vxunderground | Unsorted

Telegram-канал vxunderground - vx-underground

40629

The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/

Subscribe to a channel

vx-underground

Big news for malware enjoyers: more malware has been pushed to prod. It is more than I can count on my fingers and toes.

Bigger news for people who continually ask me for pictures of cats: I've attached a picture of a cat to this post.

Читать полностью…

vx-underground

Working on my first ever video on goop (malware) reverse engineering and analysis.

It is extremely ghetto, has lots of filler photos with pictures of cats I have saved on my desktop as I explain some concepts.

I also don't have a fancy mic, a fancy machine, ... or anything really.

My video is trying to be as short and condensed as possible, with no filler and no absurd explanations on every tiny detail of Windows internals.

I want to get to the point as fast as possible, assume the watcher understands what's going on, and if they don't they can try to learn themselves, ask questions, or just appreciate how silly the malware is.

The malware being bonked in the video is from a random DM I received. It is ordinary malware people come across in the wild. I want it to be as authentic as possible.

When I share it in the next couple of days, let me know what you think. I am well aware it not nearly as polished as pro YouTube nerds (I don't want to be a pro YouTube nerd).

I've never made a video before, it seemed kind of like a fun thingie to try, and there is a sort of demand for it from my audience... so whatever dawg, fuck it, we ball.

Читать полностью…

vx-underground

BREAKING: NEW AI MODELS CONFIRM THE COW GO MOO MOO AND DUCK GOES QUACK QUACK

AI EXPERTS MEETING MONDAY TO DISCUSS WHAT THIS MEANS

Читать полностью…

vx-underground

Post attempt number four. I'm sorry to people who have notifications enabled and keep receiving notifications.

tl;dr this is active goop, i am sharing the link because someone asked for Lua goop, but if you visit the GitHub it's not my fault if you download the .zip and accidentally run it (itll steal all your sensitive documents and passwords hehe)

Someone asked where the Lua goop was, this is the Lua goop I discussed earlier today. This GitHub profile is an active (updated 9 hours ago) SmartLoader malware campaign.

The repository "MicVST" masquerades as a legitimate open-source solution. However, the "How to Install" section in the ReadMe links to a .zip file which is the SmartLoader payload.

The .zip contains Launcher.bat which executes the *.exe and tells the *.exe to read the *.txt. The *.txt file is obfuscated Lua which is piped into the *.exe. The *.exe is a Lua VM.

This profile has been active on GitHub for about 3 months completely undetected. The SmartLoader campaign resolves an additional secondary GitHub page which acts as a configuration file for the SmartLoader payload, instructing it what to do.

https://github.com/tenrececaudatusarmour182

Читать полностью…

vx-underground

> be me
> get dm
> "smelly i found goop"
> wtf i love goop (malware)
> sends like to GitHub
> download
> look inside .zip
> instantly, at the blink of an eye, i recognize it
> SmartLoader

every single time, without fail, this is precisely how the SmartLoder malware campaign works

> find random github repo
> kind of popular
> make identical github but with typo or smth
> make "download" button link to .zip
> .zip contains EXACTLY 4 files
> launcher.bat, lua51.dll, *.exe, *.txt
> tell user to run .bat
> .bat tells .exe to read .txt
> .exe is lua engine thingie
> .txt is obfuscated lua
> always uses Prometheus obfuscator
> always uses ETH smart contracts for c2 stuff

I've had so many various SmartLoader campaigns sent to me I can smell the stink off of it from a mile away. The SPLIT SECOND they tell me something like, "haha ya it was a github kind of like the one i wanted" i IMMEDIATELY KNOW its fucking SmartLoader

Читать полностью…

vx-underground

WELL, IT SURE IS STRANGE how so many of my colleagues have all SUDDENLY decided to start doing ALT+0147 (“) and of course the ALT+0148 (”). Did I miss the memo? Is this the new standard? Because I could have SWORN we all did SHIFT + ' (") for literally forever.

I didn't even know how to do these fucking quotes, or the name of them (curly open quote and curly close quote), I had to look it up.

It's so odd... I can't figure out how THEY ALL learned the easy to remember ALT+0147 and ALT+0148 when we have SHIFT+' right next to our ENTER key.

SURE IS STRANGE HUH? TOTAL COINCIDENCE.

Читать полностью…

vx-underground

No goop bonking tonight

Some fucking dumbass drunk driver crashed into a telephone pole, a few blocks don't have electricity now

I want to punch this dude in the face

Читать полностью…

vx-underground

> get dm on telegram
> forget to reply
> check vxug email today
> 3,200+ emails
> all different emails
> all compromised emails
> all calling me the n word
> asking to reply on telegram

Chat, I'm no doctor, but I think this person wants me to reply

Читать полностью…

vx-underground

> ask ChatGPT what it knows about me
> lists stuff
> "You demonstrate a passive interest in Windows vulnerability research, although you've never found an exploit of your own"

Ok I said tell me what you know not hurt my feelings damn bitch

Читать полностью…

vx-underground

This information was first seen on social media via DarkWebInformer.

Full credit to them for seeing the post and sharing the photograph on social media.

Читать полностью…

vx-underground

Are you nerves dying from diabetes? Have you tried wrapping your feet in lettuce? The doctors won't tell you the secret lettuce technique, but it's 100% real and true

Читать полностью…

vx-underground

Had to change some wording, some people thought this was malware written by the Israel government.

This malware is masquerading as an Israel government domain to try to convince people to execute a goop (malware) payload.

Читать полностью…

vx-underground

Then I saw I could purchase other weird goop like Mercury, Cesium, and Europium, I said "wtf I want weird sounding stuff in my house".

I'm already on a bunch of lists (probably) for the malware goop, what's the problem with being on a list for weird chemical goop?

Читать полностью…

vx-underground

The split second I made this post I got DMs being like, "ERRR SCHMEEELY, WHAT IF ITS JEWISH PROPAGANDFFA?"

You'd be surprised I found goop swinging on Israel? Really? If anything, I'm surprised I don't see more of it.

I'm already seeing people being like "SHEEEMEEELI, LEAVE THIS GOOP ALONE"

Oh, so NOW we don't like goop? I LIKE ALL GOOP.

Читать полностью…

vx-underground

Good news for malware enthusiasts, another 200,000+ malwares have been uploaded to VXUG.

Good news for people who like silly pictures of cats, I've attached one to this post

Читать полностью…

vx-underground

And if it sucks, and we all hate it and think to focus on something else, it's all good too. It's fun to fuck around and try new things.

Video editing is so god damn boring though bro, holy cannoli

Anyway, let's see what happens.

Читать полностью…

vx-underground

UPDATE: NEW DETAILS EMERGING THIS DISCOVERY WAS DONE BY A SINGLE MAN IN A REMOTE CABIN IN MAINE. IT ONLY COST HIM $36,000,000 IN TOKENS AND ENOUGH ELECTRICITY TO POWER NEW YORK CITY FOR 11,000 YEARS

Читать полностью…

vx-underground

This is this particular SmartLoader payloads configuration GitHub. This link is safe to view. It is very silly.

ae.log is the configuration SmartLoader uses.
dec.log I couldn't figure out. It looks like it has another .exe inside of it encrypted and encoded as ASCII, but I stopped caring.

https://github.com/yawalinte

Читать полностью…

vx-underground

My stinky degenerate nerds, I'm begging of you, some of you need to get a grip (key weird some, not all, don't go ooga booga on me)

Every now and then I see some booger eater getting mad because when I do my dumb little malware posts I do:

> be me
Instead of
>be me

They get angry I insert a space.

Dawg, I know the standard image board etiquette is to not insert a space. I've seen the comments. I was a teenager on 4chan when people were asking if you like Mudkips.

I'm not doing an actual "greentext". I'm doing a silly write up with a 4chan like influence that also acts as a bulletin system, like a summary, or something.

Get a grip my guy. It's going to be okay.

Have a silly picture of a cat to clam your nerves

Читать полностью…

vx-underground

Also, I have THOUSANDS of malware analysis and malware development write-ups. It is soooo weird how SUDDENLY so many of these new write-ups have a summary with something named like "Why this matters".

Hmmmmmmmmmmmmmmm

Читать полностью…

vx-underground

Who the fuck is driving drunk on a Thursday anyway? Who is this guy???

Читать полностью…

vx-underground

> get another email
> "hello, my name is ___, some hacker got into my email, idk how. im really sorry about the n word stuff"

Читать полностью…

vx-underground

> be me
> get dm
> "smelly i found goop"
> wtf i love goop (malware)
> "I lost the goop... but I found a weird file on my computer"
> sends file
> malware log file
> ???
> examine log
> lots of debug information
> lmfao wtf
> see discord web hooks, hardcoded steam api key
> ???
> no identifiers really on VT
> beep boop search internet
> find the same steam api key in threat zone
> see a SHA256 hash
> look up on VT
> first seen june, 2026
> hmmm
> download file (hehe asked a friend)
> look inside file
> electron js malware
> heavily obfuscated
> skim file for anything that stands out
> references VirusTotal VM BlackList on GitHub
> lol ok
> clear text c2
> url inside referencing their Telegram
> ???
> go to their Telegram
> everything visible
> cite their Discord
> ???
> showing all their aliases
> showing draining crypto wallets
> showing stealing roblox items
> stealing counter strike items
> shows stealing emails, social media, credit cards
> shows when they started

wtf are you actually doing bro? youve documented EVERYTHING and handed it over in plain text. are you out of your mind???

Читать полностью…

vx-underground

> be me
> get dm
> "smelly i found goop"
> wtf i love goop (malware)
> "I purchased some car diagnostic software for my car. I bought it from a local shop near me. The software it came with was immediately flagged as malware"
> lol wtf?
> skeptical
> give the files plz
> he gives me files
> look inside
> ITS GOOP
> ????
> why did local car place give malware???
> look inside
> old malware, from a dead 2024 malware campaign
> malware masqueraded as car diagnostic software
> malware servers are long gone and dead

What the actual fuck?

Читать полностью…

vx-underground

ShinyHunters extortion group compromised the Florida Department of Motor Vehicles and as proof of their compromise they leaked Jeffrey Epstein's Drivers License and records

Читать полностью…

vx-underground

Today I decided to check in on the President of the United States and see what he's doing on social media on Truth Social

I opened the website and this is the first ad I see. Arguably one of the greatest ads of all time, could be hall of fame, I don't know

Читать полностью…

vx-underground

I looked at this goop masquerading as the Israel government. I don't know anything about Israeli stuff, so maybe someone can provide context on what these Threat Actors are trying to achieve.

> israel[.]gov[.]2026[.]vercel[.]app
> domain still live, don't shoot yourself in the foot
> all in hebrew
> fake cloudflare icon
> downloads .vbs file when visiting site
> govilreshet26.vbs
> a074eba155b982fdb821e8a641f6a061505d46d6cc65de031202a4ce29d486fa
> first noted 19 hours ago
> heavily obfuscated
> requests to runas admin
> checks for virtual machines (anti-reverse engineering)
> checks for every AV on the planet earth
> downloads screenconnect (remote desktop software)
> downloads from 130.12.115.24
> IP is small hosting provider in Canada
> clean IP
> clears everything in event viewer
> clears all windows defender logs
> downloads bs file from USA IRS (???)

I don't understand what this is targeting, what it's trying to achieve, or what reshet26 means in this context.

Читать полностью…

vx-underground

After seeing radioactivered yap online about radioactive goop so much, I've decided I am going to begin purchasing radioactive goop.

I know nothing about nuclear goop, or radiation goop, but it is interesting.

Now my home will be filled with malware and radioactive material

Читать полностью…

vx-underground

I got some interesting goop (malware).

To make a long story short, it is goop that is targeting the Israeli government "network 26"? (I legitimately have no idea what that means)

The domain is in Hebrew, it automates clickfix, and delivers a payload which is in Hebrew

Читать полностью…

vx-underground

It's so weird when I openly discuss my Benzodiazepine dependency and people say I'm "brave" for discussing it openly and admitting it

Bro, it's not embarrassing and it's nothing to be ashamed of.

Read the comments on the posts, EVERYONE knows SOMEONE who is addicted to something, or was addicted to something.

As much as I hate to say this, I'd argue drug addiction is probably the most common disease in the United States, possibly the planet, and for some reason people act like it's taboo or something.

Out of the thousands of comments I've received (or DMs or emails), I've only seen like ... three? Nasty comments or remarks. The rest are positive, people sharing their experiences, or people sharing their experience with loved ones who suffered from addiction.

It happens, man. It's all good. Focus on goop and silly cat pictures.

Читать полностью…
Subscribe to a channel