŸ‘3😱3πŸ₯°1πŸ€”1
vx-underground
Season 2 of FBI vs Lockbit ransomware group is scheduled to premier in roughly 1 hour. Lockbit has restored their servers (new Tor domains) and is planning on making a statement to the FBI regarding last weeks takedown. Stay tuned for the next episode of…
Will Lockbit admit defeat? Will the FBI summon the energy to complete the spirit bomb? Will Lockbit call in for back up? and who is this rumored legendary Super Saiyan?!
πŸ”₯94🀣50πŸ€”4πŸ€“4❀‍πŸ”₯2πŸ‘1
Lockbit ransomware group administrative staff have released a lengthy response to the FBI and bystanders.

In summary: they claim they failed to keep their systems up-to-date because they had become 'lazy', and they had become complacent. They believe they were compromised by CVE-2023-3824, but are not totally sure. They also speculate it could have been a 0day exploit. They also speculate other RaaS groups (their competitors) may have been compromised.

They also speculate the reason why the FBI took such aggressive action was because a recent ransomware attack performed by one of their affiliates had sensitive information on former President Donald J. Trump. They state they believe their affiliates should target government entities more often to illustrate government vulnerabilities and flaws.

It is an incredibly long read with lots of speculation and attempts to discredit law enforcement agencies.

You can read the full post here: https://samples.vx-underground.org/tmp/Lockbit_Statement_2024-02-24.txt
❀103🀣55πŸ€“13πŸ‘10❀‍πŸ”₯6πŸ”₯6😎5πŸ€”1😱1
The malware samples we archive are not toolkits. Please do not execute them on your machine.

Thanks,
🀣181😁19❀11🀯5🀝4πŸ€“3πŸ”₯1
We recently had a few people ask us if we dislike CTI (Cyber Threat Intelligence) because we occasionally meme them online.

No, in fact we very much like them. We enjoy reading the DFIR reports, notes and theories on how financially motived and/or state-sponsored groups operate, and we enjoy reading the geopolitical backgrounds and/or influences on groups. This field of research is profoundly valuable to our line of work because these factors influence malware development in more ways than one. We are big fans of research performed by groups such as Mandiant, Cisco Talos, Recorded Future (and/or Insikt Group), Intel471, CrowdStrike, and Threat Intel adjacent groups like TheDFIRReport.

Our primarily criticism of Threat Intel is not the large vendors, it is the trickle down effect from Threat Intel. For example: Mandiant may publish a paper on APT28. Following the release of their research it is inevitable that a smaller or lesser known Threat Intelligence company(ies) will regurgitate Mandiant's findings, only to slightly distort it, thus making it inaccurate or altered in some form from the initial source. As this trickle down effect continues the information becomes more and more distorted and inaccurate leading to misinformation.

We also just meme and shit post because our online account is ran by 3 people with a combined IQ of spaghetti. Sometimes we put little-to-no thought into how people will respond to memes.
❀141🀣36πŸ‘17πŸ₯°7πŸ€“5😱1
We've updated the vx-underground Crime/Legal rulings collection. We've completed years 2020 - 2024. Documented cases cover:

- Dark Overlord Group
- CardPlanet
- Equifax Hack
- Helix Mixer
- The Twitter Hack
- FastPOS
- Team Xecuter
- QQAAZZ Group
- FIN7
- Bitcoin Fog
- Trickbot
- Kelihos Botnet
- REvil ransomware
- Hydra Market
- Sandworm a/k/a Cyclops Blink
- Ryuk ransomware
- Netstalker ransomware
- Lockbit ransomware
- BreachedForums
- RaidForums
- Mt. Gox Hack
- Conti ransomware
- Callisto Group
- WarzoneRAT
- RaccoonStealer
- Lazarus Group
- APT41

... and a lot more

Check it out here: https://vx-underground.org/Crime/Legal%20Rulings
❀41πŸ‘19πŸ”₯8❀‍πŸ”₯6
exciting news coming

(if you have friends and like cash prizes)

cya soon
❀70πŸ€”28πŸ‘5😁5😒4πŸŽ‰3
We've updated the vx-underground malware sample collection.

- Virusshare.00485
- Virusshare.00486
- 92,000+ new samples

All samples have been synced the VXDB 🫑
❀‍πŸ”₯22🫑11🀣7❀5🀯2
We will be hosting our first ever VXUG trivia night. On March 8th teams of friends (or cats?) will answer malware and/or Threat Intel related questions for a chance to win money.

1st place: $500
2nd place: $250
3rd place: $100

Sponsored by Malcore πŸ™

(More info soon)
πŸ‘52❀28πŸŽ‰16πŸ₯°1
It is honestly insulting someone would use our name and deface it with shitty AI art and ... Netflix fraud? Really?
🀣270🀯15πŸ”₯13😒8πŸ‘3😁3πŸ€”3😱3❀2❀‍πŸ”₯2🫑1
This isn't real but it is insanely funny

"When we catch you, me and NCA are going to take turns running you over with your own Mercedes."

πŸ˜‚πŸ˜‚πŸ˜‚πŸ˜‚πŸ˜‚πŸ˜‚
🀣283❀26😁13πŸ”₯8πŸ‘4πŸ₯°2πŸ™1πŸ’―1πŸ€“1
Hello,

We are trying to get enough followers on Twitch to unlock some Twitch features. If you're a person who uses Twitch and would like to support us please follow vx-underground here:

https://www.twitch.tv/vxunderground_live/
❀53🀣24🫑12πŸ‘8🀝7πŸ”₯3😁2🀩2πŸ€“2😘2😒1
This is fucked up
😒203🀣29πŸ‘6😎5❀3😁3πŸ€”3🀯3πŸŽ‰3πŸ”₯2
American Fast Food restaurant Wendy's CEO announced they're considering introducing 'price surging', where food prices fluctuate based on demand

pov: in line watching baconator cheeseburger go from $5 to $20 in-real-time
🀣169😁12❀7🀯6😱6πŸ”₯4😒4πŸ‘3πŸ€”1🀩1
> Get United States court system RSS feed
> Monitor each District Court (updates every 24hrs)
> Find non-DOJ announcements on cyber criminals
πŸ€”107πŸ‘16πŸ€“7❀4
March 1st, 2024 Yaroslav Vasinskyi, the individual responsible for the REvil Kaseya supply chain attack will be sentenced.

His sentencing has been continuously been post-poned and rescheduled since 2022. He has been sitting in a county jail waiting for almost 2 years.
πŸ€”42😒18πŸ‘7🀣7πŸ€“7❀1
Conor Fitzpatrick, the previous administrator of BreachedForum, is being pulled back into court.

Upon pleading guilty, he was sentenced to 20 years supervised release. The United States government is not happy with this sentencing and is making an appeal to the higher courts.
🀣119🫑15🀯10πŸ‘7😒7πŸ”₯6πŸ₯°1🀝1