vxunderground | Unsorted

Telegram-канал vxunderground - vx-underground

40629

The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/

Subscribe to a channel

vx-underground

Chat, I'm unironically a big fan of AI now

I don't vibe code, or whatever, but it's ability to generate me slop Python scripts for reverse engineering, or it's ability to help me troubleshoot Linux gunk, is absolutely incredible.

I'll say, "Hey ChatGPT, I've got this goop that is doing X, Y, Z. Can you make me a Python script that handles it?".

My Python is trash, but ChatGPT is like, "I got you, big dawg", and gives me the thingie I need in just a few seconds, saving me tons of time browsing StackOverflow or screaming at my IDE about syntax issues.

Thank you, OpenAI, for giving me ultra mega slop Python maker 9000. It is incredibly helpful to me.

Oh, and I've never had OpenAI give me any warnings and stuff about potential violations or whatever. Anthropic complained all the time. I'm not verified by OpenAI as a cybersecurity professional, ... I just ask for slop Python and it produces magic. I don't know how it works, but it's cool and badass

Читать полностью…

vx-underground

Hahahahaha. What? You can't afford a ticket to Slermie Doop??? Sounds like you're POOR. Sorry, kid. We're HACKERS. We fucking HATE poor people.

Next thing you're going to do is say you can't afford the $2,000 Schmeemee certificate, proving you're a real hacker.

Читать полностью…

vx-underground

o ok, thank god they removed it, i was afraid the knedliky police were gonna come to my house and beat me to death with knedliky

close one

Читать полностью…

vx-underground

I like writing malware because, instead of making useful and productive software, you spend an absurd amount of time writing a really over complicated and convoluted way to create a file.

A simple line or two of code becomes like 50 lines.

It's fun, I don't know why

Читать полностью…

vx-underground

> get dm
> "smelly, is this goop?" (malware)
> "i found it on x"
> links GitHub
> download
> look inside
> .net goop
> didnt strip metadata
> internally refers to itself as FunkyStar
> internally does "ProcessAlpha", "ProcessBeta", etc

Not only is this shit slop malware, the author of this malware is larping to themselves as like, some sort of military operation. My brother in Christ, I'm happy you're feeling peppy about your slop malware, but you ARE NOT writing state-sponsored malware.

Читать полностью…

vx-underground

Hello,

So uh, a long time ago I said I was giving away tickets to DEFCON for free. A lot of people have DM'd me about it.

I can't go into too much detail about. I don't want to diss anyone, or throw shade at anyone, because I myself don't even know what the fuck happened. But, we had the money for tickets to DEFCON. We had sponsorship money. We had all the goop ready to go.

However, for reasons I don't understand, certain people, or peoples, or individuals, or whatever, were unable to effectively communicate with us and we weren't able to do the stuff we needed to do to give away free tickets.

We ended up refunding the money to the sponsors who gave us money for DEFCON tickets. I don't know, bro.

We'll try again next year, I guess

Читать полностью…

vx-underground

> post photo of girl nails
> IS SHE HOT?
> ARE THEY TRANS?

why cant you people be normal for at least one post

Читать полностью…

vx-underground

Shoutout to @recogard and @eugenepage_ for the malware campaign. Your campaign has been undetected for a month, that's pretty good

Читать полностью…

vx-underground

This image is double-silly because it features the FUCKING PIECE OF SHIT COPY-MENU WINDOWS 11 WONT KILL.

IM NOT GOING TO RESTART MY COMPUTER. FUCK YOU MICROSOFT

Читать полностью…

vx-underground

Better hold those farts in buddy, the government is after you. That gas station burrito you purchased? The gas station clerk? He's in the CIA. It's Operation Ass Blast

Читать полностью…

vx-underground

SOMEONE CONTACT THE FTC IMMEDIATELY.

VX-UNDERGROUND MADE $500.

THEYRE DEFRAUDING EVERYONE FOR ASKING PEOPLE TO VOLUNTARILY DO A SURVEY

Читать полностью…

vx-underground

As many people know, there is a thing called the "Terrible Twos". It is called this because toddlers have big emotions, but are incapable of expressing their frustration or regulating their emotions. This is a more complex task their brains haven't fully formed yet.

Although it is called the "Terrible Twos", it isn't necessarily two years old, is ranges from slightly before being two years old, all the way to almost three years old.

I'm happy to share my son has had his first few tantrums. Just kidding, I'm not happy, it actually fucking sucks.

I told my son he couldn't play with his toy and he LOST HIS MIND. He was completely inconsolable. He threw himself to the floor, screaming at the top of lungs like he was being dismembered, didn't want us to hold him or touch him, refused his snacks or comfort food, bro LOST HIS MIND.

Then he slowly calmed down... and it stopped.

Dawg, toddler tantrums fucking suck ass so much omfg it's actually the worst and it's super stressful

Читать полностью…

vx-underground

Hello Little People Living Inside My Computer (LPLIMC),

Some place hit me up and asked if I'd share a survey. They're trying to understand hackers, or something, I don't know. It's a legitimate research institute from a fancy-shmancy place, it's all on something called "a research grant" (made up words), it's non-nerds trying to understand stinky nerds.

- No login required
- Doesn't log anything
- It's anonymous

There (apparently) might be questions you're uncomfortable with (I have no idea why), so they said if you're uncomfortable with any questions you can simply skip them.

If you feel like spending 15-20 minutes clicking on multiple choice thingies to help some research place understand nerds, feel free to do it. Or don't do it, whatever.

https://globalcyberstudy.limesurvey.net/115971?lang=en&newtest=Y

Читать полностью…

vx-underground

Kathy Hochul and Letitia James have the combined IQ of a fine plate of spaghetti with some freshly made meatballs.

Soon New York state will implement the SAFE for Kids Act.

Basically, you need to verify your identity to Instagram, TikTok, or any social media platform which is algorithmic (???).

They're doing this to protect children. They ARE NOT doing it to allow social media companies to aggregate your data and sell it to third parties (or worse).

You trust Instagram, TikTok, Facebook, X, SnapChat, YouTube, Reddit, LinkedIn, and Pinterest with your driver's license, right? Because to even view these websites you need to give them your driver's license. It is to protect children from algorithms.

Just give them your driver's license, bro. They said they'll delete it and they said they won't track you. Why would multi-billion dollar companies do something potentially unethical? You trust them, right? It's to protect kids, bro, you care about kids, right?

It's a well established fact parents are incapable of parenting and we must make tech companies and the government parent our children. Right?

Читать полностью…

vx-underground

The attached blog details the conclusion to his research and the self-propagation segment.

Part I and II (linked at the beginning of the attached article) detail the underlying mechanisms which some stinky nerds might appreciate. It discusses Copilot memory manipulation and AI abusing e-mail stuff.

I'm not an AI nerd, so I'm meh.

https://enklypesalt.com/posts/context-collapse-part3-ai-worming-through-word/

Читать полностью…

vx-underground

It makes me very happy receiving DMs of malware and people asking "is this goop?".

There is a real-world chance that we can fundamentally corrupt people to begin referring to malware as "goop", and making our entire industry look like a fucking joke

That's so badass omg

Читать полностью…

vx-underground

Oh yeah? You're a "hacker"? Prove it.

Show me your $600 entry ticket for Slermie Doop 16 and massive collection of cybersecurity vendor merchandise you either received for free or purchased.

You're not a real hacker until you're a walking billboard for tech companies

Читать полностью…

vx-underground

> get dm
> "someone defaced health institute for czech republic"
> look at website
> indeed they did
> they leave a telegram handle
> dm them
> say hello
> "haha check this out bro"
> adds "smelly" to website
> lists "smelly" as a "crew member"

chat, we are cooked

Читать полностью…

vx-underground

What I find so impressive though is that this malware has been active on GitHub FOR A YEAR.

Dawg, they're banning security researchers and this malware has been present FOR A YEAR

https://github.com/Alisterscaics185/Crypto-Checker-Seed-Phrases

Читать полностью…

vx-underground

I really don't want to throw shade at anyone, but it's super confusing, because we had a giant pile of cash from sponsors. We said, "Hello, we would like to use this giant pile of cash". They pretty much said, "Okay, cool, one moment" ... then kind of radio silence.

I assume DEFCON likes money, so I don't know what happened.

Читать полностью…

vx-underground

Some guy named Dulgex just made this for me and I'm so happy omg this is awesome thank you so much bro

Читать полностью…

vx-underground

Some lady at DEFCON will be sporting vx-underground UWU nails.

What does this mean? I don't know, but I thought it was cool and badass. I wanted to share it.

Читать полностью…

vx-underground

> be me
> get message from TorGuard owner
> "i found goop" (malware)
> wtf let me see goop (malware)
> sends link
> look inside
> "width-table v0.1.0"
> malicious rust crate
> imported into "Polymarket-5min-bot"
> by "crazygirl437" on GitHub
> code walks directory and uploads files to website
> "checkenv(.)cloud"
> lol its for a rust crate that sets a table width
> image 1
> neat
> hmmmm
> beep boop search
> find X posts
> malware campaign on X
> verified accounts sending link to people
> "crazygirl437/hyper-grid"
> image 2
> more verified accounts posting stuff
> lots of impressions and likes
> image 3

Chat, we've got a full-blown Threat Actor malware campaign right here on Xitter and it is active as we speak (image 4).

Although, it is primarily social engineering work. It is spam, pushed by verified X accounts, that delivers an open-source-malware information stealer.

tl;dr free goop for everyone

Читать полностью…

vx-underground

Luther Squarepants,

I don't possess the wrist-bands, h3l3n 0f t0r does. I will ask her if she is willing to mail you CIA monitoring technology to your home

This was a very strange DM, but I respect it

Читать полностью…

vx-underground

If you're at DEFCON this year, there will be vx-underground wrist bands distributed for free.

Yes, this is an ADVERTISEMENT.

Oh, and by the way, these wrist bands were created by the CIA, FBI, NSA and, IRS. They contain a tracking beacon that activates when you fart

Читать полностью…

vx-underground

I was indeed paid to post this, although not very much. I liked the core concept of what they wanted to do. I think the people behind it are chill. My monies was given to me because I have stinky nerd street cred.

This university research place which is trying to understand "hackers", or whatever, got monies from some place to study stinky nerds.

These non-nerds were like, "well, they do crime, surely hackers and stuff have a similar psychology to other criminals". They quickly learned however that cyber criminals are FAR more paranoid than regular criminals.

With regular criminals, like a drug dealer or something, you can usually approach them and try to talk. It makes it easier because you can physically see them. With cyber criminals on the other hand, it is extremely difficult to approach them because they're (usually) hyper-paranoid and (usually) have extreme anti-government and/or anti-authority beliefs.

Additionally, unlike a majority of criminals, cyber-criminals place great importance on intellectualism and meritocracy. When this university place tried to approach hackers, they were coming in as anonymous nobodies who had no merit and no background in anything technical.

As the many nerds who follow this social media profile know, people who put out work, produce work, or do SOMETHING are (usually) treated well (or better) or given respect. It is kind of like, stinky nerd street cred.

Anyway, they found vx-underground and asked for my help to push the study. They ascertained I had stinky nerd street cred and hoped I could help them. Whenever they tried on their own they were called racial slurs, told to fuck off, were ignored, or called feds (or all of these combined).

tl;dr stinky internet nerds not think like like criminals, have different philosophies on stuff

Читать полностью…

vx-underground

Oh, I'm going through it now, they're trying to understand the psychology of Threat Actors versus non-Threat Actors

Neat

Читать полностью…

vx-underground

I'm doing that thing again where I crash out over government surveillance and tech companies needing more identification under the guise of protecting children

Читать полностью…

vx-underground

Y'know, peace and love to my fellow stinky nerds, but someone really needs to sit down and explain to people what exact RCE means. The acronym Remote Code Execution implies code (the beep boop stuff) is remotely (far away) executed (ran on the computer).

Hence, beep boop stuff that is far away runs on a computer.

Historically an RCE is like, your computer is running Soup Goop server, and Soup Goop server fails to properly parse data it receives, allowing specially crafted input to trick Soup Goop server to execute code.

So, you could like, use Python 3.11 to send some dumb slop to a remote computer address and it'll execute your bad stuff.

In this instance (and many other from Steam and malicious mods in general), the idea is that someone operates or possesses a server which, and when a player joins, the video game server syncs data to the newly connected host which pushes a payload to it.

In simple language, and as a hypothetical example, I operate Stinky Minecraft server, and if you join Stinky Minecraft server, my Stinky Minecraft server automatically pushes mods to your computer. Stinky Minecraft server does this because it automatically ensures you're compatible with Stinky Minecraft server and we can all play and have fun. However, one day Stinky Minecraft server says, "you need Goop Texture Pack Mod 0.2.1.1 and ... INFORMATION STEALING MALWARE HEHEHEHEHE" and that malware is automatically pushed to your machine (also with Goop Texture Pack Mod 0.2.1.1).

Things like this doesn't really fit the category of Remote Code Execution because nothing is being executed remotely as a vulnerability, it requires a victim machine to connect to a malicious host which syncs the payload to the machine. This is closer in terminology to arbitrary code loading, malicious plugin loading, remote installation of untrusted code ... something, I don't know, but it's not an RCE.

Overall, this is more or less a fundamental flaw in the design of video game mods because they're not appropriately sandboxed.

Читать полностью…

vx-underground

Yesterday Håkon Måløy, a stinky AI security researcher, unveiled several vulnerabilities with Microsoft Copilot which could hypothetically allow an AI-like worm in Microsoft Office documents.

the tl;dr-ish is that if you insert carefully worded instructions, as white-text thus making it invisible to the user, at the end of Microsoft Office documents, Microsoft Copilot will follow the instructions given to it.

The problem with this method (as is tradition), is that the text is still visible in the document if highlighted by the user. Hence, doing something as simple as CTRL+A would render the text visible to the user.

Regardless, Håkon Måløy successfully appended white text to a Microsoft Office document that halved the values of company data presented in the document. In simple words, the appended white text manipulated company data in the Microsoft Word file.

His second proof-of-concept demonstrated appended white texting propagating the appended white text to other Microsoft Office documents, thus making it worm-like (self-propagating).

This is an interesting idea and it is an excellent proof-of-concept. However, like many AI vulnerabilities, this relies heavily on social engineering (kind of) where as text is still present in the document, and like many AI vulnerabilities, results may not be consistent depending on how the AI interprets the data.

This isn't a diss to Mr. Måløy, I think this is really interesting, unique, and creative, and could potentially have some real world abuse. Simple tricks have proven to be very effective. The nuance is important to emphasize though because non-nerds on social media seem to be under the impression this is Terminator Copilot edition.

Читать полностью…
Subscribe to a channel