Updates to vx-underground:
- 2024-07-02 - Exposing FakeBat loader: Distribution methods and adversary infrastructure
- 2024-06-30 - Deep Analysis of Snake (404 keylogger)
- 2024-06-27 - Poseidon Stealer malspam campaign targeting Swiss macOS users
- 2024-07-02 - The LandUpdate808 Fake Update Variant
- 2024-06-24 - βPoseidonβ Mac stealer distributed via Google ads
- 2024-07-02 - Kematian Stealer forked from PowerShell Token Grabber
- 2024-07-02 - Exposing FakeBat loader: Distribution methods and adversary infrastructure
- 2024-06-30 - Deep Analysis of Snake (404 keylogger)
- 2024-06-27 - Poseidon Stealer malspam campaign targeting Swiss macOS users
- 2024-07-02 - The LandUpdate808 Fake Update Variant
- 2024-06-24 - βPoseidonβ Mac stealer distributed via Google ads
- 2024-07-02 - Kematian Stealer forked from PowerShell Token Grabber
β€27π7π5π3π₯2π2π€1
vx-underground
GIF
After nearly two weeks of radio silence from Lockbit ransomware group they've returned with a Telegram account, a Briar account, a Signal account, and an XMPP account
They also immediately threw shade at RansomHub by accusing them of being a rebrand of ALPHV.
They also immediately threw shade at RansomHub by accusing them of being a rebrand of ALPHV.
β€βπ₯32π₯8π8π2π’1
The real Lockbit ransomware group Telegram channel and their first fancy little message. Interesting times we live in, seeing them pivot to Telegram.
π6π1
We see some nerds getting super hostile to women in tech β especially if they're conventionally attractive and/or have a high number of followers on social media
If you're feeling upset: scream at your Mom, heat up some pizza rolls, and put on some anime
It's going to be okay.
If you're feeling upset: scream at your Mom, heat up some pizza rolls, and put on some anime
It's going to be okay.
π€133π―60π€£51β€17π13π€―8π€6π₯°5π’5π4π1
This post is going to be controversial. But we believe it is necessary. Threat Intelligence nerds, Blue Team nerds, and Law Enforcement nerds following us on sock accounts β don't have a conniption.
Dear Threat Actor(s) who contact us,
We advise you do NOT use the leaked Babuk builder and source code. Babuk is notorious for failing to decrypt files (especially large files), and corrupting data. If you (or your group) decide to do ransomware ... for the sake of literally everybody involved (you and/or your group, the victim, Threat Intelligence, Digital Forensic & Incident Response firms, Law Enforcement, etc) DO NOT USE BABUK. Don't go anywhere near Babuk. If someone recommends Babuk, slap them around with a large trout.
Thanks,
Dear Threat Actor(s) who contact us,
We advise you do NOT use the leaked Babuk builder and source code. Babuk is notorious for failing to decrypt files (especially large files), and corrupting data. If you (or your group) decide to do ransomware ... for the sake of literally everybody involved (you and/or your group, the victim, Threat Intelligence, Digital Forensic & Incident Response firms, Law Enforcement, etc) DO NOT USE BABUK. Don't go anywhere near Babuk. If someone recommends Babuk, slap them around with a large trout.
Thanks,
π€£104β€27π11π€4π€2π₯1π€1π’1
vx-underground
This post is going to be controversial. But we believe it is necessary. Threat Intelligence nerds, Blue Team nerds, and Law Enforcement nerds following us on sock accounts β don't have a conniption. Dear Threat Actor(s) who contact us, We advise you do NOTβ¦
Blah blah blah, helping criminals, blah blah blah. But seriously, Babuk causes EVERYONE problems. It is a colossal piece of shit.
π€£65π9π€8β€5π3π±2π€2π’1π―1
This media is not supported in your browser
VIEW IN TELEGRAM
wHy dOnT u uSe Ur larGe sOcIAl mEdIa pResCencE 2 dIsCUss pOliTicS
1. Everyone discusses politics. This is a shitpost, malware, and chill zone.
2. We are (mostly) United States based and the current political landscape closely resembles a SouthPark skit
Example:
1. Everyone discusses politics. This is a shitpost, malware, and chill zone.
2. We are (mostly) United States based and the current political landscape closely resembles a SouthPark skit
Example:
π―129π€£62π«‘13π8π€6π6β€4π€―3π2π’2π₯°1
Today CrowdStrike pushed out a botched update.
It has resulted in outages in Banks, Airlines, Emergency hotlines, ???
It's 6am on a Friday and CrowdStrike cooked the internet
It has resulted in outages in Banks, Airlines, Emergency hotlines, ???
It's 6am on a Friday and CrowdStrike cooked the internet
π₯155π€£29π23π«‘11β€5π±4π2π’1π€1π€1
As we continue to do our daily news check up, we can confirm that CrowdStrike has performed a colossal oopsie and has done catastrophic damage.
We have never witnessed an oopsie of this magnitude
We have never witnessed an oopsie of this magnitude
π129π―19π₯14β€7π«‘6π±5π3π2π’2π€2π2
CrowdStrike has performed the largest ransomware attack in history.
Accidentally.
Accidentally.
π€£319π20π₯19π«‘14β€7π’6π4π3π€3π2π―2
Threat Actors today wondering where the hell all their compromised hosts went
π146π€£113β€12π€4π4π₯2π’1π€1
How to fix the Crowdstrike thing:
1. Boot Windows into safe mode
2. Go to C:\Windows\System32\drivers\CrowdStrike
3. Delete C-00000291*.sys
4. Repeat for every host in your enterprise network including remote workers
5. If you're using BitLocker jump off a bridge
1. Boot Windows into safe mode
2. Go to C:\Windows\System32\drivers\CrowdStrike
3. Delete C-00000291*.sys
4. Repeat for every host in your enterprise network including remote workers
5. If you're using BitLocker jump off a bridge
π€£231π35π₯20π9π€5π―4β€βπ₯2π’1π€1
This media is not supported in your browser
VIEW IN TELEGRAM
CrowdStrike cooked the Los Angeles International Airport
Even non-nerds freaking out β they think it's some massive 1337 hack (it's just bad coding).
Even non-nerds freaking out β they think it's some massive 1337 hack (it's just bad coding).
π€£137π13β€βπ₯11π7π₯6π2π1π’1π€1
This media is not supported in your browser
VIEW IN TELEGRAM
CrowdStrike cooked SkyNews. They're trying to do the news with no computers.
π€£126π«‘7π₯4π2π1π’1π€1
We apologize to the many people who follow us online.
Instead of doing our regular malware sample family updates and pushing new papers, we're going to meme this CrowdStrike thing until we develop arthritis.
Instead of doing our regular malware sample family updates and pushing new papers, we're going to meme this CrowdStrike thing until we develop arthritis.
β€139π€£63π18π6β€βπ₯4π4π₯°3π’1π1π―1π€1