vx-underground
51.6K subscribers
4.53K photos
493 videos
84 files
1.57K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
> search Godot on Twitter
😁87🀣12πŸ’―3😒2❀1
vx-underground
> search Godot on Twitter
Someone told us to check it out and give our input. It's not related to malware, not a compromise or anything.

It's also giant walls of text from all over the place.

tl;dr not reading all that
🀣71πŸ’―16πŸ”₯6🀝4😒2
While we understand what the FBI is trying to convey β€” is owning a camper and a small boat really that luxurious? That seems like, a slightly above average, moderately successful lifestyle. But it isn't flashy or extreme.
πŸ’―156😒53🀣13🀯6❀4😁4πŸ‘1πŸŽ‰1
vx-underground
While we understand what the FBI is trying to convey β€” is owning a camper and a small boat really that luxurious? That seems like, a slightly above average, moderately successful lifestyle. But it isn't flashy or extreme.
SEE THIS? UR FUNDING THIS MANS CAMPING TRIPS WITH HIS FRIENDS AND FAMILY. THEY EVEN GOT A BOAT AND A USED JEEP CHEROKEE
🀣235πŸ’―18🀯7😒6😱4❀2πŸ‘1
It's Monday.

Today the United States Federal Bureau of Investigation and United Kingdom National Crime Agency decided to continue hitting Lockbit ransomware group with sticks.

As the image illustrates: they've arrested more Lockbit affiliates and taken down more infrastructure
πŸ”₯79🀣29πŸ‘10😒8πŸ‘4πŸ€”1
πŸ”₯101🀣38❀8πŸ€”8πŸ€“7πŸ‘2πŸ’―1
More arrests for Lockbit today.

Evidence unveiled shows a relationship between Lockbit and EvilCorp. However, the details remain a little fuzzy.

None of this is surprising, it's part of the cybercrime ecosystem.
πŸ‘46🀣13❀5πŸ”₯5πŸ‘3😒2πŸ€”1
Hello.

It is now Cybersecurity Awareness Month. Some organizations less privy to Cybersecurity often label this month "CSAM" month.

Please do not call it CSAM month. Call it CSA month. CSAM is something entirely different.

Thanks,
πŸŽ‰99😁45🀣27πŸ€“19πŸ’―10πŸ‘6πŸ€”4πŸ”₯3😱3πŸ₯°1😒1
vx-underground
Hello. It is now Cybersecurity Awareness Month. Some organizations less privy to Cybersecurity often label this month "CSAM" month. Please do not call it CSAM month. Call it CSA month. CSAM is something entirely different. Thanks,
TIL: CSA is also a no-no acronym. New solution: dissolve Cybersecurity Awareness Month altogether
🫑83🀣35πŸ‘10😒4πŸ’―3πŸŽ‰2πŸ‘1😁1πŸ€“1🀝1
In honor of Cybersecurity Awareness Month we are issuing a challenge!

All of you (yes, even you) have to get 1 malware.

1 malware = 1 awareness

Good luck!!!!!1
πŸ’―141❀34🫑30😁16🀣14πŸ”₯11😒4😱3πŸ₯°2πŸ‘1πŸ‘1
The cycle of the malware researcher:

> randomly appears on social media
> showcases their research
> publishes a few high quality articles
> gets offered job
> disappears
> no more public research

We've seen this probably 50 times now, no exaggeration.
😁149😒33🫑32🀣12❀4πŸ‘2πŸ‘2πŸ€“2❀‍πŸ”₯1πŸ’―1🀝1
vx-underground
The cycle of the malware researcher: > randomly appears on social media > showcases their research > publishes a few high quality articles > gets offered job > disappears > no more public research We've seen this probably 50 times now, no exaggeration.
God bless them, we're happy you got a job. But don't forget your roots (poor, depressed, addicted to amphetamines and pushing good work).
😁136❀23πŸ’―15πŸ”₯14😒8🫑8πŸ‘7🀣6πŸ€“3πŸ‘2🀝1
it's actually gnu/linux
πŸ”₯116❀32😍13πŸ’―8πŸ€“8πŸ‘7😒4πŸ‘3πŸ₯°2🀩1🀝1
Our engagement numbers have dropped a staggering 27% this month. The primary difference has been a shift away from discussing cybercrime (primarily due to fatigue).

You're all degenerates and thoroughly enjoy internet cybercrime TMZ.
🀣93😒12πŸ₯°8πŸ‘7😎7❀5πŸ’―4❀‍πŸ”₯3πŸ”₯1πŸ€”1πŸ€“1
This media is not supported in your browser
VIEW IN TELEGRAM
Today the Russian Federation's Bureau of State Technical Surveillance in collaboration with the Russian Ministry of Internal Affairs executed 148 search warrants and 96 arrests. All actions are related to the recently sanctioned Cryptex and UAPS

Info & footage via BratvaCorp
πŸ‘57😎28😒20🀣8πŸŽ‰4❀3❀‍πŸ”₯1
For the past week or so an unknown person has been sending us some interesting photos.

This person claims to be frustrated with bulletproof hosting provider 'zservers dot ru'. Their frustration resulted in them doing a 'pentest' and successfully compromising the bulletproof host provider.

It should be noted this is not the first time we've shared information on zserver being compromised. A few months ago we disclosed an unknown person had been claiming to compromise the bulletproof hosting provider. In summary: they STILL have access. It's been months.

Throughout our conversation they have sent us dozens of screenshots from this bulletproof host. They've unveiled the owners real name (with passport information and photographs). They've also shown e-mail correspondence between the owner and customers who have questions about the service and pricing.

They also successfully enumerated every customer of the bulletproof hosting provider β€” the names of the customers (probably fake), the email address used to register with the service, the billing information, and the services they're paying for.

This unknown person(s) managed to pivot further and get access to administrative resources, discovering this bulletproof hosting provider has a directory named 'passwords (all)' which is filled with hundreds, possibly thousands, of credentials to various things.

If it makes you feel any better, they do indeed read abuse complaints they receive. But, they don't take action on it. At least it's read, right?
😱84😁27πŸ‘10πŸŽ‰8🀯7🀣6❀4🫑4πŸ€“3πŸ”₯2😒1
Media is too big
VIEW IN TELEGRAM
Full footage of Cryptex and UAPS raids today from the Russian Federation's Bureau of State Technical Surveillance & Russian Ministry of Internal Affairs.

Footage via BratvaCorp and Irina Volk
🀣28❀20πŸ”₯5πŸ‘4😒4❀‍πŸ”₯1🫑1