vx-underground
46.4K subscribers
3.98K photos
426 videos
84 files
1.46K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
LAPSUS$ also threw their System Admins under the bus exposing their passwords to confluence (among other things). We have censored the passwords they displayed. However, it should be noted these passwords are very easily guessable and used multiple times...
🤔3🔥1🤯1
A Java Springcore RCE 0day exploit has been leaked. It was leaked by a Chinese security researcher who, since sharing and/or leaking it, has deleted their Twitter account.

We have not verified the exploit.

Download the 0day POC here: https://share.vx-underground.org/
👍5😢53👎1
"Now I am become Death, the destroyer of worlds." - Java, probably
😁15👎2🤬2👍1
March 29th, 2022 Ronin announced an unknown Threat Actor breached and stole $615,014,352. More specifically the individual(s) stole 173,600 Ethereum + $25,500,000.

This may be the largest heist in internet history.
🤯10
This media is not supported in your browser
VIEW IN TELEGRAM
However, this Threat Actor has not surpassed the infamous Heather Morgan a.k.a. RazzleKhan who was arrested for laundering $4,500,000,000 in Bitcoin.

Video of this individual rapping on TikTok prior to her arrest
💩21😁16🤮7👏2😱2🤔1🤣1
HIVEv5's IPfuscation technique, noted by Sentinel One, is an example of Threat Actor creativity

tl;dr the hardcoded IP addresses are masquerading as potential C2 addresses, but it is actually obfuscated shellcode arrays.

Paper and samples available here: https://samples.vx-underground.org/samples/Families/HiveRansomware/
👍2🤬1
Threat Intelligence trying to identify LAPSUS$ group's motives
😁31👍3👎1🤔1😱1
A curated list of service names in various BlackByte ransomware group attacks.

"I'm so lonely, help me."
"I'm at a dead end, help me."
"You laugh a lot, because you simply don't have the strength to cry."
"When will it end? I want this."

Intel and photo via AltShiftPrtScn
😢16😁8👍4
We are happy to announce we have received a complete copy of the Malshare collection - courtesy of our friend Silas Cutler.

We will make it available for bulk download in the coming days.
👍24🔥1
Everyone gets a 100%.
😁32😱4🤯3💩1
This media is not supported in your browser
VIEW IN TELEGRAM
x86Matthew demonstrating how to send data to other computers using sound (written in C WINAPI)

Code: https://www.x86matthew.com/view_post?id=audio_transmit
😁14👏8👍43
Image 1: EN
Image 2: RU
🎉79🔥8👍5👏53🥰1
FveGetRecoveryPasswordBackupInformation() goes first: it will tell you where did you place your BitLocker Recovery Password backup. 1 = AD, 2 = OneDrive?, 4 = AAD, 8 = file, 16 = printout.

Noted by Grzegorz Tworek
👍2😱1
March 29th, 2022 Ronin_Network announced an unknown Threat Actor breached and stole 173,600 Ethereum + $25,500,000. Or approx. $631,530,656.00

April 3rd, 2022 the funds began being washed (and/or laundered or move).

Intel and photo via peckshield && AlvieriD

Link for additional information: https://etherscan.io/address/0xbc25d57412a04956cdd95af07825c5c1f34d29eb
😱8😁31