40629
The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/
Virgin $500 AI Toothbrush vs Chad $1 Toothbrush
Читать полностью…
Dyson unveiled their "CameraJet" toothbrush.
It is a toothbrush with "AI" (???) which has a bunch of cameras on it. These cameras monitor your brushing habits and livestream the inside of your mouth to the Dyson app on your phone, basically allowing you to perform an endoscopy on yourself.
Dyson claims the AI within the toothbrush was developed using 16,000,000 lines of code and also them performing AI analysis on 470,000 dental images they've collected over the past 6 years. In other words, Dyson somehow collects about 213+- dental records a day (???).
Dyson claims the AI on the toothbrush isn't stored on the cloud, and it only livestreams to you. This is probably true. However, when you purchasing the toothbrush you must register with Dyson (from their website, or the Dyson app on your cellphone).
Here is what Dyson CameraJet does collect:
- Full name
- E-mail address
- Country, region
- Dyson product
- WiFi information
- Bluetooth (local-network access, device discovery)
- Location permissions (GPS)
- Home and Device information
Dyson, based off of their own privacy policy, collects your GPS location and correlates it with local outdoor air-quality and weather. It may also use this in conjunction with local-network access device discovery to enumerate potential air purifiers, fans, or robotic cleaners. Furthermore, the Dyson app requests labeling where your Dyson CameraJet is located in the house (Master Bathroom, Basement Bathroom, etc).
... why?
> be me
> get dm
> "smelly, i found goop"
> wtf i love goop (malware)
> sends url
> needs to be CURL'd
> try to CURL
> delivers picture of penis
> ???
> try again
> IP address banned
> try from different IP
> penis again
> banned again
> try third time
> more penis, more ban
Dawg, they got Pete Hegseth in the data breach. It's available for sale for $100
Читать полностью…
I really recommending reading this.
In summary, a company which does ID verification for in-person interactions (hotels, car rentals, ID verification for alcohol or marijuana, etc) has some how exposed over 153,000,000 drivers licenses for people in the United States and Canada.
It is a catastrophic data breach, probably one of the worse I've ever seen. If you're in the United States and have traveled, gotten a hotel, purchased marijuana or alcohol, there is a high probability you're in this.
Unlike other breaches, this includes a photo of the person (from the license), making verification you've identified the person significantly easier.
This poses a significant threat to celebrities (musicians, YouTubers, streamers, adult entertainers, actors, etc), politicians, lawyers, wealthy people (CEOs, investors, people of public interest), Law Enforcement Officers, etc
Krebs himself, and several other security researchers, have already confirmed they're in the data leak.
tl;dr gah damn dawg this company is going to be sued into oblivion
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
I've been cookin' dawg, I'm on that 2025-2026 making power moves type shit.
I started off in August, 2025 at 280lbs (127kg). September, 2026 I'm at 215lbs (97.5kg).
However, for reasons I don't understand, when I don't eat for long stretches of time, I get an absolutely insatiable appetite for sugar, basically raw sugar almost. I also get kind of groggy, forget stuff, and chug water, like an absolutely insane thirst.
Anyway, I had a giant bowl of Vanilla Ice Cream drenched (basically filling the bowl) with Maple Syrup and then covering it in Chocolate Syrup.
I now feel much better, I'm no longer thirsty, and head isn't groggy.
I don't understand why my body does this.
Well, the malware campaign is dead, I learned a lot along the way, it was fun (I was suffering).
Back on the hunt for goop (people just send it to me)
Get a load of this guy, the meta data is present in his Java payload and he labels it internally as *checks notes*
"There is no God"
???
> be me
> get dm
> "smelly i found goop"
> "its a fake pokemon thing"
I don't even have to fucking look at it, I know IMMEDIATELY what this is. I FUCKING HATE NODEJS AND JAVA GOOP. I FUCKING HATE IT SO MUCH
Opening social media to see some dork reverse engineering using Claude and Claude missing a bunch of important goop because the person using Claude doesn't actually know anything about malware or reverse engineering and their post is all slop
Читать полностью…
> be me
> get dm
> "smelly i found goop"
> wtf i love goop (malware)
> fake cloudflare download page
> tries to convince roblox nerds its robux
> haha_classic.gif
> look inside
> downloads powershell script
> curl file
> redirects, fails a bunch
> curl file again, but ask to not redirect
> goop download successful
> goop strategy so far is lots of staging
> .ps1 -> .exe -> .exe downloads more .exe
> ok
> curl next .exe
> fails, redirects again
> omfg bro
> curl file again, but ask to not redirect
> works
> look inside
> .exe with manually written COM for custom .NET
> tl;dr manual .NET loader
> whoa neato
> bonk with stick
> manually strip out .net code from .exe
> goop strategy thus far
> .ps1 -> .exe -> .exe -> .exe custom load csharp .exe
> look inside
> heavily obfuscated c# .exe
> evades emulation
> hehe silly goop
> decompile with ILSPY
> follow code execution manually
> checks system environment (fingerprinting)
> checks to see if .exe is in russia (lmfao)
> kills itself if its russian IP address (lmfao)
> checks gpu, cpu, ram, etc
> connects to spoopy IP address (tries to be sneaky)
> 158.94.208.92:61120
> tells 158.94.208.92:61120 what kind of PC its on
> 158.94.208.92:61120 asks what files are on PC
> gives 158.94.208.92:61120 file listing of PC
> csharp .exe waits for 158.94.208.92:61120
> 158.94.208.92:61120 may deliver more goop later
haha silly goop, this is v v silly
stage 1: cloudenterprisenew(.)com
stage 2: 8758aa166281eca53eecf11d167bf069ac3c3c07490b16f2efa687fd514081e8
stage 3: 1e0a8824261e3edb36d12fd5ce659cbb3989d4470809d2310cc56cd47da53555
stage 4: 6c14ea6f34a3a8f6a5eaa576e95c191326a2c4d58f9c19a0faf8ad139970a713
Stage 2 and Stage 4 weren't on VT
pic unrelated
> be me
> outside
> hehe sun feel good
> weird thingie on tree
> looks like fuzzy frog
> wtf frogs are cool
> approach fuzzy frog
> fuzzy frog flies off tree
> bites me
> scream
> "ah wtf, you fucking bitch"
> slap fuzzy frog hard af
> fuzzy frog on ground twitching
> finger has two tiny marks
> bleeding a little
> look down at fuzzy frog
> not fuzzy frog
> bat
Governments are funny and make funny goop
https://www.levelblue.com/blogs/spiderlabs-blog/still-circling-blind-eagles-toolkit-keeps-evolving
NEVER FEAR, NEVER HEAR, NEVER HOPE, NEVER TALK, NEVER EVER HAVING A THING, NEVER FEEL, NEVER WILL, I NEVER CRY, I NEVER DIE, I WON'T DIE MISSING YOU
https://www.youtube.com/watch?v=uJYI2hnc2SA
For more details and the full court ruling you can read it here:
https://media.ca7.uscourts.gov/cgi-bin/OpinionsWeb/processWebInputExternal.pl?Submit=Display&Path=Y2026/D08-25/C:25-1354:J:Lee:aut:T:fnOp:N:3597567:S:0
Oh, I see, it's because Dyson sells air-purifiers and stuff, so this is all rolled together from the Dyson app. Nothing from the thingie announced today gives much information on what the "CameraJet" collects except "Coverage Maps" (places your clean and don't) and floss habits.
Читать полностью…
My malware setup at home is beginning to become absurd. Like, it's actually ridiculous.
Right now I've got some goofy cheapo desk, and three monitors on it. However, I need to get a longer desk which supports more monitors, an additional computer for a storage server for my goop collection, and (ideally) another machine for a local malware analysis sandbox for emulation.
It is ridiculous bro, what am I even doing anymore with all this goop
The company which leaked data is IDScan. IDScan does not list all of their customers, however some are publicly known. If you have ever used these companies (and provided an ID) your data has been leaked:
- Shell
- AMC Theaters
- DraftKings
- Dutchie
- FedEx
- Hertz
- Chevrolet (General Motors)
- GameStop
- Jack Henry
- MRI (Checkpoint ID)
- Polaris
- Simmons Bank
- LendingUSA
- Circa Resort & Casino
- Planet 13
- Rouses Market
- US Coast Guard Academy
- Caesars Entertainment
- Motorola
Can't trust online ID verification, now you can't trust in-person ID verification.
Fucking hell man
tl;dr not eating for so long, blood sugar getting low (probably) and body demanding calorie dense material + sugar to correct itself
Anyway, now we go back to your regularly scheduled programming on VX-TV. Tonight we've got goop (malware) being pushed to prod, I've got goop that needs to be bonked, and also challenging the developers of EtherRAT to a YuGiOh duel
> be me
> get DM
> "smelly, want to see my malware?"
> its a threat actor lmfao
> "just please dont share"
> ok lol lemme see ur goop
> download their .exe
> look inside
> weird .exe, weird sections
> partially position independent
> doesnt use NT functionality
> cool, but standard c malware
> anti-vm tricks, blah blah blah
> nothing super crazy, standard goop
> not doofus goop, but not good-good goop
> keep bonking
> something weird
> confused
> ???
> look closer
> look extra closer
> never seen this type of code before
> confusion
> no idea whats going on
> keep bonking
> its a fucking VM
> malware has its own instruction set
> basically made their own mini programming language inside .exe
> ???
dawg, they asked me to not emulate this or anything so it isnt submitted to AV companies.
do you have any idea how much of a bitch this to statically reverse? im just taking shots in the dark now, i have no idea what the fuck is going on. normally at this point id switch to emulation to see how it interacts in a sandbox
I've been reverse engineering this NodeJS + Java malware payload for over 12 hours now.
This malware is obfuscated using a commercial obfuscator, and I am inexperienced with Java reverse engineering, so this has been very painful.
I may motivated by my disdain for this goop
Oh, well would you look at that, NodeJS goop that loads Java goop. I HATE YOU
Читать полностью…
You can actually learn a lot about malware and reverse engineering if you use AI to expand your knowledge base, ask questions as you go, and test and verify what happens yourself
But some dorks don't do that, they just slap the slop button and drool
extra silly points that the person who sent me the goop found it from a google ad lmfao
tl;dr no free robux, but free goop
> tell wife
> wife freaks out
> says I'll get rabies
> okay lol
> drive to ER
> tell them bit by bat
> they give me cool guy pass
> cut everyone in ER line
> haha suckers
> doctor sees me
> lol we gotta give you shots
> ok no big deal
> leaves
> comes back with 6 needles
> wtf
> "one in both shoulder"
> "one in both butt cheeks"
> "4 shots where bat bit you"
> needles fucking gigantic
> wtf
> get 8 shots
> body lumpy from shots
> tells me need to come back
> in 3 days, 7 days, 14 days
> wtf 6 more shots
Dawg, DO NOT become exposed to rabies. The shots HURT A LOT.
Chat, we're cooked.
Today I decided to review the malware collection. How much malware have I collected over the past 7.5 years? I've collected 42.13 TB
WHAT AM I DOING WITH ALL THIS GOOP
It turns out this goop someone sent me in a DM was state-sponsored malware designed to perform espionage on select groups on individuals in South America
This malware campaign was attributed to APT-C-36
Silly government written malware haha bonk bonk haha
Real ones know that this audio clip is from Dragon Ball Z: Broly the Legendary Super Saiyan, at the climatic ending when Goku was losing the fight to Broly, everyone was down and out, and Goku needed the energy from Trunks, Gohan, Piccolo, and Vegeta to defeat Broly once and for all before the comet destroyed the planet.
Totally unreasonable for them to show Planet Namek from the Frieza Saga
Vegeta was being a total bitch, refusing to give his energy to Goku, because Vegeta saw Goku as a lesser Saiyan and wasn't deserving of his royal energy (he is the Prince of all Saiyans). Eventually Vegeta concedes, gives Goku his energy, but tells him to "But Kakarot, finish him... finish him NOW!".
Instantly upon receiving the energy Goku hits a pseudo-SSJ2, terrifying Broly at Goku's newly acquired energy, even verbally saying out loud, "What?! Where is he getting all of this energy?!".
This accompanied by Haji's Kitchen "Lost" and "Day After Day".
I'm being so deadass, AI didn't even write this shit and I didn't even need to Google it, when this movie came out in the early 2000s me and middle school homies watched this fucking movie on repeat, we'd be rolling around the block on our bikes singing "Day After Day" and thinking about how Goku's Kamehameha wave didn't even scratch Broly when Goku was SSJ1
tl;dr United States government rules it may be legal to possess CSAM (Child Pornography) if it's AI generated
Dawg, last week the United States Seventh Circuit Court of Appeals made a decision which will unironically change the way CSAM (Child Pornography) is handled in the United States.
Under United States v. Anderegg, Anderegg was charged with distribution and possession of Child Pornography. Anderegg used Stable Diffusion AI to generate hyper-realistic depictions of children having sex.
While charged with CSAM, Anderegg appealed the decision and argued it was not possession of CSAM because the "children" in the images were not "real" children. Rather, Anderegg and his attorneys argued that it is not illegal to possess obscene material which does not harm anyone.
The courts official ruling: By 1969 ruling of Stanley v. Georgia, you are protected by the United States First Amendment to privately possess obscene material in one's home. Hence, because the images are completely computer generated, and no actual child was used to create the pornography, the United States government cannot constitutionally criminalize someone's private possession of those obscene images in their home under this statute