vx-underground
46.4K subscribers
3.99K photos
427 videos
84 files
1.46K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
This media is not supported in your browser
VIEW IN TELEGRAM
>Openly share 159GB file of kitty cat pictures
>5,350+ people rush to download the file
>850TB of web traffic flood in
>Cloudflare reports 1,850% increase in web traffic
>everyone_panic.jpeg
>More people try to download the file can't
>People angry, demand cats
πŸ”₯108πŸ₯°39🀣22❀12🫑6πŸ‘3πŸ‘3❀‍πŸ”₯1😒1πŸ€“1
APT samples and papers:

2024.10.24 - Operation Cobalt Whisper - Threat Actor Targets Multiple Industries Across Hong Kong and Pakistan
2025.01.20 - Operation Hurricane - A brief discussion of the techniques and tactics of the Xinhai Lotus organization in memory
2025.01.21 - Love and hate under war - The GamaCopy uses military-related bait to launch attacks on Russia
2025.01.23 - Mapping Suspected KEYPLUG Infrastructure - TLS Certificates, GhostWolf, and RedGolf APT41 Activity
2025.01.23 - The J-Magic Show - Magic Packets and Where to find them
2025.01.28 - ScatterBrain - Unmasking the Shadow of PoisonPlug's Obfuscator
2025.01.29 - CL-STA-0048 - An Espionage Operation Against High-Value Targets in South Asia
2025.01.29 - Operation Phantom Circuit - North Koreas Global Data Exfiltration Campaign
2025.02.03 - Analysis of malicious HWP cases of APT37 group distributed through K messenger
2025.02.03 - macOS FlexibleFerret - Further Variants of DPRK Malware Family Unearthed
2025.02.07 - Chinese-Speaking Group Manipulates SEO with BadIIS
2025.02.11 - Sandworm APT Targets Ukrainian Users with Trojanized Microsoft KMS Activation Tools in Cyber Espionage Campaigns
2025.02.12 - 2024 Global APT Research Report
2025.02.12 - Cybercrime - A Multifaceted National Security Threat
2025.02.12 - The BadPilot campaign - Seashell Blizzard subgroup conducts multiyear global access operation
2025.02.12 - UAC-0063 Cyber Espionage Operation Expanding from Central Asia
2025.02.13 - Analyzing DEEP#DRIVE - North Korean Threat Actors Observed Exploiting Trusted Platforms for Targeted Attacks
2025.02.13 - Multiple Russian Threat Actors Targeting Microsoft Device Code Authentication
2025.02.13 - RedMike (Salt Typhoon) Exploits Vulnerable Cisco Devices of Global Telecommunications Providers
2025.02.13 - Stimmen aus Moskau - Russian Influence Operations Target German Elections
2025.02.13 - You've Got Malware - FINALDRAFT Hides in Your Drafts
2025.02.18 - Earth Preta Mixes Legitimate and Malicious Components to Sidestep Detection
2025.02.19 - Signals of Trouble - Multiple Russia-Aligned Threat Actors Actively Targeting Signal Messenger
2025.02.20 - Analysis of the APT-C-28 (ScarCruft) organizations attack activities using fileless delivery of RokRat
2025.02.20 - DeceptiveDevelopment targets freelance developers
2025.02.20 - SPAWNCHIMERA Malware - The Chimera Spawning from Ivanti Connect Secure Vulnerability
2025.02.20 - Stately Taurus Activity in Southeast Asia Links to Bookworm Malware
2025.02.20 - Weathering the storm - In the midst of a Typhoon
2025.02.21 - Angry Likho - Old beasts in a new forest
2025.02.23 - The Bybit Incident - When Research Meets Reality
2025.02.24 - Erudite Mogwai Uses Custom Stowaway to Stealthily Advance Online
2025.02.24 - Operation SalmonSlalom - A new attack targeting industrial organizations in APAC
2025.02.25 - Chinese APT Target Royal Thai Police in Malware Campaign
2025.02.26 - RustDoor and Koi Stealer for macOS Used by North Korea-Linked Threat Actor to Target the Cryptocurrency Sector
2025.02.27 - A case of phishing email attack by Larva-24005 group targeting Japan
2025.02.27 - Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools
2025.02.27 - Squidoor - Suspected Chinese Threat Actor's Backdoor Targets Global Organizations
2025.03.03 - Operation sea elephant - The dying walrus wandering the Indian Ocean
2025.03.04 - Call It What You Want - Threat Actor Delivers Highly Targeted Multistage Polyglot Malware
2025.03.04 - Likely DPRK Network Backstops on GitHub, Targets Companies Globally
2025.03.05 - Silk Typhoon targeting IT supply chain
2025.03.12 - Ghost in the Router - China-Nexus Espionage Actor UNC3886 Targets Juniper Routers
2025.03.12 - Hack The Sandbox - Unveiling the Truth Behind Disappearing Artifacts
2025.03.12 - New Android Spyware by North Korean APT37
2025.03.13 - Analyzing OBSCURE#BAT - Threat Actors Lure Victims into Executing Malicious Batch Scripts to Deploy Stealthy Rootkits
2025.03.13 - Detailed Analysis of DocSwap Malware Disguised as Securit
πŸ”₯31❀9πŸ‘7😒1πŸ€“1
The attached images is from a 1988 malware analysis report from AT&T Bell Labs. The report does a high-level overview of a viral infector targeting UNIX operating systems.
πŸ”₯41πŸŽ‰2❀1πŸ‘1πŸ€“1
Updates to the Malware Builder collection via Cryakl (may include subvariants)

-A7m3dRat
-CraxsRat
-Gh0stCringe
-HadesRat
-KazyBot
-Nbclass
-PhoenixKeylogger
-PurpleFox

https://vx-underground.org/Builders
πŸ”₯28πŸ€“2πŸ‘1😒1
Hello to the Threat Actor who compromised the Parliament of the Republic of South Africa Xitter account and gave us a shoutout... kind of?

They live streamed homosexual pornography and left the vx-underground Xitter tab open.

πŸ₯΄πŸ₯΄
🀣196😱8❀6❀‍πŸ”₯4😁2πŸ€“2πŸ₯°1
In these trying times the one thing which remains constant is the value of kitty cat pictures.

Please take a copy of our kitty cat picture collection. It is 159.9GB (111,429 files) of kitty cat pictures (a torrent!)

Economic problems 🀝Kitty cats

https://vx-underground.org/Torrents
❀‍πŸ”₯66🀝13πŸ₯°5❀4🀣4😁1😒1πŸ€“1
vx-underground
In these trying times the one thing which remains constant is the value of kitty cat pictures. Please take a copy of our kitty cat picture collection. It is 159.9GB (111,429 files) of kitty cat pictures (a torrent!) Economic problems 🀝Kitty cats https://vx…
Spent a long time making sure this torrent was good, TorGuard could seed it for us, and fixing our melted infra.

You nerds better download these cat pictures.
❀82πŸ€“19🫑10😒1
Hello,

We see from our torrents that an absolutely colossal amount of people are downloading AND seeding our kitty cat picture collection

What the fuck lol
❀120❀‍πŸ”₯24🀣7πŸ‘5πŸ€”3πŸŽ‰3πŸ€“2😒1πŸ’―1🀝1
Thank you, B F R e p o V 3 F i l e s, for sharing the cat picture collection. Not sure if you'd like to label it a breach, but we'll take it.

Β―\_(ツ)_/Β―
🀣194πŸ‘18❀‍πŸ”₯13πŸ₯°6❀5😍4πŸ€”2🫑2πŸ”₯1πŸ‘1πŸ€“1
Hello,

"Sean" has informed us that, somewhere in the midst of our kitty cat collection, is a photo of a cute doggie making homophobic remarks.

This is terrible news. The entire collection is contaminated.
😱200🀣190😒18πŸ‘17❀12😁11πŸ€“6🫑4πŸ”₯2🀯2πŸ’―2
Hello,

Tomorrow we have a large update coming. Unsurprisingly, it is the same ol', same ol'. It is malware source code, samples, and papers.

-smelly smellington

P.S. glad so many of you liked the kitty cat collection. It's fun doing goofy stuff on the internet
πŸ‘98❀‍πŸ”₯43❀12πŸŽ‰5πŸ’―5πŸ”₯1πŸ₯°1😁1
wtf python imports are tariffed
😁157🀣111🀯13😒10πŸ™5πŸ€”4😱3πŸŽ‰3🫑3❀2πŸ’―2
gronk is this true
πŸ‘35🀣17πŸ€”6😒2
vx-underground
gronk is this true
Also, unrelated to Gronk, we've updated vx-underground. We've added InTheWild 140 - 151. This is 275,000 new malware samples.

Additionally, we've updated TheOldNewThing archive for January, February, and March.

Large paper tsunami coming today.

Cheers,
❀40❀‍πŸ”₯8πŸ€“5πŸ‘1😒1