40629
The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/
Two members of the infamous Scattered Spider group (a sub-group of ALPHV ransomware group) have plead guilty to the attack on TfL (Transport for London).
Thalha Jubair, 20 (image 1) and Owen Flowers, 18 (image 2).
Flowers was initially released from custody on strict conditions, which the courts note he violated on two occasions in March, 2025 and May, 2025.
According to the National Crime Agency, Mr. Jubair and Mr. Flowers initially intended to take their cases to a trial in Woolwich Crown Court. However, both individuals later switched to a guilty plea.
Both individuals are scheduled for sentencing July 16th, 2026.
While both fall under the United Kingdom's Computer Misuse Act, and is capable of delivering life in prison for both individuals, due to their young age and guilty plea, Mr. Jubair and Mr. Flowers are likely facing 10 years in prison.
Images via United Kingdom National Crime Agency, see subsequent post for more information and case details.
GTV VI leaks reportedly show the pricing for the game at $25,999
Gamers can take out a loan from Rockstar Games official banking app, or get a 2% discount if they pay in full at checkout
They have options available if you have no credit or poor credit
I know you expected a post about malware, or something, but I've been battling demons (trying to get a baby to sleep) and I've got nothing.
I did however find this video to be cute and silly, so I decided to share it
Okay, the silly shenanigans are over. I've repaired the damage done to my box. Overall this was a very whimsical Saturday.
For people new to this account:
Do I really not use a VM when doing malware analysis? Yes. I have a VM, but I don't know, I get lazy. I throw the malware in a random directory called like, "sgsdggggg" (I type random letters on the keyboard) and start poking it.
Is this the first time I've detonated malware on my computer? No. I've detonated ransomware (REvil), some suspected state-sponsored malware from the Russian government (APT28), a crypto-miner, and now this.
I also once messed up an rsync command and synced my tax documents to the staff at DEFCON. They expected malware, instead they got my birth certificate, my tax returns, and some other various documents.
Do I panic? No, I deal with malware every single day. I collect malware, reverse engineer malware, write malware, etc. It is more annoying than actually concerning. The only time I was genuinely concerned was when I detonated REvil because I usually don't make backups (I'm not a coward).
Basically, I'm a jackass who has gotten way too comfortable with malware and you should not do what I do.
I guess the only thing more embarrassing than accidentally detonating an information stealer payload on your computer, while trying to remove the .exe file extension, is reviewing the payload closer and seeing it comes with cartoon pornography (I've censored it) and an image of a random woman
Читать полностью…
shout out to salat stealer for having my banking information right now
Читать полностью…
I'm torn mentally, physically, and maybe a little bit sexually.
I hate advertisements. On the other hands, I like malware. I don't know what to do. I am forsaken.
Dawg, I don't want to sound like a hater, but some of you malware nerds NEED to lock in and TRY HARDER.
Someone found a malicious GitHub repo and DM'd it to me. It had piss poor obfuscation (if you even want to call it that, it's Base64 encoding) and the malware C2 is basically plain text.
The delivery method is masquerading as an Adobe Acrobat plugin? My Brother in Christ, WHAT ARE YOU DOING
The C2 is literally houndsregimeskid-dot-com
Hounds Regime Skid? Hounds Regimes Kid?
Also, for the record, if the people who wrote this malware are reading this: I'm not the guy spamming your Telegram C2. That is someone else. You left all of Telegram channel stuff plain text too
Just cancelled my Codex Claude Slop subscription.
I'm running my own AI thingie at home. It'll be cheaper in the long run, it just required a few hardware purchases.
Someone DMd me something they received on Discord. They thought it could potentially be malware.
It was malware.
However, it was Electron JS AI slop malware. You can tell because it was easily disassembled and the AI notes were present.
I'm so god damn tired of malware slop
One of my favorite people in the world is petikvx.
He randomly showed up one day and was like, "Bonjour, j'ai beaucoup de logiciels malveillants."
I said, "I don't speak German, pal".
Then he started giving me a bunch of malware. He is the primary person who does our bulk malware stuff. Everyday he sends me malware. I receive it, sync it with the malware place, and go on about my business.
I checked my chat logs, I haven't spoken to the guy since February, 2026. Before that it was like, July, 2025, yet EVERY SINGLE DAY he is sending me malware.
I barely know the guy. He shows up, he says, "J'aime beaucoup les logiciels malveillants. S'il vous plaît, partagez ce logiciel malveillant avec d'autres personnes.", and that's it.
I don't know his name, I don't know where he works, I don't know how old he is, I literally know almost nothing about the guy.
He doesn't even speak English that well
I fucking love this guy. He is my best friend.
Telegram nerds missed it, but some dumb fucks on X were discussing malware on Steam wallpaper engine, but no one cited the fucking source, provided images, or malware sample goopies. I looked into it, and it's legit, it's from Kaspersky. I called them mean words (I wasn't mad, I'm just passionate and at the time I was hungry).
https://securelist.com/dozens-of-malicious-wallpapers-found-on-steam-workshop/120186/
More information:
(the link is cooked, it's in Mandarin so it's really, really, really long)
https://rayblog.rising.com.cn/2026/06/%E4%BE%9B%E5%BA%94%E9%93%BE%E6%94%BB%E5%87%BB%E7%9B%AF%E4%B8%8Aai%E5%85%AC%E5%8F%B8%ef%bc%9a%E6%99%BA%E8%B0%B1ai%E8%BE%93%E5%85%A5%E6%B3%95%E5%AE%98%E7%BD%91%E4%B8%8B%E8%BD%BD%E9%93%BE%E6%8E%A5/
"smelly, vxug is legal in the usa, is it legal in my country?"
Читать полностью…
Randomly remembered when one of the developers of the IcedId botnet successfully bribed Ukrainian police to forge his death certificate to avoid being arrested
That is so unbelievably cool and badass.
The best thing about being a Dad is that now I can dress like Dad
I just purchased several pairs of cargo shorts and button up shirts I intend on tucking in.
I get so many DMs, emails, and comments on social media of people calling me a cat
It's some sort of deep state psyop by silly cat picture to make me a furry
It's not going to work. Stop calling me a cat and stop asking me to meow you goobers
"Why are you reverse engineering malware on your main PC? Why don't you use a VM? If you used a VM you wouldn't have infected yourself"
Читать полностью…
What do I do in this scenario?
1. Disconnect from internet
2. Sigh, take a huge rip off my vape
3. Blame the keyboard, not me.
4. Remove the .exe, any persistence mechanism on my machine
5. Angrily reset all my passwords
6. Refuse to use a VM in the future, I'm not a coward
> be me
> "smelly is this malware?"
> download file
> file.exe
> click to rename file
> accidentally hit enter
> detonate malware on personal pc
chat, ive accidentally detonated an information stealer on my pc. brb
Image 1. Website with uBlock Origin on
Image 2. Website with uBlock Origin off
uBlock Origin IS PREVENTING US FROM FREE MALWARE
It's Father's Day this weekend.
My wife asked what I wanted and the answer was shrimple.
I want to lay in bed and not move for 24 hours. I will only move to urinate, or defecate, or consume the fast food slop I have delivered from Uber Eats.
Let me rot in peace for 1 day.
Interesting, it was undetected virtually everywhere. It was also undetected in a sandbox because it's a bloated piece of shit and has too many dependencies.
The only AVs that detected it from static analysis was Rise and MalwareBytes
Was thinking about online age verification stuff today
It dawned on me that I've got underwear that is probably 18 years old
Yeah, I'm killing myself tonight
The United Kingdom is ran by a bunch of fucking morons. I mean that wholeheartedly. These stupid fucks think you can "ban" VPNs and think "banning" VPNs will "protect the children".
"Ban" VPNs and watch what happens next.
> be gamers
> "I DONT TRUST KERNEL MODE ANTI CHEATS!11"
> "ILL NEVER TRUST A VIDEO GAME COMPANY"
> runs anime_waifu_wallpaper.exe as admin
> steam malware stuff
> all the click bait places screaming
> malware from wallpaper engine
> don't cite original article
> from Kaspersky
Dawg, these Threat Actors targeted true degenerates. Look at this malware payload. This is seriously one of the malicious wallpapers
I haven't checked the Chinese Threat Intelligence places in awhile. I said, "Hmph, I wonder what's going on over in Mandarin city" (I don't know any cities in China, so I make up names).
I checked out Rising (瑞星), they do technical write-ups about malware hitting China, and stuff, because they're ... headquartered in China. They're a Chinese company.
Anyway:
> be me
> open rising blog
> all mandarin
> damn i wish i could read
> translate page
> supply chain attack
> wtf.jpeg?
> AutoGLM hit
> wtf.mp4?
> Chinese AI agent thingie
> made by Z ai
> (idk wtf that is)
> GitHub for AutoGLM compromised
> download link replaced with malware payload
I said, "What the fuck? You guys have premium AI slop too? You guys have nerds attacking your supply chains too?"
Wow, we have so much in common
chat, we gotta get into the malicious web browser extension games. the nerds crave anime
https://socket.dev/blog/152-chrome-live-wallpaper-extensions-hid-ad-tracking