vx-underground
51.1K subscribers
4.48K photos
484 videos
84 files
1.56K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Over the past couple of days we have become aware of malware targeting gamers! More specifically, a currently unidentified Threat Actor is utilizing an infostealer to target individuals who cheat (Pay-to-Cheat) in video games.

A Call of Duty cheat provider (PhantomOverlay) was alerted of fraudulent activity when user accounts began making unauthorized purchases. The cheat provider was the first to notice the fraudulent activity and reached out to the suspected victim. Since the initial victim was identified, more and more victims have been identified.

The scope of the impact is so large, and in a bizarre twist of fate, Activision Blizzard is coordinating with cheat providers to aid users impacted by the massive infostealer campaign.

Currently there is a presumed impact of:
- 3,662,627 Battlenet accounts compromised
- 561,183 Activision accounts compromised
- 117,366 Elite PVPers accounts compromised
- 572,831 UnknownCheats accounts compromised
- 1,365 PhantomOverlay accounts compromised

When Elite PVPers was approached by PhantomOverlay administrative staff about the compromised accounts, Elite PVPers confirmed they have identified 40,000+ valid user accounts compromised. These are seemingly freshly stolen credentials and are not present from previous publicly available credential dumps. However, due to the size of the data we have not been able to thoroughly review the data for duplicates.

Additionally, impacted users have begun reporting being victims of crypto-draining – their Electrum BTC wallets have been drained. We do not have any information on the amount of money stolen.
πŸ”₯48🀣46πŸ‘10❀3😁3😱3❀‍πŸ”₯1
vx-underground
Over the past couple of days we have become aware of malware targeting gamers! More specifically, a currently unidentified Threat Actor is utilizing an infostealer to target individuals who cheat (Pay-to-Cheat) in video games. A Call of Duty cheat provider…
It should be noted that some of these accounts are also not cheaters. Some users impacted utilized gaming software for latency improvement (?), VPNs, and Controller Boosting software

(we don't know what this means)
πŸ‘42😁12🀯7❀6πŸ₯°2
DarkGate loader has the most sophisticated loader we've ever seen. It's over for the anti-virus industry. How would anyone defeat or detect this?!
🀣106🀯12😎7πŸ€“3❀2😱2πŸŽ‰2πŸ‘1πŸ”₯1
Unpopular opinion: cheating in video games is cool and badass

You should have nothing but the utmost respect for nerds who spent their time reverse engineering a game and developing ways to cheat. It isn't easy work especially with the advancement of anti-cheats.
❀214πŸ€“84🫑32πŸ€”16πŸ‘13🀣7πŸ”₯6😒3🀝2😎2🀯1
FTX founder Sam Bankman-Fried has been sentenced to 25 years in prison.
πŸ₯°97πŸŽ‰67🀣46😒15πŸ‘10πŸ”₯8πŸ™5❀4πŸ€“3❀‍πŸ”₯1
In case you missed our first ever VXUG trivia night, first place won $500 & last place won custom made hoodies (sponsored by Malcoreio)

The hoodies include their team name and a silly quote from them.

Congratulations to Bandrel's team for the swag.
❀71πŸ‘17❀‍πŸ”₯6🫑2
🀣105πŸ’―13🀯8πŸ˜‡6❀4πŸ”₯4❀‍πŸ”₯2πŸ€“2πŸ‘1😁1
Telegram is a wild place
🀣197❀17πŸ”₯11πŸ€”7πŸ₯°5πŸ’―4πŸ‘1
Checked in with Lockbit ransomware group administrative staff yesterday. We haven't spoken with them in a few weeks. They're now looking to expand operations into Violence-as-a-Service.

Very cool – malware, extortion, money laundering, and now violence πŸ‘
🀣172πŸ‘30😱12❀11πŸ”₯11🫑10😎3😒2πŸŽ‰2πŸ₯°1πŸ’―1
The more we read about the xz supply chain attack the more we realize that everyone needs to move to Windows XP.

This wouldn't have happened on Windows XP
🀣141πŸ’―20❀11πŸ‘4πŸ‘2🀝2❀‍πŸ”₯1πŸ€”1🀯1
women are scary
πŸ”₯135🀣48😱12😁9πŸ€“8🫑6πŸ’―5πŸ₯°4❀3πŸŽ‰3πŸ‘2
vx-underground
Checked in with Lockbit ransomware group administrative staff yesterday. We haven't spoken with them in a few weeks. They're now looking to expand operations into Violence-as-a-Service. Very cool – malware, extortion, money laundering, and now violence πŸ‘
Lockbit has clarified this is not to intimidate potential victims of ransomware. Lockbit administrative staff claim they were recently robbed and need to get their money back.
🀣114πŸ€”14❀5πŸ‘1😱1πŸ’―1
meemaw shows nerds how to use ffmpeg, uses a 2 character password, uses neofetch, and complains about bloat on her 4gb linux box

based and linux pilled

https://www.youtube.com/watch?v=YVI6SCtVu4c
❀183πŸ‘11πŸ‘7🀯6πŸ’―4πŸ”₯3πŸ€”3😁1
The xz situation is absolutely insane and almost certainly state sponsored.

This is an excellent example of a widely used software being maintained by basically one person.

Read this web article and then frown and become sad.

https://boehs.org/node/everything-i-know-about-the-xz-backdoor
😱82πŸ€“15πŸ”₯8🫑7πŸ‘4🀯4❀3🀣2❀‍πŸ”₯1😒1
😭😭😭 which one of you nerds did this
🀣196😁19❀11πŸ’―6😎6😒5πŸ€“3πŸ”₯2πŸ˜‡2🫑1
Times like this we need a reminder that only one person can protect us from OSS supply chain attacks

meemaw. She would know immediately
❀171πŸ’―26🀣11πŸ”₯5πŸ₯°4😒2
The xz backdoor was initially caught by a software engineer at Microsoft. He noticed 500ms lag and thought something was suspicious.

This is the Silver Back Gorilla of nerds. The internet final boss.
πŸ”₯187🫑84πŸ€“25😁12🀣11❀8πŸ’―7πŸ‘5πŸ‘1πŸ˜‡1
Microsoft engineer: 500ms lag in liblzma? Something's up.

Also Microsoft engineer: 45 minute lag in Microsoft Teams? Perfect.
🀣374πŸ”₯42😁29❀14πŸ‘12πŸ’―5πŸ₯°3πŸ€“3
JiaT75 on GitHub pretending to be an OSS enthusiast and 100% NOT a state-sponsored Threat Actor
🀣250❀10πŸ˜‡7πŸ‘6😎3🀯2❀‍πŸ”₯1πŸ’―1πŸ€“1