vx-underground
46.4K subscribers
3.98K photos
426 videos
84 files
1.45K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
We are close to breaking 100,000 followers on Twitter. When we break 100,000 we will be doing more swag giveaways (on Twitter).

We will be giving away 1 of the each of the following hoodies (4 hoodies). We ship internationally. However, we are currently unable to ship to Ukraine or Russia.
😢15👍14🔥9
Yesterday ESET released a paper on a malware dubbed "WsLink". WsLink utilizes a custom built Virtual Machine. Not a VM for a hosting an OS, a VM for bytecode interpretation (similar to the JVM or PVM).

Paper: https://cutt.ly/2DWfw4P
Ubiquiti is suing Brian Krebs
❤‍🔥1👍1
The internal conflict in LAPSUS$ extortion group continues. They put out this message yesterday on their Telegram, but deleted it approx. 5 minutes later.

- "+44" is the United Kingdom country code
- "kkk" is the Portuguese equivalent of "LOL".
😱7👏2
Despite a series of arrests from UK authorities LAPSUS$ extortion group continues operations.

LAPSUS$ has leaked 70GB of material from Globant, a large software development company based in Luxembourg

Intel and photos courtesy of Dominic Alvieri
❤‍🔥1
LAPSUS$ also threw their System Admins under the bus exposing their passwords to confluence (among other things). We have censored the passwords they displayed. However, it should be noted these passwords are very easily guessable and used multiple times...
🤔3🔥1🤯1
A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.

We have not verified the exploit.

Download the 0day POC here: https://share.vx-underground.org/
👍5😢53👎1
"Now I am become Death, the destroyer of worlds." - Java, probably
😁15👎2🤬2👍1
March 29th, 2022 Ronin announced an unknown Threat Actor breached and stole $615,014,352. More specifically the individual(s) stole 173,600 Ethereum + $25,500,000.

This may be the largest heist in internet history.
🤯10
This media is not supported in your browser
VIEW IN TELEGRAM
However, this Threat Actor has not surpassed the infamous Heather Morgan a.k.a. RazzleKhan who was arrested for laundering $4,500,000,000 in Bitcoin.

Video of this individual rapping on TikTok prior to her arrest
💩21😁16🤮7👏2😱2🤔1🤣1
HIVEv5's IPfuscation technique, noted by Sentinel One, is an example of Threat Actor creativity

tl;dr the hardcoded IP addresses are masquerading as potential C2 addresses, but it is actually obfuscated shellcode arrays.

Paper and samples available here: https://samples.vx-underground.org/samples/Families/HiveRansomware/
👍2🤬1
Threat Intelligence trying to identify LAPSUS$ group's motives
😁31👍3👎1🤔1😱1
A curated list of service names in various BlackByte ransomware group attacks.

"I'm so lonely, help me."
"I'm at a dead end, help me."
"You laugh a lot, because you simply don't have the strength to cry."
"When will it end? I want this."

Intel and photo via AltShiftPrtScn
😢16😁8👍4
We are happy to announce we have received a complete copy of the Malshare collection - courtesy of our friend Silas Cutler.

We will make it available for bulk download in the coming days.
👍24🔥1
Everyone gets a 100%.
😁32😱4🤯3💩1