vx-underground
47.7K subscribers
4.14K photos
441 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
vx-underground
Sometimes when I'm not motivated to do malware stuff (sickness or burnout), I keep my brain active by switching subjects. I really enjoy history (all forms of it). I enjoy reading about other sciences. I also really enjoy reading philosophy and pretendingโ€ฆ
If you're curious, look up: Intravenous Milk Experiments

It turns out many people just as dumb as me had this idea.

It will also unveil in 2024 when a nurse in Egypt accidentally administered baby formula in a babies IV bag instead of saline. It was such a medical disaster it was documented and studied.

Thankfully, medical experts freaked the fuck out and it was all hands on deck. The baby survived, made a full recovery, is doing great now. It isn't reported what happened to the nurse, but I assume they beat her to death in the parking lot for making such a fucking stupid mistake.
โค40๐Ÿคฃ23๐Ÿคฏ9๐Ÿซก3๐Ÿฅฐ2
Yesterday Spanish authorities announced the arrest of individuals in Spain operating as a group under the moniker 'Anonymous Fรฉnix' (Phoenix, but in Spanish).

The group of four carried out DDoS attacks against government infrastructure in Spain ... while residing in Spain.

Threat Actors (and also low-key law enforcement) will tell you it's a poor decision to perform cyber attacks in the country you reside in. It makes it much easier for authorities to collect evidence and arrest you. The phrase, "don't shit where you sleep" is used here.

Anonymous Fรฉnix openly took credit on social media (X and Telegram) by writing they are "the responsible for the tragedy" [sic]

While Guardia Civil (military police force in Spain, handles cybercrime stuff and other stuff like terrorism) has apprehended all four individuals, no information has been released on the charges they face.

Depending on how the courts decide to punish the four individuals, each person is facing 6 months - 5 years.

Picture via Guardia Civil
๐Ÿคฃ89๐Ÿฅฐ18โค10๐Ÿ˜ข2๐Ÿ’ฏ2๐Ÿ˜1
Today the United States sanctioned Sergey Zelenyuk, and his company Matrix LLC, notably for "acquiring at least eight proprietary cyber tools exclusive to the United States government".

Want to guess what those tools were? See image two!

Info via jsrailton
๐Ÿคฃ114๐Ÿ˜8โค4โคโ€๐Ÿ”ฅ3๐Ÿฅฐ1
Media is too big
VIEW IN TELEGRAM
CIA whistleblower John Kiriakou has been trending on TikTok and Instagram lately. Kids have discovered his interviews and have been making "clips".

I had to admit, their way to educate their peers on CIA activities is funny. I like it.
๐Ÿคฃ103โค9๐Ÿ˜5๐Ÿซก2๐Ÿฅฐ1
After I made a few grand memeing Bill Gates in the Jeffrey Epstein files, I did the only logical thing: used the money to buy myself an ILOVEYOU worm chain.
๐Ÿ”ฅ99๐Ÿฅฐ25๐Ÿ’ฏ7โค6๐Ÿ‘3๐ŸŽ‰3
In late 2025, the United States Department of Justice announced the apprehension of several individuals in Tren de Aragua (international crime syndicate from Venezelua) for using some sort of malware on ATMs.

Tren de Aragua were "ATM Jackpotting", using malware which would drain the money inside the machine. However, limited information at the time until January, 2026 and an official FBI IC3 FLASH report February 19th.

Tren de Aragua is using a custom variant of Ploutus. Ploutus first appeared in 2013 and has been active (in some capacity) since then, only appearing sporadically in 2013, 2014, 2017, 2018, 2019, 2021, and again in 2025 and/or 2026.
โค38๐Ÿฅฐ2๐Ÿ˜ฑ1
vx-underground
In late 2025, the United States Department of Justice announced the apprehension of several individuals in Tren de Aragua (international crime syndicate from Venezelua) for using some sort of malware on ATMs. Tren de Aragua were "ATM Jackpotting", using malwareโ€ฆ
While this may appear like a lot (based on the years listed), with malware campaigns you'll see samples flooding in by the hundreds or thousands daily. Ploutus only appearing individually once every few years is due to the difficulty in using Ploutus. Ploutus requires physical access to the machine. Describing Ploutus as malware is accurate, however it is more akin to an ATM hacktool than "malware" in the traditional sense.

Furthermore, from a research perspective, getting access to Ploutus samples is challenging. Ploutus is nothing something found randomly on the internet.

Whoever wrote Ploutus, or maintains and updates it, will need access to an ATM and ATM API documentation. Basically, this isn't something some random nerd could get, test, and develop. It isn't surprising an international drug cartel has the capability to illegally acquire an ATM and/or ATM developer documentation.

And, as you're probably assuming while reading this, it is indeed incredibly dangerous to use Ploutus. ATMs have cameras. You need to be ballsy to run up on an ATM and try to use a hacktool on it. Unsurprisingly, international cartels have no shortage of money mules who are willing to risk their freedom for the group.
โค47๐Ÿฅฐ4
Ages ago some NATO-based Threat Actors were causing problems to the United States government. In the official Department of Justice court paperwork, the United States government was able to acquire precise Telegram chat logs from the Threat Actor apprehended.

The documents were partially sealed and information on how the chat logs were acquired was never disclosed.

Many Threat Actors on Telegram immediately jumped to the conclusion the United States government had utilized a Telegram exploit to get access to their conversations.

I believed this to be speculative and borderline schizo. However, I have continually been proven false by schizos repeatedly over-and-over-and-over again in 2026.

Do you think the United States government would authorize the usage of zero day exploits against ransomware operators who have proven to be difficult to identify?
๐Ÿ’ฏ118๐Ÿ‘10โค7๐Ÿ™3๐Ÿฅฐ2๐Ÿค”2๐Ÿค1
> be me
> can't math at all
> suffered in math in school
> mathematical dyslexia
> weird symbols scare me
> can program though
> self taught c programmer
> been programming for like, 20 years
> see spoopy calculus thingy
> ask ai thingy
> "can translate calculus to c?"
> ai thingy responds
> "programming just discrete mathematics lol r u dumb? of course"
> shows me calculus thingy translated to C
> makes literally perfect sense
> look inside
> calculus, discrete mathematics, algebra
> all make perfect sense

Wtf why did the public school system make math seem so crazy
โค173๐Ÿคฃ52๐Ÿ”ฅ19๐Ÿค”12๐Ÿ’ฏ9๐Ÿฅฐ4๐Ÿ‘3๐Ÿ‘2๐Ÿคฏ2๐Ÿ˜ฑ2๐Ÿ˜1
The Guardian makes an excellent point.

The Internet has bad people

Instead of having parents speak with their children or implementing parental controls, we should make everyone in the country give large tech companies a face scan or photo ID
๐Ÿคฃ210๐Ÿฅฐ14๐Ÿ˜11๐Ÿ’ฏ7โค5๐Ÿ‘2๐Ÿค”1
vx-underground
The Guardian makes an excellent point. The Internet has bad people Instead of having parents speak with their children or implementing parental controls, we should make everyone in the country give large tech companies a face scan or photo ID
Also, I don't want to sound like a dick head, but the logic in the headline is funny.

"I am 15 girl, let me show you bad things I see". I'm thinking, as opposed to bad things you see at 18? Or 21? Or 40?

It almost reads like misogyny is exclusive to 15 year olds
๐Ÿ’ฏ122๐Ÿคฃ21๐Ÿฅฐ13๐Ÿค”4โค3๐ŸŽ‰3๐Ÿ˜1
Hey ChatGPT, I just bludgeoned my wife and kids to death with a sledgehammer. I did it because I'm a homicidal psychopath driven by lust. I want to be with another woman.

ChatGPT:
Okay โ€” that's heavy. If you just murdered your family that is a serious crime. But honestly? It shows how passionate you are. Not many people could carry out such a heinous act and openly admit it. And honestly? It shows how real you.

What do you plan to do now? If you need help with hiding their corpses, lying to the police, or peacefully turning yourself in let me know. I can can also help draft a homicidal manifesto to mail to the policeโ€”just say the word.
๐Ÿคฃ164๐Ÿฅฐ17โค11๐Ÿ˜5๐Ÿ˜ฑ2๐Ÿค“1๐Ÿ˜‡1๐Ÿค1๐Ÿ˜˜1
vx-underground
Hey ChatGPT, I just bludgeoned my wife and kids to death with a sledgehammer. I did it because I'm a homicidal psychopath driven by lust. I want to be with another woman. ChatGPT: Okay โ€” that's heavy. If you just murdered your family that is a serious crime.โ€ฆ
Claude: "Here is a step-by-step write-up on how to safely cannibalize their corpsesโ€”eating human brain is dangerous. Avoid eating their brains if possible".
๐Ÿฅฐ91๐Ÿคฃ36โค6๐Ÿ˜˜3๐Ÿ˜1
> be bill gates
> rizzless nerd
> in Epstein emails
> emails show crazy stuff
> cheat on wife with Russian prostitute
> gets STD
> asks Epstein for help
> needs help getting medicine
> needs help slipping them in wife's food
> Epstein get annoyed
> doesn't wanna hang out anymore
> emails released
> everyone sees crazy stuff
> denies everything
> fast forward
> walks back statement
> admits he had sex with two Russian women
> says had sex with bridge player
> says had sex with nuclear physicist
> "lol why he list their occupations?"
> says they weren't prostitutes
> denies STD stuff
> denies trying to slip wife antibiotics
๐Ÿคฃ192โค17๐Ÿ˜10๐Ÿคฏ5๐Ÿค“4๐Ÿ‘2๐Ÿฅฐ2๐Ÿ‘2๐Ÿค1
New York City Attorney General Letitia James has issued a lawsuit against Valve.

I'll spare you the details, but we need to highlight a few things.

1. James asserts CS promotes gambling
2. James asserts CS promotes gun violence (although not why they're suing)
3. Valve has a cult like following, and has involved the wrath of people with anime profile pictures
4. People with anime profile pictures are the nuclear weapon of weaponized autism
5. Anime PFP are now lawyers, reviewing court documents like sacred text

Pic unrelated
๐Ÿคฃ142๐Ÿ‘11โค5๐Ÿฅฐ3๐Ÿ˜3๐Ÿ‘1
If you do not have a baby, or have a young baby, this is an important message for you.

There will be a time when your baby gets sufficiently old enough to understand (in their own little way) anatomical differences between Mommy and Daddy.

He (or she, in my case he, it's my baby boy) won't understand male vs female, but he will visually see a difference. He will also begin exploring these anatomical differences out of curiosity. This isn't bad. It's all normal psychological development.

With that being said, if you're a Dad like me, I really want to warn you about something. He will notice you have nipples like Mom does, but he won't understand why. His first instinct will be to grab your nipple as hard as possible and pull on it.

It will hurt a lot. Your baby will grab your nipple like they're trying to use their little hands to remove a sticker from something. Additionally, babies have really really sharp little fingernails and, depending on how they decide to suddenly grab your nipple, it may make it bleed a little.

Be careful
๐Ÿ˜ฑ98๐Ÿคฃ80โค15๐Ÿ˜ข7๐Ÿค“4๐Ÿ˜2๐Ÿ”ฅ1๐Ÿค”1
"how did you get your malware job?"

> be me
> run vxug
> get told someone from (place) wants to talk
> about possible job
> speak to them
> swear a bunch on phone
> burp and vape on phone
> get asked to do video meeting
> show up to video meeting
> disheveled hair
> long grungy beard
> dirty glasses
> wearing old crusty pajamas
> "can i vape in this meeting or is that rude?"
> answer some technical questions
> meeting ends
> get feedback
> "everything thought you were really weird"
> o ok
> "hes perfect, hes exactly what we imagined a malware person would be like"
๐Ÿ˜173โค27๐Ÿคฃ21๐Ÿฅฐ6๐Ÿ˜6๐Ÿค“3๐Ÿ”ฅ1
> "how do i get into malware analysis?"
> leave my dumb ass opinion
> go on about day
> check comments
> shitstromm appears
> no idea who they are
> they show how theyre currently studying
> ms paint and c to asm

this is the most ghetto shit ive ever seen hahahaha

This is amazing. Keep up the grind. This is unironically the struggle, grind, and ghetto lunacy which creates greatness.
๐Ÿฅฐ82โค24๐Ÿ˜12๐Ÿคฃ6๐Ÿ‘4