vx-underground
49.4K subscribers
4.33K photos
469 videos
84 files
1.53K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
vx-underground
GIF
After nearly two weeks of radio silence from Lockbit ransomware group they've returned with a Telegram account, a Briar account, a Signal account, and an XMPP account

They also immediately threw shade at RansomHub by accusing them of being a rebrand of ALPHV.
❤‍🔥32🔥8😎8😁2😢1
The real Lockbit ransomware group Telegram channel and their first fancy little message. Interesting times we live in, seeing them pivot to Telegram.
👍6😁1
We see some nerds getting super hostile to women in tech — especially if they're conventionally attractive and/or have a high number of followers on social media

If you're feeling upset: scream at your Mom, heat up some pizza rolls, and put on some anime

It's going to be okay.
🤓133💯60🤣5117😁13🤯8🤔6🥰5😢5👏4😎1
This post is going to be controversial. But we believe it is necessary. Threat Intelligence nerds, Blue Team nerds, and Law Enforcement nerds following us on sock accounts – don't have a conniption.

Dear Threat Actor(s) who contact us,

We advise you do NOT use the leaked Babuk builder and source code. Babuk is notorious for failing to decrypt files (especially large files), and corrupting data. If you (or your group) decide to do ransomware ... for the sake of literally everybody involved (you and/or your group, the victim, Threat Intelligence, Digital Forensic & Incident Response firms, Law Enforcement, etc) DO NOT USE BABUK. Don't go anywhere near Babuk. If someone recommends Babuk, slap them around with a large trout.

Thanks,
🤣10427👍11🤓4🤝2🔥1🤔1😢1
This media is not supported in your browser
VIEW IN TELEGRAM
wHy dOnT u uSe Ur larGe sOcIAl mEdIa pResCencE 2 dIsCUss pOliTicS

1. Everyone discusses politics. This is a shitpost, malware, and chill zone.

2. We are (mostly) United States based and the current political landscape closely resembles a SouthPark skit

Example:
💯129🤣62🫡13😁8🤓6😎64🤯3👍2😢2🥰1
Today CrowdStrike pushed out a botched update.

It has resulted in outages in Banks, Airlines, Emergency hotlines, ???

It's 6am on a Friday and CrowdStrike cooked the internet
🔥155🤣29😁23🫡115😱4👏2😢1🤓1🤝1
As we continue to do our daily news check up, we can confirm that CrowdStrike has performed a colossal oopsie and has done catastrophic damage.

We have never witnessed an oopsie of this magnitude
😁129💯19🔥147🫡6😱5👍3👏2😢2🤓2😇2
CrowdStrike has performed the largest ransomware attack in history.

Accidentally.
🤣319😁20🔥19🫡147😢6👏4😇3🤝3👍2💯2
Threat Actors today wondering where the hell all their compromised hosts went
😁146🤣11312🤔4😇4🔥2😢1🤓1
How to fix the Crowdstrike thing:

1. Boot Windows into safe mode
2. Go to C:\Windows\System32\drivers\CrowdStrike
3. Delete C-00000291*.sys
4. Repeat for every host in your enterprise network including remote workers
5. If you're using BitLocker jump off a bridge
🤣231😁35🔥20👍9🤔5💯4❤‍🔥2😢1🤓1
This media is not supported in your browser
VIEW IN TELEGRAM
CrowdStrike cooked the Los Angeles International Airport

Even non-nerds freaking out – they think it's some massive 1337 hack (it's just bad coding).
🤣137😁13❤‍🔥11🙏7🔥6👏2👍1😢1🤓1
This media is not supported in your browser
VIEW IN TELEGRAM
CrowdStrike cooked SkyNews. They're trying to do the news with no computers.
🤣126🫡7🔥4😇2😁1😢1🤓1
CrowdStrike cooked airports in India. They're issuing handwritten boarding passes
🔥101🤣58😁7😢5🤓21
We apologize to the many people who follow us online.

Instead of doing our regular malware sample family updates and pushing new papers, we're going to meme this CrowdStrike thing until we develop arthritis.
139🤣63😁18👍6❤‍🔥4👏4🥰3😢1🎉1💯1🤓1
🤣113😁31🤔8😢3🙏2🤓21
Stock exchange opened. It appears CrowdStrike share holders are relatively concerned.
🔥91🤣50😱9🤩7🤓3👍21