vx-underground
51.7K subscribers
4.54K photos
495 videos
84 files
1.57K links
The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Download Telegram
Instagram still hasn't (correctly) patched their AI goop account reset thingy. Accounts are still being stolen and Instagram hasn't said anything about it. Nerds continue to find ways to convince AI to reset accounts for them.

People on social media are freaking out because some of these profiles apparently are big sources of revenue for them.

Meanwhile, rumors are floating around that a few weeks ago Instagram laid off a large percentage of their Trust & Safety department and had it replaced with AI.

Very cool
🀣147❀8😁8πŸ‘5πŸ₯°4πŸ€“4πŸŽ‰1
This is a very silly photo.

WeezerOSINT shared a photo of someone speaking with Instagram Trust & Safety. They told him what he is describing is "impossible" and denied the existence of the AI bug thing

"It doesn't exist, nerd. AI is never wrong" - Zuckerberg, probably
🀣167❀14πŸ€“9😁4πŸ₯°2πŸŽ‰2
I have something to share, but it would be such an absurdly long write-up I'm not sure if it's even worth it.

tl;dr FOIA (Freedom of Information Act) request on the SolarWinds compromise. Government sharing details on SolarWinds compromise and impact
❀76πŸ‘16πŸ”₯9🀣8😘5😎3🀯2πŸ₯°1😱1😒1
vx-underground
I have something to share, but it would be such an absurdly long write-up I'm not sure if it's even worth it. tl;dr FOIA (Freedom of Information Act) request on the SolarWinds compromise. Government sharing details on SolarWinds compromise and impact
Hello, I'm sorry to the people I kept hanging. I'm dealing with my baby right now.

I'll be doing a little write-up later today and sharing it on vx-underground if you want to read it yourself.

In summary, the FOIA request discusses a high level summary of SolarWinds malware payload and a few government employees who were targeted provide some information on stuff. It also unveils some cool and badass secret government code names.

I did not place the FOIA request. Although FOIA requests can be made public, for reasons I don't understand the person who initially placed it didn't make it explicitly public (unless I missed something, somewhere).

It was fun reading it. Moving forward I may archive FOIA stuff related to cybersecurity.

I've been really behind on many things. Working from home and having a 14 month is challenging. I am hoping when he starts school in a few years I will have more free time (around 2030?).
🀣52❀25❀‍πŸ”₯7πŸ₯°2πŸŽ‰2πŸ‘1
As someone who enjoys malware and malware accessories, I for one believe this to be incredible news and I applaud Satya Nadella for this

As someone who deals with malware defensively, I for one believe this is terrible news and I hate Satya Nadella so much right now it's unreal
🀣145πŸ‘16😁15❀3πŸŽ‰3πŸ₯°2🀩2πŸ”₯1😒1
vx-underground
As someone who enjoys malware and malware accessories, I for one believe this to be incredible news and I applaud Satya Nadella for this As someone who deals with malware defensively, I for one believe this is terrible news and I hate Satya Nadella so much…
It's funny. Last night I was going pee-pee and I had an idea for a schizo post that would be written something like, "Just got off the phone with the CEO of malware (Satya Nadella). He said don't even trip, dawg, we've got tons of new features coming to the Windows ecosystem so you and your group of nerds can continue to discover new things to abuse".

The idea then was posting it with a picture of a cat on a cell phone.

I didn't post it because I was like, "Nah, Microsoft is having a bunch of problems right now, no way Satya Nadella gives the approval to add more gumpie to their slermie frumpy machines".

I was wrong. He has plenty of gumpies for the slermies.
🀣97❀6😁4🀩4πŸ₯°2😒1
After seven years of discussing malware, collecting malware, archiving malware, writing malware, reversing malware, reading about malware, and searching for malware, ... my brain is deep fried like some gump.

When I made this website and social media profile, I was initially very formal, I used dark-art, I tried to be all professional.

Fast forward seven years and I'm writing incomprehensible nonsense and spamming pictures of cats. I'm unironically thinking things like, "Microsoft confirmed their glumpies got slermied. The goop detonated on the frumpest was written by Russian gwumpnessicas".

I have no idea what this website is doing to my brain, bro. My mind is slowly imploding.
🀯92πŸ₯°37❀‍πŸ”₯17❀13😁12🀣7πŸŽ‰4πŸ™4😘4😱3πŸ€“3
Yeah, so pretty much this guy is releasing an exploit in solidarity with Nightmare Eclipse guy. He said he notified GitHub about the exploit 60 minutes before releasing this paper.

I don't do web stuff, and I'm not a VSCode nerd, so I'm confused by the underlying technologies.

If you're a stinky GitHub and VSCode nerd maybe you'll understand.

tl;dr click github dev, github dev opens editor, in github dev editor have javascript, javascript does shortcuts automatically. github treats javascript shortcuts as real human input, or something. use javascript shortcut stuff to automatically install vscode extension. the vscode extension steals your data

tl;dr tl;dr user clicks 1 link, 1 click steals all data from your github

https://blog.ammaraskar.com/github-token-stealing/
😱57❀25πŸ”₯12🀣7🫑7🀯4😒1
I was sniffing around trying to learn more about this FOIA (Freedom of Information Act) gumpy I found on the internet.

*I didn't find it, someone else found it and sent it to me

It's from Bloomberg and (currently) behind a paywall as part of their "FOIA News", or whatever silly name they're calling it to make it interesting.

> lists victims (but redacted)
> interviews witnesses
> big shenanigans
> solarwinds was precise in what doing
> nicknamed "Lazy Fortnite" by government (???)
> victim 1 is v v v important

https://assets.bwbx.io/documents/users/iqjWHBFdfxIU/ry9xLM9wJMxA/v0
πŸ‘26😱12❀8😒2πŸ€“2😎1
This media is not supported in your browser
VIEW IN TELEGRAM
Pretty slow couple of days in cybersecurity, only 15 companies hit by ransomware, only 18,000,000 malwares noted in the wild, only three or four North Korean and Russian cyber operations discussed, and only two new Microsoft 0days
😁104πŸ₯°26❀9😒3πŸ”₯2
Malware
❀113πŸ₯°37😁27🀣15😱6❀‍πŸ”₯4😒1πŸ’―1
Microsoft introduces Microsoft Scout, also known as Autopilot.

Scout is always on and has file system and application access "based on your corporate policy".

Best news for Threat Actors in a long time

https://www.microsoft.com/en-us/microsoft-365/blog/2026/06/02/introducing-microsoft-scout-your-always-on-personal-agent/
🀣112❀‍πŸ”₯14πŸ₯°7❀6😁4πŸ‘2😒1
vx-underground
Microsoft introduces Microsoft Scout, also known as Autopilot. Scout is always on and has file system and application access "based on your corporate policy". Best news for Threat Actors in a long time https://www.microsoft.com/en-us/microsoft-365/blog…
This thing can have full access to your file system and is always on.

I can't imagine a better thing to abuse on Windows. Imagine all the cool malware and system components we can abuse, oh my lord
❀81😁41😎11πŸ‘7πŸ‘3πŸ₯°2πŸ”₯1πŸŽ‰1
The people crave malware and malware accessories
❀74πŸ”₯23πŸ‘4πŸ‘1πŸ₯°1😒1
> see someone discussing position independent code
> "no need to walk peb"
> look inside
> invokes VirtualQuery
> ???
🀯53❀17🀣12😱2😒1
My goofy ass website gets 142,000+- unique visitors a month. Dawg, I have GOT to find a way to monetize this without dropping to my knees and begging like a dirty scoundrel on the internet.

I've worked on this gunkie slermie everyday for 7 years. I gotta do something
❀124πŸ‘22🫑15πŸ₯°8πŸ’―6🀩2😒1
vx-underground
My goofy ass website gets 142,000+- unique visitors a month. Dawg, I have GOT to find a way to monetize this without dropping to my knees and begging like a dirty scoundrel on the internet. I've worked on this gunkie slermie everyday for 7 years. I gotta…
Ah ha! I've got an idea! I cover every inch of the website with big dick pill advertisements.
πŸ”₯239🀣86❀32πŸ’―15😎8πŸ‘6😱6πŸ₯°4❀‍πŸ”₯3🀯2🀩2
I've got a backstreet boys song stuck in my head I haven't heard since 1999
πŸ₯°98❀‍πŸ”₯21🀣16❀11πŸ”₯8😒8😱2πŸ‘1😁1
Meta is still having some minor security problems. Instagram is currently exposing phone numbers and email addresses associated with accounts when trying to perform a password reset

This is cool and badass because everyone is sharing Mark Zuckerbergs phone number right now
🀣174πŸ₯°19😁15🫑7❀4🀯1πŸŽ‰1