40629
The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/
Although this says "17+ verified people", we have little faith in Roblox.
Especially when Roblox sued YouTuber Ruben Sim (in an attempt to silence him) for becoming a whistleblower and exposing Roblox developer Arnold Castillo for his pedophilia
https://www.justice.gov/usao-sdin/pr/new-jersey-man-federally-charged-enticement-minor-and-interstate-transportation-minor
Let's talk about ransomware for a second.
Ransomware Threat Actors are opportunity driven. They do not have specific targets in mind. If you've got a dollar, they want it.
The reality of the matter, in the ransomware ecosystem, is initial access brokering is cheap and affordable, it is a worthwhile investment for ransomware affiliates to establish a good relationship with an initial access broker.
There is an initial access broker who will sell you roughly 1,000,000 misconfigured VPN's for $1,500. These 'misconfigured' VPNs typically will be companies which have accidentally set a VPN user login to something like 'test' as the username AND password. Although this may sound absurd, or unlikely, these are extremely common as companies may simply overlook small errors. However, these misconfigured VPNs are not curated. Ransomware affiliates might have to spend weeks, or months, sorting through the list determining which companies discovered have:
1. Money
2. Do not violate the rules of the ransomware group
3. Have insufficient security posture
4. Are outside with CIS (ex-soviet countries).
This is often how ransomware groups collide with each other. Two different initial access brokers may have identified (or gotten access) to the exact same organization and then sold this identified vulnerable organization, or access, to two different ransomware groups. There have been stories where ransomware affiliates gain access, only to discover upon entry the organization has already been ransomed!
Companies that have correctly configured EDRs (a detected blue team), a SOC, and have good policy and/or asset control will defeat most ransomware affiliates. More often than not, if an affiliate encounters a company that has a good EDR, or hardened machines, they may simply abandon the target all together (or sell it to a different ransomware operator) because it may not be worth their time. Metaphorically speaking, time is money to the Ransomware Threat Actor.
Regarding targets, there is another aspect often overlooked. Ransomware operators residing outside NATO often do not understand the culture or targets they have identified. For example, we have witnessed ransomware groups target public school systems, failing to understand how the United States allocates money for schools. They mistakenly believe tax-funded schools are ripe with cash and simply do not believe negotiators when they say the victim doesn't have the money. They rely on publicly available information (often wrong information) from places like Wikipedia or ZoomInfo. They see big numbers and believe that this is the profit margins.
tl;dr if you very seriously want to defeat ransomware, security companies need to understand the financial limitations many organizations face. They do not have the money, or man power, larger companies have to combat an ever evolving threat landscape.
NOTE: There are some caveats to this rant. Every ransomware affiliate will seek different avenues of gaining access. Blah, blah, blah.
Thanks for reading. Have a goodnight (or morning).
Nevermind, our friends at Malcoreio will be giving away 20 physical copies of Black Mass Volume II next week.
Читать полностью…
Lazarus group, if you're reading this, please give us an autograph. It would be super cool to have. Also, tell Mr. Kim Jong Un we said "Hello"
Читать полностью…
tfw Trickbot, an internationally wanted cyber-gang, was more organized and had better benefits for employees than your employer
Читать полностью…
Anyone familiar with the Apex Legends™ IDE?
Читать полностью…
Some nerd named ParkinsonFrost has created an Infosec muppet show.
Читать полностью…
We are doing a book giveaway on Twitter. If you're interested in books, or something, check it out here:
https://twitter.com/vxunderground/status/1698911064539206022
We have personally used his research and documentation hundreds, if not thousands, of times.
He was a true gift with an incredible skill for writing.
Rest in Peace.
Today at 9:31AM EST Stake, an Australian based crypto gambling site, was compromised. The currently unidentified threat actor(s) steal over $41,000,000 in cryptocurrency.
- First transaction, $16,000,000 stolen
- Second series of transactions, $25,000,000 stolen
We've updated the vx-underground Windows malware paper collection
- 2023-08-28 - Uac bypass via UIPI or Windows Task Manager
- 2023-08-27 - Demonstrating Parent Process ID Spoofing
- 2023-08-23 - Demonstrating how IIS decrypts AppPool credentials
- 2023-07-26 - WSPCoerce - PoC to allow authentication from Windows hosts using MS-WSP
- 2023-06-18 - DCOMHijack - Demonstating lateral movement using DCOM and DLL hijacking
- 2023-06-09 - No Alloc, No Problem - Leveraging Program Entry Points for Process Injection
- 2023-06-01 - Improving the stealthiness of memory injections techniques
- 2023-05-21 - PCAPeek - PoC reassembler for reverse VNC traffic
- 2022-09-05 - DirectX and HyperV - An Offensive View
No, we do not accept NFTs as donations. How the hell are we gonna pay server bills with a .png file?
Читать полностью…
Roblox is a popular game for children. Roblox has also been a hunting ground for child predators for years now.
Instead of improving the safety of the young userbase that plays the game, CEO David Baszucki announced Roblox will be launching an official Roblox dating app.
August 2023 (version 1.82) of Visual Studio Code now supports Port Forwarding to allow easier access from Threat Actors.
inb4 Visual Studio Code as a C2?
Very cool 👍
More information: https://code.visualstudio.com/docs/editor/port-forwarding
Our friends at Malcoreio have agreed to sponsor a Black Mass Volume II giveaway. When it is released next weekend we will be giving away 10 copies =D
Читать полностью…
You've successfully identified every phishing attempt made against you or your organization, but then just across the horizon you spot the phishing final boss.
https://chase.com@n9.cl/8bzuupbz
Today Google TAG (Threat Analysis Group) reported they have identified North Korean State-Sponsored Threat Actors targeting security researchers (again).
They identified accounts on both Twitter and Mastodon. 😋
https://blog.google/threat-analysis-group/active-north-korean-campaign-targeting-security-researchers/
Today the United States and United Kingdom sanctioned 11 individuals believed to be responsible for the Trickbot botnet.
They sanctioned Trickbot managers, HR representatives, developers, QA engineers, network administrators and more.
More information: https://home.treasury.gov/news/press-releases/jy1714
We have extremely exciting news. Our second book will be released next weekend.
Black Mass Volume II.
Digital copies are free on vx-underground. Physical copies will be available for purchase on Amazon.
United States Presidential Candidate Vivek Ramaswamy has proposed abolishing the United States Federal Bureau of Investigation. His proposed solution does not account for Cyber Crime (although maybe the financial aspects of it).
Читать полностью…
Before we make more updates to vx-underground we have to sync our off-site backups across a few different regions. We're syncing 7TB+ of data at like, 5Mbps.
tl;dr meme game continues (also the giveaway is tomorrow)
Have a nice day:)
Some dork on Telegram is selling vx-underground samples for $300. He even takes a screenshot of our website, proclaiming it to be his (???), and says he got the malware from a seizure (???)
👏DON'T 👏PAY 👏FOR 👏 MALWARE 👏
New achievement unlocked for perpetual vx-underground goofs:
- "What's the password?"
- Typos (everywhere)
- Receiving messages from compromised government e-mails.
We receive messages from compromised government e-mails every week now
P.S. Yes, smelly needs Grammarly.
Absolutely tragic news. Geoff Chappell, the reverse engineer and author, has passed away today. His work was incredible.
Our deepest condolences to Geoff's family, friends, and colleagues.
Check out Mr. Chappell's work. It's amazing: https://geoffchappell.com
The leader singer of Smash Mouth, Steve Harwell, has passed away at age 56.
Their hit song "All Star" alongside the film "Shrek" inspired hundreds, if not thousands, of memes and trolls.
Rest in power, king.
https://youtu.be/L_jWHffIx5E?si=5f54sugwfY29zwjB
There is a famous video online shared between people involved in doxxing, swatting, scamming, sim-swapping, etc. An individual is doxxed live in a Discord chatroom. He fails to mute his mic. His mother becomes very angry.
We have blurred the video to protect their identities.
When we released our first book (Black Mass Volume I) some individuals received botched copies from our publisher. Some individuals received the book with comic book drawings, others received the book alongside balls of yarn (???).
In the spirit of us celebrating our many typos, failures, and goofs, Black Mass Volume II will include a coloring book segment. It will include illustrations of ransomware operators and vx-underground staff (and more!). It is exciting times!
Black Mass Volume I was free in digital format. Getting a physical copy was $8.00 (available on Amazon, by the book if you want to support us).
Black Mass Volume II will also be free in digital format. We are unsure of the price currently because we still are not sure how much it will cost to publish it.
Attached is a preview of coloring in the vx-underground staff segment. As you can see from this illustration, we are edgy and illiterate Orangutans with anime waifu posters.