The largest collection of malware source, samples, and papers on the internet. Password: infected Website: https://www.vx-underground.org/ vx-underground Telegram chatroom link: https://t.me/+njfLzUrqos01ZWNh
A long time, when a VXUG member was an adolescent, their relatives told them to never download untrustworthy .exe's.
When using Limewire, they encountered song.mp3.exe.
They became excited and thought it was both a song and a program from the music artist.
It was malware.
You can watch us (and the guests) absolutely make a mess out of trivia here: https://www.twitch.tv/vxunderground_live
Читать полностью…We went from the Chewbacca Defense to the Autism Defense
Читать полностью…Hello, how are you? Hope your week has been good. We have another large update. Paper additions will be coming this week. Until then please download more malware.
Downloadable collections:
- Virussign.2024.03.06
- Virussign.2024.03.07
- Virussign.2024.03.08
- Virussign.2024.03.09
- Virussign.2024.03.10
- Virussign.2024.03.11
- Virussign.2024.03.12
- Virussign.2024.03.13
- Virussign.2024.03.14
- InTheWild.0114
VXDB updates:
- All samples synced and up-to-date
- 96,000 samples synced
About to make the entire vx-underground website rainbow colors and watch these weirdos go into a black out rage
Читать полностью…Amazon began rolling out beta AI assistant "Rufus" to selected users in February, 2024. Nerds have begun receiving this beta.
As is tradition, these nerds have begun finding ways to weaponize, exploit, or abuse, this AI assistant.
Looking at you, HackingLZ 😭
tl;dr modify shell open command (default) to malicious payload with subsequent invocation of text editor + parameters. The .txt file won't be malicious, but the thing responsible for opening them will be
¯\_(ツ)_/¯
Hello,
If you like vx-underground please consider donating. Every dollar helps us and allows us to do cool stuff like archive more malware, archive more stuff from pacer, and do giveaways.
Thank you. I love you.
Become a monthly donor here: https://donorbox.org/vxug-monthly
Why are these dorks selling stuff off vx-underground? Also, those are builders, not the source code. The source code is on GitHub
Читать полностью…Let's address the elephant in the room.
If a ransomware group resided in the United States, publicly swore allegiance to the United States and all allies of the United States, and only deployed ransomware to Russia — would Law Enforcement or Cyber Threat Intelligence care?
We are postponing vx-underground trivia night to March 15th, 2024. Helen got COVID19 😭
Читать полностью…In the entire document Lockbit is noted 7 times, Conti is listed 4 times, ALPHV is never mentioned. There references to Lockbit are often looked over as a note, not really described in detail. They're seen as 'encryption programs'.
Читать полностью…Russia-based Cyber Threat Intelligence firms have an APT name designated for the United States government: Sand Eagle
Читать полностью…Trivia night is live.
Hosted by the wonderful lauriewired
Sponsored by Malcoreio
https://www.twitch.tv/vxunderground_live
Tonight is vx-underground Trivia night at 9PM EST! Hosted by Laurie Wired, and Helen of Tor
Special guests include: Ali from Hak5, TracketPacer, and 0xTib3rius (as the evil Team Rocket)
Sponsored by Malcoreio – last place wins a crusty sock worn by Smelly:(
Diogos Santos Coelho, the administrator of RaidForums, is pleading with the UK government to not be extradited to the United States. He states he is vulnerable, has autism, and was groomed as a child to run RaidForums
https://www.theguardian.com/law/2024/mar/15/diogo-santos-coelho-pleads-uk-block-us-extradition-cybercrime-raidforums
Moments ago the United States House approved the ban of TikTok. The vote will now go to the United States Senate for approval. President Joe Biden has stated if it passes the Senate he will authorize it.
The ban is for ... national security, or children safety, or something
tl;dr chinese app bad, ban anything we don't like under the 'guise of children or national security. This sets a terrible precedent
We still have dorks messaging us, foaming out the mouth, asking why we're promoting the LGBTQ agenda
The vx-uwu design was created as a touch-in-cheek reference to anime and classic internet meme nyan cat.
Degenerates are treating rainbows and cuteness like gang affiliations😭
Hello, how are you?
Apologies for the delays. We've been knee deep in lame stuff — real-world responsibilities, or something. Anyway, we've got a bunch of nerd news to share, list of content additions, things we need to upload to the VXDB and more.
Full list of additions below...
Family Updates:
- AveMaria
- Azorult
- BlackwoodLoader
- CherryLoader
- Grandoreiro
- IcedId
- KasseikaRansomware
- KrustyLoader
- MortisLocker
- QakBot
- SmokeLoader
- SubtlePaws
- VileLoader
- WikiLoader
- YoungLotus
Collection Updates:
- Virussign.2024.03.06
- Virussign.2024.03.07
- Virussign.2024.03.08
- Virussign.2024.03.09
- Virussign.2024.03.10
- Virussign.2024.03.11
- Virussign.2024.03.12
Malware Analysis Papers:
- 119 new papers added for 2024
- 17 new papers added for 2023
- 16 new papers added for 2022
- 6 new papers added for 2021
- 6 new papers added for 2020
- 14 new papers added for years 2011 - 2019
VXDB notes:
- VirusSign and VirusShare recent additions have NOT been synced with VXDB
- Approx. sync date is 2024-03-16
Thank you for waiting, sometimes it is difficult running the largest open-source malware repository on the internet.
More to come soon. I love you.
"Can a .txt file be malicious?"
Short answer: No
Long answer: Anything is possible through the power of Windows HKEY_CLASSES_ROOT
No updates again this Sunday.
I love you so much, omg
Our opinion: probably not. However, they would 100% care about the money laundering and/or tax evasion. The United States IRS doesn't mess around. They WILL get their money one way or another.
Читать полностью…Today it was announced Akira Toriyama, the creator of Dragon Ball, passed away. Today will act as an international day of mourning for all Dragon Ball nerds for all memories and memes Mr. Toriyama brought us.
More information: https://en.dragon-ball-official.com/news/01_2499.html
"The ransomware is always encryption software on the other side", - Vladimir Vladimirovich Putin, probably
Читать полностью…Russia-based Cyber Threat Intelligence firms do not list Lockbit or Babuk ransomware group as financially motivated or state-sponsored Threat Actors - they're tools. See attached image #3 for list of known ransomware groups 🤔🤔🤔🤔
Читать полностью…We continue to receive hateful remarks from individuals because of the vx-uwu logo - most notably we are called 'trannies' and are told to 'kys'.
Dorks terrified of vx-uwu colors and anime