vx-underground
46.7K subscribers
4.01K photos
430 videos
84 files
1.46K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Today the United States Department of Justice announced the indictment (and in some cases additional charges) for 12 individuals. The defendants are charged in RICO conspiracy for over $263,000,000 in cryptocurrency theft, money laundering, and home break-ins.

Each individual listed was (in some capacity) involved in the COM(munity) scene.

This is the first time, to the best of our knowledge, a group of primarily English speaking, loosely affiliated, cybercriminals are in a RICO case.

RICO, the United States "Racketeer Influenced and Corrupt Organizations Act", passed in 1970, is generally reserved for organized crime. It was designed to combat organized crime and allows prosecutors to charge individuals involved in an ongoing criminal enterprise.

RICO charges are not a joke. These are extremely serious charges.

RICO charges allow multiple people to be tied to a conspiracy and amplify any/all charges. A single RICO charge is worth 20 years in Federal Prison and can extend to life in prison.

The United States Department of Justice slapping COM-scene people with a RICO charge is a sign they're not playing around with cryptocurrency fraud.

The individual indicted are as follows:
- MALONE LAM a/k/a "King Greavys", "7", "$$$", "Kg", "Anne Hathaway"
- MARLON FERRO a/k/a "Marlo", "GothFerrari"
- HAMZA DOOST a/k/a "Scyllia", "Β’"
- CONOR FLANSBURG a/k/a "OO", "Green Room", "d0uu0b"
- KUNAL MEHTA a/k/a "Papa", "The Accountant", "Shrek", "Neil"
- ETHAN YARALLY a/k/a "Rand", "15%"
- CODY DEMIRTAS a/k/a "K O", "Kody"
- AAKAASH ANAND a/k/a "Light", "Dark"
- EVAN TANGEMAN a/k/a "E", "Tate", "Evan | Exchanger"
- JOEL CORTES a/k/a "J"
- [Unidentified 1] a/k/a "~_~", "Squiggly", "CHEN"
- [Unidentified 2] a/k/a "Danny", "Meech"
- TUCKER DESMOND

The full article, released by the Department of Justice, defines the roles of each individual, the charge they carry, a total sum of money stolen and/or items illegally acquired using stolen money, and additional (unlisted) co-conspirators.

Note: per the RICO charge, if the Judge rules the individual was involved in widespread fraud or violent crime, individuals may face a punishment of life in prison. Hence, each person listed may eligible for life in prison

Time being faced:
- MALONE LAM: 60 years
- MARLON FERRO: 60 years
- HAMZA DOOST: 40 years
- CONOR FLANSBURG: 40 years
- KUNAL MEHTA: 40 years
- ETHAN YARALLY: 40 years
- CODY DEMIRTAS: 40 years
- AAKAASH ANAND: 60 years
- EVAN TANGEMAN: 40 years
- JOEL CORTES: 40 years
- [Unidentified 1] - 60 years
- [Unidentified 2] - 60 years
- TUCKER DESMOND - 20 years
πŸ₯°56πŸ‘21😒7🀣7🀝7πŸ”₯5❀4😁1
May 11th, 2025, Coinbase was compromised. Coinbase confirmed the compromise on May 15th, 2025 with the United States Securities and Exchange Commission (U.S. SEC)

Coinbase states an unknown Threat Actor e-mailed them asserting they had obtained sensitive personal identifiable information (PII) on the Coinbase userbase, as well as internal documentation from Coinbase which derives from customer service and/or account management systems.

Coinbase has confirmed the compromise is the result of multiple contractors and/or employees outside of the United States receiving "payment" for access to their systems. Coinbase confirms the individuals who received payment for access have been terminated.

The unknown Threat Actor demanded $20,000,000. Coinbase asserts they will NOT pay the ransom demand and succumb to extortionists. They have placed a $20,000,000 bounty for the identification and apprehension of individual(s) responsible for the compromise.

Customer data stolen as a result of the compromise:
- First name
- Last name
- Address
- Phone number
- Email address
- Last 4 digits of social security number
- Masked bank-account numbers
- Government ID images (drivers license, passport)
- Account data (balance, transaction history)

No passwords or private keys were obtained.

Coinbase has stated they believe the estimated damage to their company (internal, or reputational) to be between $100,000,000 - $400,000,000.
🀣83🀯24❀10😁5πŸ‘3πŸ”₯3😱2😒2🀝1😘1
πŸŽ‰239😁25🫑14🀣10πŸ€”4❀2❀‍πŸ”₯1πŸ‘1πŸ’―1
vx-underground
Photo
this is a meme, my wife didnt cheat on me
🀣145πŸ™32😒9πŸ€“6❀5πŸ”₯4🫑4πŸ€”3🀯3🀝3😱2
We are now 6 years old.

In 6 years this account, and website, went from small and obscure to one of the largest information security related Twitter profiles. Twitter and Telegram combined, vx-underground has over 400,000 people who follow our content and discussions.

It is very surreal feeling seeing a small personal project, dedicated to saving stuff that I thought was cool, becoming so large and popular. Sometimes I find it hard to believe what I say matters to anyone, because at the end of the day I'm just some stinky nerd who likes spamming cat pictures.

As I've said for the past 6 years: nothing will change. We will continue to provide free malware source, samples, and papers.

That's all I've got to say right now. Thank you for all the love and support. I look forward to continually serving all of you.

- smelly smellington
πŸ”₯174❀107❀‍πŸ”₯29🫑11πŸ‘8🀣8πŸ‘5πŸŽ‰4πŸ€“2😒1
srry
❀228😁57πŸ”₯18🀣7πŸ₯°6❀‍πŸ”₯2😒1πŸ˜‡1
Dear person DdoSing us,

We're not around right now combat the DdoS and we're all super busy. If you'd like to get our attention, or send a message, or whatever you're doing, please DdoS us at later period in time.

I'm busy with my newborn son and Bradley is still taking care of his Dad. I think we'll have better capacity to deal with a DdoS in like... August or September? So if you want to actually get our attention do it then. Otherwise, unfortunately, you'll just keep DdoSing us forever and nothing will really happen.

Sorry!
❀198🀣55πŸ”₯17😁12🀯4πŸ’―4πŸ™3πŸ€“3😒2😎2πŸ€”1
vx-underground
Dear person DdoSing us, We're not around right now combat the DdoS and we're all super busy. If you'd like to get our attention, or send a message, or whatever you're doing, please DdoS us at later period in time. I'm busy with my newborn son and Bradley…
Learned we were under DDoS by accident when I was messaging TorGuard about moving some data around. I forgot the directory layout, checked the site, and realized it was being DdoSd. I was like, "Gosh dang it, I guess we'll talk about it some other time".

Anyway, got to go, having baked potatoes for dinner.

Talk to you later. Love you
- smelly
❀142😁18πŸ”₯6πŸŽ‰4😒1πŸ™1😎1
πŸ₯°93😍11❀‍πŸ”₯6❀5😒1
Ladies, what's preventing you from wearing these? Be honest
😁108🀣67😍12❀9πŸ‘3πŸ™2😒1
Media is too big
VIEW IN TELEGRAM
me when the feds show up asking why ive got 30tb of malware
🀣202😍31❀9πŸ‘9😁5πŸ€”5πŸ₯°1😒1πŸ’―1
Hello,

For the past 6 years I've had people ask if I will be attending DEFCON. The answer is still: No. However, I may make an appearance at DEFCON 35 or DEFCON 36. It will also be the first cybersecurity conference I've ever attended. Cool beans

Thanks,
- smelly smellington
πŸ”₯138❀19😱11❀‍πŸ”₯10πŸ‘8πŸ‘4🫑4😒1
🀣194❀12🫑7😒6😁2πŸ€“1😘1
VMPSoft has been DMCA-ing YouTube videos which show how to combat malware payloads abusing VMProtect
😁105🀣75πŸ€”9πŸ”₯5πŸ€“5❀1πŸ‘1🀯1😒1
vx-underground
VMPSoft has been DMCA-ing YouTube videos which show how to combat malware payloads abusing VMProtect
"Leave our customers alone!!!1" β€” VMPSoft, probably
🀣115😁11πŸ‘3πŸ’―2❀1
Politics aside β€” will this impact the cybercrime ecosystem? If the Russian Federation establishes a friendship with the United States, will we see an impact on ransomware groups?
πŸ€”117😁29🀣15πŸ‘6🀝4😒3🀩1
This media is not supported in your browser
VIEW IN TELEGRAM
mfw I roll back a snapshot
🀣132😁21🀯4🫑4❀2πŸ”₯2😱1