vx-underground
47.7K subscribers
4.16K photos
443 videos
84 files
1.49K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Yesterday Spanish authorities announced the arrest of individuals in Spain operating as a group under the moniker 'Anonymous Fรฉnix' (Phoenix, but in Spanish).

The group of four carried out DDoS attacks against government infrastructure in Spain ... while residing in Spain.

Threat Actors (and also low-key law enforcement) will tell you it's a poor decision to perform cyber attacks in the country you reside in. It makes it much easier for authorities to collect evidence and arrest you. The phrase, "don't shit where you sleep" is used here.

Anonymous Fรฉnix openly took credit on social media (X and Telegram) by writing they are "the responsible for the tragedy" [sic]

While Guardia Civil (military police force in Spain, handles cybercrime stuff and other stuff like terrorism) has apprehended all four individuals, no information has been released on the charges they face.

Depending on how the courts decide to punish the four individuals, each person is facing 6 months - 5 years.

Picture via Guardia Civil
๐Ÿคฃ91๐Ÿฅฐ19โค10๐Ÿ˜ข2๐Ÿ’ฏ2๐Ÿ˜1
Today the United States sanctioned Sergey Zelenyuk, and his company Matrix LLC, notably for "acquiring at least eight proprietary cyber tools exclusive to the United States government".

Want to guess what those tools were? See image two!

Info via jsrailton
๐Ÿคฃ120๐Ÿ˜8โค4โคโ€๐Ÿ”ฅ3๐Ÿฅฐ1
Media is too big
VIEW IN TELEGRAM
CIA whistleblower John Kiriakou has been trending on TikTok and Instagram lately. Kids have discovered his interviews and have been making "clips".

I had to admit, their way to educate their peers on CIA activities is funny. I like it.
๐Ÿคฃ111โค9๐Ÿ˜5๐Ÿซก2๐Ÿฅฐ1
After I made a few grand memeing Bill Gates in the Jeffrey Epstein files, I did the only logical thing: used the money to buy myself an ILOVEYOU worm chain.
๐Ÿ”ฅ104๐Ÿฅฐ27๐Ÿ’ฏ7โค6๐Ÿ‘3๐ŸŽ‰3๐Ÿ˜1
In late 2025, the United States Department of Justice announced the apprehension of several individuals in Tren de Aragua (international crime syndicate from Venezelua) for using some sort of malware on ATMs.

Tren de Aragua were "ATM Jackpotting", using malware which would drain the money inside the machine. However, limited information at the time until January, 2026 and an official FBI IC3 FLASH report February 19th.

Tren de Aragua is using a custom variant of Ploutus. Ploutus first appeared in 2013 and has been active (in some capacity) since then, only appearing sporadically in 2013, 2014, 2017, 2018, 2019, 2021, and again in 2025 and/or 2026.
โค41๐Ÿฅฐ2๐Ÿ˜ฑ1
vx-underground
In late 2025, the United States Department of Justice announced the apprehension of several individuals in Tren de Aragua (international crime syndicate from Venezelua) for using some sort of malware on ATMs. Tren de Aragua were "ATM Jackpotting", using malwareโ€ฆ
While this may appear like a lot (based on the years listed), with malware campaigns you'll see samples flooding in by the hundreds or thousands daily. Ploutus only appearing individually once every few years is due to the difficulty in using Ploutus. Ploutus requires physical access to the machine. Describing Ploutus as malware is accurate, however it is more akin to an ATM hacktool than "malware" in the traditional sense.

Furthermore, from a research perspective, getting access to Ploutus samples is challenging. Ploutus is nothing something found randomly on the internet.

Whoever wrote Ploutus, or maintains and updates it, will need access to an ATM and ATM API documentation. Basically, this isn't something some random nerd could get, test, and develop. It isn't surprising an international drug cartel has the capability to illegally acquire an ATM and/or ATM developer documentation.

And, as you're probably assuming while reading this, it is indeed incredibly dangerous to use Ploutus. ATMs have cameras. You need to be ballsy to run up on an ATM and try to use a hacktool on it. Unsurprisingly, international cartels have no shortage of money mules who are willing to risk their freedom for the group.
โค50๐Ÿฅฐ4
Ages ago some NATO-based Threat Actors were causing problems to the United States government. In the official Department of Justice court paperwork, the United States government was able to acquire precise Telegram chat logs from the Threat Actor apprehended.

The documents were partially sealed and information on how the chat logs were acquired was never disclosed.

Many Threat Actors on Telegram immediately jumped to the conclusion the United States government had utilized a Telegram exploit to get access to their conversations.

I believed this to be speculative and borderline schizo. However, I have continually been proven false by schizos repeatedly over-and-over-and-over again in 2026.

Do you think the United States government would authorize the usage of zero day exploits against ransomware operators who have proven to be difficult to identify?
๐Ÿ’ฏ122๐Ÿ‘10โค8๐Ÿ™3๐Ÿฅฐ2๐Ÿค”2๐Ÿค2
> be me
> can't math at all
> suffered in math in school
> mathematical dyslexia
> weird symbols scare me
> can program though
> self taught c programmer
> been programming for like, 20 years
> see spoopy calculus thingy
> ask ai thingy
> "can translate calculus to c?"
> ai thingy responds
> "programming just discrete mathematics lol r u dumb? of course"
> shows me calculus thingy translated to C
> makes literally perfect sense
> look inside
> calculus, discrete mathematics, algebra
> all make perfect sense

Wtf why did the public school system make math seem so crazy
โค179๐Ÿคฃ53๐Ÿ”ฅ19๐Ÿค”12๐Ÿ’ฏ11๐Ÿฅฐ4๐Ÿ‘3๐Ÿ‘2๐Ÿคฏ2๐Ÿ˜ฑ2๐Ÿ˜1
The Guardian makes an excellent point.

The Internet has bad people

Instead of having parents speak with their children or implementing parental controls, we should make everyone in the country give large tech companies a face scan or photo ID
๐Ÿคฃ220๐Ÿฅฐ15๐Ÿ˜12๐Ÿ’ฏ9โค5๐Ÿ‘2๐Ÿค”2๐Ÿ˜ข1
vx-underground
The Guardian makes an excellent point. The Internet has bad people Instead of having parents speak with their children or implementing parental controls, we should make everyone in the country give large tech companies a face scan or photo ID
Also, I don't want to sound like a dick head, but the logic in the headline is funny.

"I am 15 girl, let me show you bad things I see". I'm thinking, as opposed to bad things you see at 18? Or 21? Or 40?

It almost reads like misogyny is exclusive to 15 year olds
๐Ÿ’ฏ132๐Ÿคฃ23๐Ÿฅฐ13๐Ÿค”4โค3๐ŸŽ‰3๐Ÿ˜1
Hey ChatGPT, I just bludgeoned my wife and kids to death with a sledgehammer. I did it because I'm a homicidal psychopath driven by lust. I want to be with another woman.

ChatGPT:
Okay โ€” that's heavy. If you just murdered your family that is a serious crime. But honestly? It shows how passionate you are. Not many people could carry out such a heinous act and openly admit it. And honestly? It shows how real you.

What do you plan to do now? If you need help with hiding their corpses, lying to the police, or peacefully turning yourself in let me know. I can can also help draft a homicidal manifesto to mail to the policeโ€”just say the word.
๐Ÿคฃ177๐Ÿฅฐ19โค11๐Ÿ˜5๐Ÿ˜ฑ2๐Ÿ˜‡2โคโ€๐Ÿ”ฅ1๐Ÿค“1๐Ÿค1๐Ÿ˜˜1
vx-underground
Hey ChatGPT, I just bludgeoned my wife and kids to death with a sledgehammer. I did it because I'm a homicidal psychopath driven by lust. I want to be with another woman. ChatGPT: Okay โ€” that's heavy. If you just murdered your family that is a serious crime.โ€ฆ
Claude: "Here is a step-by-step write-up on how to safely cannibalize their corpsesโ€”eating human brain is dangerous. Avoid eating their brains if possible".
๐Ÿฅฐ94๐Ÿคฃ39โค6๐Ÿ˜˜3๐Ÿ˜1
> be bill gates
> rizzless nerd
> in Epstein emails
> emails show crazy stuff
> cheat on wife with Russian prostitute
> gets STD
> asks Epstein for help
> needs help getting medicine
> needs help slipping them in wife's food
> Epstein get annoyed
> doesn't wanna hang out anymore
> emails released
> everyone sees crazy stuff
> denies everything
> fast forward
> walks back statement
> admits he had sex with two Russian women
> says had sex with bridge player
> says had sex with nuclear physicist
> "lol why he list their occupations?"
> says they weren't prostitutes
> denies STD stuff
> denies trying to slip wife antibiotics
๐Ÿคฃ205โค17๐Ÿ˜10๐Ÿคฏ6๐Ÿค“4๐Ÿ‘3๐Ÿฅฐ2๐Ÿ‘2๐Ÿค1
New York City Attorney General Letitia James has issued a lawsuit against Valve.

I'll spare you the details, but we need to highlight a few things.

1. James asserts CS promotes gambling
2. James asserts CS promotes gun violence (although not why they're suing)
3. Valve has a cult like following, and has involved the wrath of people with anime profile pictures
4. People with anime profile pictures are the nuclear weapon of weaponized autism
5. Anime PFP are now lawyers, reviewing court documents like sacred text

Pic unrelated
๐Ÿคฃ153๐Ÿ‘12โค5๐Ÿฅฐ3๐Ÿ˜3๐Ÿ‘1
If you do not have a baby, or have a young baby, this is an important message for you.

There will be a time when your baby gets sufficiently old enough to understand (in their own little way) anatomical differences between Mommy and Daddy.

He (or she, in my case he, it's my baby boy) won't understand male vs female, but he will visually see a difference. He will also begin exploring these anatomical differences out of curiosity. This isn't bad. It's all normal psychological development.

With that being said, if you're a Dad like me, I really want to warn you about something. He will notice you have nipples like Mom does, but he won't understand why. His first instinct will be to grab your nipple as hard as possible and pull on it.

It will hurt a lot. Your baby will grab your nipple like they're trying to use their little hands to remove a sticker from something. Additionally, babies have really really sharp little fingernails and, depending on how they decide to suddenly grab your nipple, it may make it bleed a little.

Be careful
๐Ÿ˜ฑ105๐Ÿคฃ95โค17๐Ÿ˜ข7๐Ÿค“4๐Ÿ˜2๐Ÿ”ฅ1๐Ÿค”1
"how did you get your malware job?"

> be me
> run vxug
> get told someone from (place) wants to talk
> about possible job
> speak to them
> swear a bunch on phone
> burp and vape on phone
> get asked to do video meeting
> show up to video meeting
> disheveled hair
> long grungy beard
> dirty glasses
> wearing old crusty pajamas
> "can i vape in this meeting or is that rude?"
> answer some technical questions
> meeting ends
> get feedback
> "everything thought you were really weird"
> o ok
> "hes perfect, hes exactly what we imagined a malware person would be like"
๐Ÿ˜187โค27๐Ÿคฃ27๐Ÿฅฐ6๐Ÿ˜6๐Ÿค“3๐Ÿ”ฅ1
> "how do i get into malware analysis?"
> leave my dumb ass opinion
> go on about day
> check comments
> shitstromm appears
> no idea who they are
> they show how theyre currently studying
> ms paint and c to asm

this is the most ghetto shit ive ever seen hahahaha

This is amazing. Keep up the grind. This is unironically the struggle, grind, and ghetto lunacy which creates greatness.
๐Ÿฅฐ96โค27๐Ÿ˜12๐Ÿคฃ7๐Ÿ‘5
> get DM
> hey check out this weird website
> lol ok
> doubao-app(dot)com
> pretending to be doubao(dot)com
> doubao is ai thingy from bytedance
> look at website
> download installer (.zip)
> .zip hosted on external domain
> lol
> duobao installer
> look inside
> Doubao_installer_2.0.31.exe
> n9.exe
> look at Doubao_installer_2.0.31.exe
> 307mb
> big boi
> electron app (js, ugh again)
> revert eyes to n9.exe
> 799kb
> small boi
> 32bit binary, c++ 8 (???)
> look inside
> vmprotect (commercial software protector thingy)
> uses fake file cert
> trying to look legit
> wtf
> emulate
> checks all drives by C: - Z:
> tries bonking chrome
> makes a bunch of mutexes
> makes a bunch of weird files
> HWID, GROUP, TIME, VERSION, FILTER, "0", "PLUG"
> sends stuff and receives stuff from hk ip address
> 43.199.114.131
> port 7777
๐Ÿฅฐ73๐Ÿ˜32โค11๐Ÿ‘8