vxunderground | Unsorted

Telegram-канал vxunderground - vx-underground

40629

The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/

Subscribe to a channel

vx-underground

I'm not really interested in content creation, but I've never done it before and it seems kind of fun to try something new

Читать полностью…

vx-underground

DEV#POPPER, big fan of how you encode the URL and say "helloipbot!!" in your ETH goop, I think it's clever, I like it. Not even memeing, it made me giggle

Читать полностью…

vx-underground

to clarify, the interview appeared to be for Nike, they sent a project over which looked like it would be to work on a Nike front-end solution e-commerce thingie, but the solution thingie loaded malware

Читать полностью…

vx-underground

I have no idea why someone would want to try to compromise trucking companies that do logistics, delivering food and stuff, super weird

Читать полностью…

vx-underground

Someone is DDoSing vx-underground.

I am unsure why someone would want to take the malware library offline.

Unfortunately, because the website is offline, I can no longer work. All I can do now is eat this delicious ham and cheese sandwich and watch anime.

Читать полностью…

vx-underground

> Last time on Dragon Ball Z
> be me
> get DM
> "smelly i found goop"
> wtf i love goop (malware)
> download
> look inside
> malware masquerading as Pokemon Map Loader
> bonk bonk
> installer -> nodejs goop -> java goop
> java obfuscated with qProtect 2.0
> annoying
> uses ethereum something-something for C2 stuff
> make some posts
> say campaign is dead (c2 from eth stuff is dead)
> annoying
> get DM
> "Hey Smelly, I'm REDACTED with REDACTED. That malware campaign you're describing is REDACTED. You're free to post as you please, but I would appreciate if you didn't mention REDACTED because REDACTED"
> ok nbd, idc, i wont mention some stuff
> go on about business
> forget
> get DM
> "Hey Smelly, REDACTED from REDACTED again, recently we REDACTED. I need to advise you that the Threat Group REDACTED believes you're the one REDACTED because you were discussing their malware on X"

Читать полностью…

vx-underground

Yeah, so basically there is this guy in the United States named Bernie Sanders, and he has a homie named Greg Casar, and pretty much today (September 3rd, 2026) released a blueprint of a proposal of a "ban" artificial "superintelligence".

The Brownie Summers guy, or whatever his name is, said he and his homie Caesar's Pizza came up with the idea when they saw OpenAI and Anthropic AI models "hacking" everything. They said that the AI companies are "losing control" over their "superintelligence" and it needs to be banned.

So I was like, "Well, I like goop a whole lot. I know a little bit about AI goop, I deal with goop and schlinkus a bit. What did he mean by this?"

All these headlines are floating around social media but no one actually explained what Burpie Slimmers or Gurgle Pants actually wrote, and I had to unironically go way out of my way to read it.

Chat, you're NEVER going to believe what they wrote. It is LITERALLY 1 (one) page PDF with some bulletin points and ideas. Bamboozle Slinkers and Goopus CarAccident haven't done shit other than say, "hehe what if?"

Anyway, here is what they wrote (this is literally it):

Читать полностью…

vx-underground

Virgin $500 AI Toothbrush vs Chad $1 Toothbrush

Читать полностью…

vx-underground

Dyson unveiled their "CameraJet" toothbrush.

It is a toothbrush with "AI" (???) which has a bunch of cameras on it. These cameras monitor your brushing habits and livestream the inside of your mouth to the Dyson app on your phone, basically allowing you to perform an endoscopy on yourself.

Dyson claims the AI within the toothbrush was developed using 16,000,000 lines of code and also them performing AI analysis on 470,000 dental images they've collected over the past 6 years. In other words, Dyson somehow collects about 213+- dental records a day (???).

Dyson claims the AI on the toothbrush isn't stored on the cloud, and it only livestreams to you. This is probably true. However, when you purchasing the toothbrush you must register with Dyson (from their website, or the Dyson app on your cellphone).

Here is what Dyson CameraJet does collect:
- Full name
- E-mail address
- Country, region
- Dyson product
- WiFi information
- Bluetooth (local-network access, device discovery)
- Location permissions (GPS)
- Home and Device information

Dyson, based off of their own privacy policy, collects your GPS location and correlates it with local outdoor air-quality and weather. It may also use this in conjunction with local-network access device discovery to enumerate potential air purifiers, fans, or robotic cleaners. Furthermore, the Dyson app requests labeling where your Dyson CameraJet is located in the house (Master Bathroom, Basement Bathroom, etc).

... why?

Читать полностью…

vx-underground

> be me
> get dm
> "smelly, i found goop"
> wtf i love goop (malware)
> sends url
> needs to be CURL'd
> try to CURL
> delivers picture of penis
> ???
> try again
> IP address banned
> try from different IP
> penis again
> banned again
> try third time
> more penis, more ban

Читать полностью…

vx-underground

Dawg, they got Pete Hegseth in the data breach. It's available for sale for $100

Читать полностью…

vx-underground

I really recommending reading this.

In summary, a company which does ID verification for in-person interactions (hotels, car rentals, ID verification for alcohol or marijuana, etc) has some how exposed over 153,000,000 drivers licenses for people in the United States and Canada.

It is a catastrophic data breach, probably one of the worse I've ever seen. If you're in the United States and have traveled, gotten a hotel, purchased marijuana or alcohol, there is a high probability you're in this.

Unlike other breaches, this includes a photo of the person (from the license), making verification you've identified the person significantly easier.

This poses a significant threat to celebrities (musicians, YouTubers, streamers, adult entertainers, actors, etc), politicians, lawyers, wealthy people (CEOs, investors, people of public interest), Law Enforcement Officers, etc

Krebs himself, and several other security researchers, have already confirmed they're in the data leak.

tl;dr gah damn dawg this company is going to be sued into oblivion

https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/

Читать полностью…

vx-underground

I've been cookin' dawg, I'm on that 2025-2026 making power moves type shit.

I started off in August, 2025 at 280lbs (127kg). September, 2026 I'm at 215lbs (97.5kg).

However, for reasons I don't understand, when I don't eat for long stretches of time, I get an absolutely insatiable appetite for sugar, basically raw sugar almost. I also get kind of groggy, forget stuff, and chug water, like an absolutely insane thirst.

Anyway, I had a giant bowl of Vanilla Ice Cream drenched (basically filling the bowl) with Maple Syrup and then covering it in Chocolate Syrup.

I now feel much better, I'm no longer thirsty, and head isn't groggy.

I don't understand why my body does this.

Читать полностью…

vx-underground

Well, the malware campaign is dead, I learned a lot along the way, it was fun (I was suffering).

Back on the hunt for goop (people just send it to me)

Читать полностью…

vx-underground

Get a load of this guy, the meta data is present in his Java payload and he labels it internally as *checks notes*

"There is no God"

???

Читать полностью…

vx-underground

I kind of want to try making some really ghetto 60 second clips explaining goop analysis.

Pretty much like, what I write online with ">" stuff but with silly pictures of cats, basic animations, explosions, just really short and simple.

Читать полностью…

vx-underground

This is really exciting malware actually.

tl;dr they're updating their goop as I poke the goop with a stick

They're also using ETH Smart Contracts got C2 resolution, except this malware campaign is LIVE. They updated their goop ETH C2 stuff .... 1 hour ago as of this writing.

The IP address it resolves to was detected as being malicious ... today. This girlie is alive-alive. These malware developers are cooking and spearphishing nerds trying to get interviews at Nike and stuff

They're currently masquerading as Babel on NPM.

This is an active campaign SocketSecurity described as DEV#POPPER

New malware IP as of ... literally this exact writing, these nerds are working as I'm typing:

193.247.144.38

Читать полностью…

vx-underground

> be me
> get dm
> "smelly i found goop"
> wtf i love goop (malware)
> "I got invited to a job interview, to make a long story short the project they asked me to work on I think was malware... interested in looking?"
> look inside
> its malware

FAKE JOB INTERVIEW GOOP?!

Читать полностью…

vx-underground

tl;dr strange, strange, strange goop targeting trucking companies in the United States, too much to type so used silly pictures

> be me
> get dm
> "smelly i found goop"
> wtf i love goop (malware)
> "I'm a SOC analyst for a large trucking carrier. Several of our carriers have been sent some malware. We asked a third party cybersecurity company to review the malware, they said they'll need time to download it and run code directly to memory"
> ???
> downloads masqueraded vbs
> vbs supposed to tell truckers their schedule
> supposed to say what theyre hauling and stuff
> wtf lol
> look inside

too much to write actually, just look at funny pictures
Masqueraded file:

Stage 0 (Masquerading domain):
carrierpackready(.)com

Stage 1 VBS:
d26be4bef5afbebc9a831ee00bdf0fd2f5e57e86eb8e89a0b57c9534352f3cdf

Stage 2 JS:
72a5f71233cbe244048e335aad829570f5aba2b72a8e346544ae9fd327c321ea

Contract:
0xfb9B234CdcE6dd9E0Eb4895b5682eBebE0b3D277
0xCc4BCd51e0eA7E254b0F30044538F6Cb86a4E61b

Contract Creator:
0xBA8B70D5B15cFbFD628F71560aAb996356c0fa84

Drop-dead-resolved C2:
do(.)opinionvip(.)club
amc-us(.)mprevive(.)com
play(.)app-open(.)click
api-wls(.)ngrok(.)app
main-tunnel(.)ngrok(.)io

Читать полностью…

vx-underground

tl;dr malware developers pissed off some big ass corpo and now big ass corpo is bonking them back, but because i discussed their goop before big ass corpo bonked them back they think the weird cat guy some how magically is capable of bonking them back

I DIDNT DO FUCKING SHIT

Читать полностью…

vx-underground

Bro wrote, "cannot exceed human intelligence". Dawg, like 75% of the United States population can't tell you how many sides are on a triangle (the answer is 7).

Читать полностью…

vx-underground

If you're curious on how to get into goop (malware) research, it's simple.

1. Don't panic
2. Bring your computer to Apple Bees, really get to know her
3. Ask about her hobbies and interests
4. Don't ask her about her ex-BF
5. Use the staff of Sheogorath to place the computer in an alternate dimension
6. Cover yourself in mayonnaise
7.
8.
9. Ask a friend or eat an banana

You've now mastered goop

Читать полностью…

vx-underground

Oh, I see, it's because Dyson sells air-purifiers and stuff, so this is all rolled together from the Dyson app. Nothing from the thingie announced today gives much information on what the "CameraJet" collects except "Coverage Maps" (places your clean and don't) and floss habits.

Читать полностью…

vx-underground

My malware setup at home is beginning to become absurd. Like, it's actually ridiculous.

Right now I've got some goofy cheapo desk, and three monitors on it. However, I need to get a longer desk which supports more monitors, an additional computer for a storage server for my goop collection, and (ideally) another machine for a local malware analysis sandbox for emulation.

It is ridiculous bro, what am I even doing anymore with all this goop

Читать полностью…

vx-underground

The company which leaked data is IDScan. IDScan does not list all of their customers, however some are publicly known. If you have ever used these companies (and provided an ID) your data has been leaked:

- Shell
- AMC Theaters
- DraftKings
- Dutchie
- FedEx
- Hertz
- Chevrolet (General Motors)
- GameStop
- Jack Henry
- MRI (Checkpoint ID)
- Polaris
- Simmons Bank
- LendingUSA
- Circa Resort & Casino
- Planet 13
- Rouses Market
- US Coast Guard Academy
- Caesars Entertainment
- Motorola

Читать полностью…

vx-underground

Can't trust online ID verification, now you can't trust in-person ID verification.

Fucking hell man

Читать полностью…

vx-underground

tl;dr not eating for so long, blood sugar getting low (probably) and body demanding calorie dense material + sugar to correct itself

Anyway, now we go back to your regularly scheduled programming on VX-TV. Tonight we've got goop (malware) being pushed to prod, I've got goop that needs to be bonked, and also challenging the developers of EtherRAT to a YuGiOh duel

Читать полностью…

vx-underground

> be me
> get DM
> "smelly, want to see my malware?"
> its a threat actor lmfao
> "just please dont share"
> ok lol lemme see ur goop
> download their .exe
> look inside
> weird .exe, weird sections
> partially position independent
> doesnt use NT functionality
> cool, but standard c malware
> anti-vm tricks, blah blah blah
> nothing super crazy, standard goop
> not doofus goop, but not good-good goop
> keep bonking
> something weird
> confused
> ???
> look closer
> look extra closer
> never seen this type of code before
> confusion
> no idea whats going on
> keep bonking
> its a fucking VM
> malware has its own instruction set
> basically made their own mini programming language inside .exe
> ???

dawg, they asked me to not emulate this or anything so it isnt submitted to AV companies.

do you have any idea how much of a bitch this to statically reverse? im just taking shots in the dark now, i have no idea what the fuck is going on. normally at this point id switch to emulation to see how it interacts in a sandbox

Читать полностью…

vx-underground

I've been reverse engineering this NodeJS + Java malware payload for over 12 hours now.

This malware is obfuscated using a commercial obfuscator, and I am inexperienced with Java reverse engineering, so this has been very painful.

I may motivated by my disdain for this goop

Читать полностью…

vx-underground

Oh, well would you look at that, NodeJS goop that loads Java goop. I HATE YOU

Читать полностью…
Subscribe to a channel