vx-underground
49.4K subscribers
4.33K photos
469 videos
84 files
1.53K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
vx-underground
Okay, before I make a silly post have some context. Rostelecom is the largest telecommunication company in Russia. If you're in the United States, Rostelecom is basically like their AT&T or Verizon. Anyway, Rostelecom has a Cyber Threat Intelligence division…
It's funny stuff. When you reside in the United States (and presumably Europe) you always read about the Russian Federation or Chinese government performing cyber state-sponsored operations. It makes us look like a bitch who is getting bullied.

But then you cross the pond on the internet and take a look around and you're like, "hehe ya, we're doing it too actually, our cybersecurity companies just dont discuss it"
❀80πŸ’―37πŸ”₯16🀣12πŸ₯°4❀‍πŸ”₯1🀯1
As a malware nerd, I am so unimaginably tired of hearing about Stuxnet.

At this point it's propaganda by the United States to showcase supposed American superiority.

I refuse to believe that is the only state-sponsored malware campaign people know about or reference
❀66🀣42πŸ’―23πŸ₯°3πŸ”₯1
This media is not supported in your browser
VIEW IN TELEGRAM
Back in '84, nerds were developing this stuff with documentation printed on paper back they received physically in the mail.

The crowd collectively shit their pants in awe that someone was capable of doing this.

I just shit my pants thinking about it
πŸ₯°75😁22❀14πŸ‘5πŸ”₯1🀣1
Someone unironically recommended I buy a children's book on cybersecurity to read to my son.

I will not subject my son to computer shenanigans. He must forge his own path. His happiness is more important than legacy.

Malware is illegal and for nerds
πŸ₯°154🀣41❀24❀‍πŸ”₯4😁3πŸ‘1
vx-underground
Someone unironically recommended I buy a children's book on cybersecurity to read to my son. I will not subject my son to computer shenanigans. He must forge his own path. His happiness is more important than legacy. Malware is illegal and for nerds
However, if he wants to malware, I will super charge his brain and inject everything I know about malware and computer shenanigans into his skull and hope he exceeds me in every way possible.
❀138πŸ₯°30πŸ”₯15❀‍πŸ”₯7😱3
People living inside my computer,

I have updated the website which apparently most of you didn't know existed

I collect malware source code, samples, papers, and builders.

I've added more malware, I've stopped counting, but it's a big number

https://vx-underground.org/Updates
❀62🀣11πŸ₯°6πŸ”₯5πŸ‘3πŸ™3
ShinyHunters is ransoming ... HALLMARK CARDS

Those fucking shitty birthday cards you pick up at the drug store ARE BEING HELD RANSOMWARE

WHO RANSOMS BIRTHDAY CARDS

(info via AlvieriD)
🀣108❀14πŸ”₯8🀯7😁3πŸ₯°1
Dawg, I saw some stinky nerds discussing this recently identified malicious NPM package

This is, by a significant margin, some of the worst malicious code I've ever seen. I don't mean 'worst' as in dangerous, I mean this code is HOT garbage

https://socket.dev/npm/package/3-ways-how-to-get-free-gems-in-clash-of-clans834/files/1.0.2/package%20gene.py
🀣81❀9πŸ₯°3πŸ‘2πŸ€“2
vx-underground
Dawg, I saw some stinky nerds discussing this recently identified malicious NPM package This is, by a significant margin, some of the worst malicious code I've ever seen. I don't mean 'worst' as in dangerous, I mean this code is HOT garbage https://sock…
This dumb son of a bitch hardcoded the username 'Administrator' because that is (probably) the username on his (or her) machine. You're supposed to resolve the username with %USERPROFILE%, ya fuckin' goof
🀣132❀7πŸ₯°4😁4
Hello to all my Telegram friends who messaged me about Axios supply chain attack.

I'm well aware it happened. Here is reaction when it occurred in near real-time
πŸ₯°72🀣33😁10❀2🫑2
Here is another one of my reactions (I was in bed)
πŸ₯°67🀣38❀7😁4❀‍πŸ”₯2😒1
Big shenanigans on the internet today as Threat Researchers speperhypothulate that the Threat Actor responsible for the Axios supply chain attack may have accidentally DoS'd their own infrastructure from the volume of data coming in

Pathetic
πŸ₯°56🀣43❀7😁6πŸ‘1
vx-underground
Big shenanigans on the internet today as Threat Researchers speperhypothulate that the Threat Actor responsible for the Axios supply chain attack may have accidentally DoS'd their own infrastructure from the volume of data coming in Pathetic
I wanted to say propose, speculate, theorize, hypothesize, but I couldn't pick a word, so I made up speperhypothulate. I'm basically Shakespeare
πŸ₯°37πŸ‘12🫑11🀣5❀3πŸ”₯3πŸ€“3
1. This isn't fake.

2. Credentials are stored as hashes. It should be literally, with no exaggeration, impossible for a vendor to know your credentials while uppercase UNLESS they weren't storing passwords as hashes.

What the fuck is HSBC India doing?
🀣177❀11πŸ₯°7🀯6😁4πŸ”₯2
vx-underground
1. This isn't fake. 2. Credentials are stored as hashes. It should be literally, with no exaggeration, impossible for a vendor to know your credentials while uppercase UNLESS they weren't storing passwords as hashes. What the fuck is HSBC India doing?
I've seen some conversations online that suggest HSBC India has been transforming credentials with ToUpper prior to hashing. Now with a new code base, or something, in place users must now type in all upper case to account for the previous implementation

Okay, if that is true, isn't that a colossal fuck up? They were stripping case sensitivity while also telling users they need uppercase and lowercase letters? What the fuck is going on over there?
🀣99❀19🀝6πŸ‘4πŸ₯°4😱1
CISCO SOURCE CODE STOLEN

BITCH ITS TUESDAY

STOP
🀣153❀15πŸ₯°5😁3😒2
vx-underground
CISCO SOURCE CODE STOLEN BITCH ITS TUESDAY STOP
I'm sorry for yelling and the bad words. It has been a very intense 1 week and 2 days.

It has been so dramatic it borders on some kind of sadistic comedy piece
❀49😁26πŸ₯°10πŸ’―3❀‍πŸ”₯2
❀113🀩33😁23πŸ’―3πŸ₯°2πŸ”₯1😍1
Whoa

Core audience (my nerds and stinky internet degenerates), I made a post about an hour ago intended for my nerd homies about family shenanigans. I thought it was kind of funny, mildly interesting.

It somehow escaped core audience at a high rate of speed and some really weird people were making some really weird comments.

We got supply chain attacks, malware, and premium pictures of kitty cats, we do not have time for non-nerds stinking up the place.

Yikes.

Anyway, more updates on silly internet stuff soon. It involves malware and will include a picture of a cat.

Cheers
❀94😍7πŸ”₯4πŸ₯°2🀣2😁1
Chat, look what images just appeared ON THE DARK WEB (Telegram, where all crime happens on the internet apparently). ShinyHunters posted it.

Is this actual stuff from the alleged Cisco data compromise as a result of the Trivy supply chain attack? Are these images unrelated? How sensitive is this data? How is ShinyHunters involved with TeamPCP? Is this even real?

Find out on the next action packed episode of Dragon Ball Z
πŸ‘52😁19🀯15❀5πŸ‘2πŸ”₯1πŸ₯°1