vx-underground
47.7K subscribers
4.13K photos
441 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Telegram is cool and badass
😁116🤣57❤‍🔥8💯8🥰64🔥3🤓2🤔1🤯1🤩1
vx-underground
Telegram is cool and badass
It's recursive (Telegram is cool and badass)
🤣150😁147🔥4🤩4😢2🤓2❤‍🔥1🤔1🎉1😇1
Thank you to our friend ddd1ms for the NAS hardware donation.

We are no longer storing the vx-underground archives on an old creeky external harddrive.

We now have 48TB of RAID storage, or something, something fancy. It's really cool. Thank you so much.
🎉14323❤‍🔥9😎8👍4😢2🤝2🥰1
vx-underground
Thank you to our friend ddd1ms for the NAS hardware donation. We are no longer storing the vx-underground archives on an old creeky external harddrive. We now have 48TB of RAID storage, or something, something fancy. It's really cool. Thank you so much.
The potatoes are there because the NAS heats them up, then the mini-fan on the floor distributes a nice potato smell throughout the office.
🤣16929🤓8😍3🥰2😢2❤‍🔥1👍1
Hello,

Please do not lie on your resume and claim to be 'employed' at vx-underground. It is very awkward when we have to inform your potential employer that you're lying.

Also, it's weird, don't be a booger.

Thanks,
🤣236👍1715🤓11🫡10🤯9😢4❤‍🔥3🤔2👏1💯1
We've updated the vx-underground Malware Ingestion feed. All ingested malware samples from May, June, and July are now present and available for bulk download.

*All samples named appropriately via VirusTotal API.

May, 2024:
- 90.3GB (compressed)
- 358,067 malware samples

June, 2024:
- 118.3GB (compressed)
- 354,248 malware samples

July, 2024:
- 103.4GB (compressed)
- 379,219 malware samples

August, 2024 (1st - 16th)
- 416GB (uncompressed)
- 668,422 malware samples

You nerds better be pullin' this stuff >:(

Check it out here: https://vx-underground.org/Samples/MalwareIngestion
35🫡16👍2😁2😢1
🤓74🤣39😢8🥰4🔥31
Dear large enterprise companies using our website,

Contact your boss, or your bosses boss, and tell them to give us some of their large enterprise company money. We offer everything for free, if you're going to profit off our work, at least throw us a few bucks

Thanks,
142👍27💯20🤣11😘9👏7🤓2❤‍🔥1😢1
$2,266 for the official vx-underground channel?

You might as well spit in our face and shit in our shoes. We've worked tirelessly for 5 years and you think we'd sell our souls for $2,266?

The disrespect is crazy 😭😭😭
💯247🤣145👍14🤯12😢75🤓5😁4🔥3🥰2🤔1
Most prolific serial killers in American history:

10. David Berkowitz
9. Samuel Little
8. Aileen Wuornos
7. Gary Ridgway
6. Jeffrey Dahmer
5. Richard Ramirez
4. Dennis Rader
3. John Wayne Gacy
2. Ted Bundy
1. Boeing
🤣193💯27🫡155😢5👍4🔥2😁2😱2😍2🥰1
Updates:

Families:
- AgentTesla
- AsyncRAT
- CryptBot
- DarkComet
- DCRat
- FormBook
- GuLoader
- Latrodectus
- LummaStealer
- Mirai
- OxyPumper
- RedLine
- Remcos
- RevengeRAT
- SnakeKeylogger
- STRRAT
- TrickBot
- XMRig
- XWorm
- ZharkRAT

Papers:
- 2012-10-02 - Blackhole Exploit Kit: Rise and Evolution.pdf
- 2015-09-15 - In Pursuit of Optical Fibers and Troop Intel: Targeted Attack Distributes PlugX in Russia.pdf
- 2015-09-24 - Meet GreenDispenser: A New Breed of ATM Malware.pdf
- 2021-12-22 - Establishing the TigerRAT and TigerDownloader Malware Families.pdf
- 2022-04-27 - BRONZE PRESIDENT Targets Russian Speakers with Updated PlugX.pdf
- 2022-08-22 - Ocean Lotus APT Group.pdf
- 2022-10-12 - TOAD attacks: Vishing combined with Android banking malware now targeting Italian banks.pdf
- 2023-04-14 - SHATTEREDGLASS Server Emulator.pdf
- 2023-07-03 - Chinese Threat Actors Targeting Europe in SmugX Campaign.pdf
- 2023-07-29 - Unknown powershell backdoor with ties to new Zloader.pdf
- 2023-09-14 - Peach Sandstorm password spray campaigns enable intelligence collection at high-value targets.pdf
- 2023-12-11 - Mustang Panda's PlugX new variant targetting Taiwanese government and diplomats.pdf
- 2024-01-24 - The Endless Struggle Against APT10- Insights from LODEINFO v0.6.6 - v0.7.3 Analysis.pdf
- 2024-03-04 - On-Device Fraud on the rise: exposing a recent Copybara fraud campaign.pdf
- 2024-03-22 - APT29 Uses WINELOADER to Target German Political Parties.pdf
- 2024-03-22 - Large-Scale StrelaStealer Campaign in Early 2024.pdf
- 2024-03-24 - Analysis of DEV#POPPER: New Attack Campaign Targeting Software Developers Likely Associated With North Korean Threat Actors.pdf
- 2024-04-02 - Updated StrelaStealer Targeting European Countries.pdf
- 2024-04-19 - Gold Pickaxe iOS Technical Analysis- IPA Overview and C2 Communication Start up.pdf
- 2024-04-27 - Finding Malware: Detecting SOGU with Google Security Operations.pdf
- 2024-06-09 - New Threat: A Deep Dive Into the Zergeca Botnet.pdf
- 2024-06-24 - StrelaStealer Resurgence: Tracking a JavaScript-Driven Credential Stealer Targeting Europe.pdf
- 2024-07-05 - CLEARFAKE Update Tricks Victim into Executing Malicious PowerShell Code.pdf
- 2024-07-09 - Italian government agencies and companies in the target of a Chinese APT.pdf
- 2024-07-10 - DodgeBox: A deep dive into the updated arsenal of APT41 - Part 1.pdf
- 2024-07-11 - Brief technical analysis of the 'Poseidon Stealer' malware.pdf
- 2024-07-11 - ClickFix Deception: A Social Engineering Tactic to Deploy Malware.pdf
- 2024-07-11 - CRYSTALRAY: Inside the Operations of a Rising Threat Actor Exploiting OSS Tools.pdf
- 2024-07-11 - MoonWalk: A deep dive into the updated arsenal of APT41 - Part 2.pdf
- 2024-07-14 - Fake AWS Packages Ship Command and Control Malware In JPEG Files.pdf
- 2024-07-14 - Malware Analysis: Rhadamanthys.pdf
- 2024-07-15 - CVE-2024-38112: Void Banshee Targets Windows Users Through Zombie Internet Explorer in Zero-Day Attacks.pdf
- 2024-07-16 - MirrorFace Attack against Japanese Organisations.pdf
- 2024-07-16 - NullBulge: Threat Actor Masquerades as Hacktivist Group Rebelling Against AI.pdf
- 2024-07-17 - The Return of Ghost Emperor's Demodex.pdf
- 2024-07-18 - Emerging IoT Wiper Malware: Kaden and New LOLFME Botnet Variants.pdf
- 2024-07-23 - A Simple Approach to Discovering Oyster Backdoor Infrastructure.pdf
- 2024-07-24 - APT45: North Korea's Digital Military Machine.pdf
- 2024-07-24 - Malware Campaign Lures Users With Fake W2 Form.pdf
- 2024-07-24 - Rhysida using Oyster Backdoor to deliver ransomware.pdf
- 2024-07-24 - UAC-0063 Attack Detection: Hackers Target Ukrainian Research Institutions Using HATVIBE, CHERRYSPY, and CVE-2024-23692.pdf
- 2024-07-25 - Growing Number of Threats Leveraging AI.pdf
- 2024-07-28 - CyberGate Technical Analysis.pdf
- 2024-07-30 - Too big to care: Our disappointment with Cloudflare's anti-abuse posture.pdf
- 2024-07-31 - Research Update: Threat Actors Behind the DEV#POPPER Campaign Have Retooled and are Continuing to Target Software Developers via Social Engineering.pdf
- 2024-08-01
🔥43👍105🎉5🤯4🤣3🫡2🤓1
39% of our web visitors are using Tor.
🤣24635🥰29❤‍🔥13🤔10😎8🤓7😘4👏3🤯2😱1
We cookin' now 🙏

(our virus database now implements basic YARA rules and tagging)

(we're bringing in roughly 2 malware samples a second)

(lord help our server bills)
🔥9011🫡11🤣6🥰5❤‍🔥1👍1😢1
TorGuard VPN is running a 60% off deal with promo code VXDADDY.

No, this isn't a joke. This all happened on a whim from a meme.
😎130🤣49🔥14❤‍🔥73😁3🤔3🥰2😢1
"Kros", Jim, and Ron,

Thank you for covering our asses. Please DM us. You all slightly gave us more than the lost $500 so we'll give you free swag, or something, whatever is clever.

Thanks,

P.S. Jim the homie, he doesn't even know what we do and he gave us money 😭😭😭
😁78❤‍🔥31🔥149🥰9🤣4🫡4😢2👍1
🚨BREAKING NEWS 🚨
🤣308😁24🔥18😎11😱9🫡75😘5🙏2👏1😢1
😭😭😭
🤓155🤣35🤯1615💯7😁6👍2😢2🤔1
Today a person operating under the moniker 'Bizarredect' compromised a North Korean ISP and dumped 31GB of North Korean data

https://gofile.io/d/nLSE4n
97🤯37🔥21🤣17👍4😁4😢4👏2🎉2😱1🤓1
Us trying to review the stolen North Korean data
🤣265😁18🤓6😎6💯3👍1😢1