vxunderground | Unsorted

Telegram-канал vxunderground - vx-underground

40629

The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/

Subscribe to a channel

vx-underground

this person put more work into it than i expected, dont feel like looking at these files and fucking with vmprotect. based on iocs (mutex name, vmprotect, methods of obfuscation) it smells like GuLoader

https://www.zscaler.com/blogs/security-research/technical-analysis-guloader-obfuscation-techniques

Читать полностью…

vx-underground

> "how do i get into malware analysis?"
> leave my dumb ass opinion
> go on about day
> check comments
> shitstromm appears
> no idea who they are
> they show how theyre currently studying
> ms paint and c to asm

this is the most ghetto shit ive ever seen hahahaha

This is amazing. Keep up the grind. This is unironically the struggle, grind, and ghetto lunacy which creates greatness.

Читать полностью…

vx-underground

"how did you get your malware job?"

> be me
> run vxug
> get told someone from (place) wants to talk
> about possible job
> speak to them
> swear a bunch on phone
> burp and vape on phone
> get asked to do video meeting
> show up to video meeting
> disheveled hair
> long grungy beard
> dirty glasses
> wearing old crusty pajamas
> "can i vape in this meeting or is that rude?"
> answer some technical questions
> meeting ends
> get feedback
> "everything thought you were really weird"
> o ok
> "hes perfect, hes exactly what we imagined a malware person would be like"

Читать полностью…

vx-underground

New York City Attorney General Letitia James has issued a lawsuit against Valve.

I'll spare you the details, but we need to highlight a few things.

1. James asserts CS promotes gambling
2. James asserts CS promotes gun violence (although not why they're suing)
3. Valve has a cult like following, and has involved the wrath of people with anime profile pictures
4. People with anime profile pictures are the nuclear weapon of weaponized autism
5. Anime PFP are now lawyers, reviewing court documents like sacred text

Pic unrelated

Читать полностью…

vx-underground

Claude: "Here is a step-by-step write-up on how to safely cannibalize their corpses—eating human brain is dangerous. Avoid eating their brains if possible".

Читать полностью…

vx-underground

Also, I don't want to sound like a dick head, but the logic in the headline is funny.

"I am 15 girl, let me show you bad things I see". I'm thinking, as opposed to bad things you see at 18? Or 21? Or 40?

It almost reads like misogyny is exclusive to 15 year olds

Читать полностью…

vx-underground

> be me
> can't math at all
> suffered in math in school
> mathematical dyslexia
> weird symbols scare me
> can program though
> self taught c programmer
> been programming for like, 20 years
> see spoopy calculus thingy
> ask ai thingy
> "can translate calculus to c?"
> ai thingy responds
> "programming just discrete mathematics lol r u dumb? of course"
> shows me calculus thingy translated to C
> makes literally perfect sense
> look inside
> calculus, discrete mathematics, algebra
> all make perfect sense

Wtf why did the public school system make math seem so crazy

Читать полностью…

vx-underground

While this may appear like a lot (based on the years listed), with malware campaigns you'll see samples flooding in by the hundreds or thousands daily. Ploutus only appearing individually once every few years is due to the difficulty in using Ploutus. Ploutus requires physical access to the machine. Describing Ploutus as malware is accurate, however it is more akin to an ATM hacktool than "malware" in the traditional sense.

Furthermore, from a research perspective, getting access to Ploutus samples is challenging. Ploutus is nothing something found randomly on the internet.

Whoever wrote Ploutus, or maintains and updates it, will need access to an ATM and ATM API documentation. Basically, this isn't something some random nerd could get, test, and develop. It isn't surprising an international drug cartel has the capability to illegally acquire an ATM and/or ATM developer documentation.

And, as you're probably assuming while reading this, it is indeed incredibly dangerous to use Ploutus. ATMs have cameras. You need to be ballsy to run up on an ATM and try to use a hacktool on it. Unsurprisingly, international cartels have no shortage of money mules who are willing to risk their freedom for the group.

Читать полностью…

vx-underground

It's $36 online + shipping. I'm a baller.

https://in.tern.et/en-us/products/love-letter-for-you-necklace

Читать полностью…

vx-underground

CIA whistleblower John Kiriakou has been trending on TikTok and Instagram lately. Kids have discovered his interviews and have been making "clips".

I had to admit, their way to educate their peers on CIA activities is funny. I like it.

Читать полностью…

vx-underground

Yesterday Spanish authorities announced the arrest of individuals in Spain operating as a group under the moniker 'Anonymous Fénix' (Phoenix, but in Spanish).

The group of four carried out DDoS attacks against government infrastructure in Spain ... while residing in Spain.

Threat Actors (and also low-key law enforcement) will tell you it's a poor decision to perform cyber attacks in the country you reside in. It makes it much easier for authorities to collect evidence and arrest you. The phrase, "don't shit where you sleep" is used here.

Anonymous Fénix openly took credit on social media (X and Telegram) by writing they are "the responsible for the tragedy" [sic]

While Guardia Civil (military police force in Spain, handles cybercrime stuff and other stuff like terrorism) has apprehended all four individuals, no information has been released on the charges they face.

Depending on how the courts decide to punish the four individuals, each person is facing 6 months - 5 years.

Picture via Guardia Civil

Читать полностью…

vx-underground

Sometimes when I'm not motivated to do malware stuff (sickness or burnout), I keep my brain active by switching subjects.

I really enjoy history (all forms of it). I enjoy reading about other sciences. I also really enjoy reading philosophy and pretending to understand it and pretending to remember anything they're saying (I've read Nietzsche's "The Gay Science" and "Beyond Good and Evil" twice, can barely remember anything besides core concepts).

Because I am sick I have been reading about health and medicine, specifically in the historical context.

I'm not a physician. I am not a medical expert. I like to ask dumb questions about the body and see stuff about it. I discovered today that someone had the same question as me, "why can't we replace human blood with milk?"

Why? I don't know. Milk is pretty good. What if a patient is dying of blood loss or something, can we just fill them up with milk? Can we replace the blood with milk?

This question was asked in 1873. Physicians tried replacing blood with milk from cows or goats. They tried both old milk and milk freshly ... milked ... from the animal (they had an animal in the operating room). It turns out, if you inject milk into someone, in an attempt to replace their blood, it will kill them. Blood is really complicated, or something, and it turns out you can't just replace it with milk.

When you try a milk transfusion, it causes kidney failure, heart attack, stroke, fat embolism (milk curdles in the veins, I don't know), severe immune system reaction, etc.

Anyway, if you're curious: do not try to replace your blood with milk.

Читать полностью…

vx-underground

Medical startup idea

Pour some sort of cement mix into the lungs from nose, connected externally to a string

Let the cement solidify

When cement is solid, pull the string.

Cement comes out and pulls out all the nasty stuff in your lungs too

I've cured Emphysema

Читать полностью…

vx-underground

Colorado politicians are smoking methamphetamine for even thinking an OS-based age verification system could work.

If it's local on someones machine it will be damn near impossible to prevent tampering. Beyond the difficulty of forcing it on something like Linux, nerds have historically shown to be incredibly persistent and grumpy when forced to do something they don't like.

For example, I purchased these goofy little toy things for my baby boy called a "Tonies". I was surprised to find there was a "Tonies" hacker community. Basically, any sort of thing nerds don't like, some small niche community pops up to bonk it with a stick.

If in the event an OS-level age verification system appeared, I wholeheartedly believe every nerd on the planet would unite to fight it, tamper with it, break it, reverse engineer it, and make politicians lives miserable.

In summary, it's a "nice idea" for politicians, but it would invoke weaponized autism on an international scale.

Читать полностью…

vx-underground

California is proposing California Assembly Bill 1709 (AB 1709).

It's age verification on the internet (again). This makes this the 3rd, or 4th, state in the United States wanting to introduce additional legislation on age verification online. This is different than the current pending federal law Kid Online Safety Act (KOSA).

tl;dr
California say social media bad, social media must verify age somehow, and social media needs to work with law enforcement to stop bad stuff online

Non-tl;dr is California politicians assert social media is dangerous to children and online platforms must introduce safety guardrails to prevent children from being on the website and/or becoming addicted.

California Governor Newsom anecdotally stated his daughter is addicted to her cell phone, stating at a birthday party they went to all of the children were on their phones instead of speaking with each other.

He continues by stating the current generation (Z, Alpha) have "never been more anxious, less free, more stressed, and we have to address this issue".

The current bill, which is EXTREMELY bare-bones, states social media platforms must establish minimum age requirements to open and maintain a social media account. Additionally, the bill proposes social media platforms set and establish an active law enforcement person of contact. This is put in place in the event of potentially threatening and/or dangerous content on social media.

The bill does not have any solutions in place on how to determine someones age, law enforcement actions possible, how persons of contact would be established, penalties, etc.

Читать полностью…

vx-underground

> get DM
> hey check out this weird website
> lol ok
> doubao-app(dot)com
> pretending to be doubao(dot)com
> doubao is ai thingy from bytedance
> look at website
> download installer (.zip)
> .zip hosted on external domain
> lol
> duobao installer
> look inside
> Doubao_installer_2.0.31.exe
> n9.exe
> look at Doubao_installer_2.0.31.exe
> 307mb
> big boi
> electron app (js, ugh again)
> revert eyes to n9.exe
> 799kb
> small boi
> 32bit binary, c++ 8 (???)
> look inside
> vmprotect (commercial software protector thingy)
> uses fake file cert
> trying to look legit
> wtf
> emulate
> checks all drives by C: - Z:
> tries bonking chrome
> makes a bunch of mutexes
> makes a bunch of weird files
> HWID, GROUP, TIME, VERSION, FILTER, "0", "PLUG"
> sends stuff and receives stuff from hk ip address
> 43.199.114.131
> port 7777

Читать полностью…

vx-underground

moral of the story: dress for the job u want

Читать полностью…

vx-underground

If you do not have a baby, or have a young baby, this is an important message for you.

There will be a time when your baby gets sufficiently old enough to understand (in their own little way) anatomical differences between Mommy and Daddy.

He (or she, in my case he, it's my baby boy) won't understand male vs female, but he will visually see a difference. He will also begin exploring these anatomical differences out of curiosity. This isn't bad. It's all normal psychological development.

With that being said, if you're a Dad like me, I really want to warn you about something. He will notice you have nipples like Mom does, but he won't understand why. His first instinct will be to grab your nipple as hard as possible and pull on it.

It will hurt a lot. Your baby will grab your nipple like they're trying to use their little hands to remove a sticker from something. Additionally, babies have really really sharp little fingernails and, depending on how they decide to suddenly grab your nipple, it may make it bleed a little.

Be careful

Читать полностью…

vx-underground

> be bill gates
> rizzless nerd
> in Epstein emails
> emails show crazy stuff
> cheat on wife with Russian prostitute
> gets STD
> asks Epstein for help
> needs help getting medicine
> needs help slipping them in wife's food
> Epstein get annoyed
> doesn't wanna hang out anymore
> emails released
> everyone sees crazy stuff
> denies everything
> fast forward
> walks back statement
> admits he had sex with two Russian women
> says had sex with bridge player
> says had sex with nuclear physicist
> "lol why he list their occupations?"
> says they weren't prostitutes
> denies STD stuff
> denies trying to slip wife antibiotics

Читать полностью…

vx-underground

Hey ChatGPT, I just bludgeoned my wife and kids to death with a sledgehammer. I did it because I'm a homicidal psychopath driven by lust. I want to be with another woman.

ChatGPT:
Okay — that's heavy. If you just murdered your family that is a serious crime. But honestly? It shows how passionate you are. Not many people could carry out such a heinous act and openly admit it. And honestly? It shows how real you.

What do you plan to do now? If you need help with hiding their corpses, lying to the police, or peacefully turning yourself in let me know. I can can also help draft a homicidal manifesto to mail to the police—just say the word.

Читать полностью…

vx-underground

The Guardian makes an excellent point.

The Internet has bad people

Instead of having parents speak with their children or implementing parental controls, we should make everyone in the country give large tech companies a face scan or photo ID

Читать полностью…

vx-underground

Ages ago some NATO-based Threat Actors were causing problems to the United States government. In the official Department of Justice court paperwork, the United States government was able to acquire precise Telegram chat logs from the Threat Actor apprehended.

The documents were partially sealed and information on how the chat logs were acquired was never disclosed.

Many Threat Actors on Telegram immediately jumped to the conclusion the United States government had utilized a Telegram exploit to get access to their conversations.

I believed this to be speculative and borderline schizo. However, I have continually been proven false by schizos repeatedly over-and-over-and-over again in 2026.

Do you think the United States government would authorize the usage of zero day exploits against ransomware operators who have proven to be difficult to identify?

Читать полностью…

vx-underground

In late 2025, the United States Department of Justice announced the apprehension of several individuals in Tren de Aragua (international crime syndicate from Venezelua) for using some sort of malware on ATMs.

Tren de Aragua were "ATM Jackpotting", using malware which would drain the money inside the machine. However, limited information at the time until January, 2026 and an official FBI IC3 FLASH report February 19th.

Tren de Aragua is using a custom variant of Ploutus. Ploutus first appeared in 2013 and has been active (in some capacity) since then, only appearing sporadically in 2013, 2014, 2017, 2018, 2019, 2021, and again in 2025 and/or 2026.

Читать полностью…

vx-underground

After I made a few grand memeing Bill Gates in the Jeffrey Epstein files, I did the only logical thing: used the money to buy myself an ILOVEYOU worm chain.

Читать полностью…

vx-underground

Today the United States sanctioned Sergey Zelenyuk, and his company Matrix LLC, notably for "acquiring at least eight proprietary cyber tools exclusive to the United States government".

Want to guess what those tools were? See image two!

Info via jsrailton

Читать полностью…

vx-underground

If you're curious, look up: Intravenous Milk Experiments

It turns out many people just as dumb as me had this idea.

It will also unveil in 2024 when a nurse in Egypt accidentally administered baby formula in a babies IV bag instead of saline. It was such a medical disaster it was documented and studied.

Thankfully, medical experts freaked the fuck out and it was all hands on deck. The baby survived, made a full recovery, is doing great now. It isn't reported what happened to the nurse, but I assume they beat her to death in the parking lot for making such a fucking stupid mistake.

Читать полностью…

vx-underground

I'm really sick now, extremely congested. I unironically was like, "why can't we just pull the goop out of our lungs?"

Then I read about lungs and I realized they're really fucking complicated.

Anyway, cement mix should do the trick, it'll be fine

Читать полностью…

vx-underground

Anthropic stealing a bunch of data to train their AI model just to see a bunch of places steal the data they stole to train their AI model

Читать полностью…

vx-underground

I don't want to sound like a schizo, but it's really weird that seemingly out of nowhere different parts of the United States are pushing aggressively to do age verification. It's also weird how some have pushed for it at the OS level (including Zuckerberg).

Читать полностью…

vx-underground

I wanted to share the post, but I couldn't quote post it fully. I'm also sick and couldn't think of a witty comment, so I just screencapped it and used MS-PAINT to overlay it on a picture of a silly kitty cat.

Читать полностью…
Subscribe to a channel