vxunderground | Unsorted

Telegram-канал vxunderground - vx-underground

40629

The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/

Subscribe to a channel

vx-underground

Hello,

We do not share or archive Cobalt Strike or BruteRatel builders and/or leaks because they are intellectual property of individuals or organizations.

We anger enough people with our content or conversations, we don't want a lawsuit 😂

Thanks,

Читать полностью…

vx-underground

Update: we are now blocked too =D

It worked earlier this morning. It is like a regional slow-roll-out botched deployment from Discord.

However, the mobile app works.

tl;dr block all traffic from Discord.exe?

Читать полностью…

vx-underground

Users all across the globe are reporting they are seeing a "You've been blocked" message when trying to access Discord.

It appears there has been a CloudFlare misconfiguration somewhere...

Have a nice Friday, Discord 🙂

Читать полностью…

vx-underground

Today a Threat Actor shared with us his attempt to SMS-phish an individual at a large company. As you can see from the attached image, it went very well.

Читать полностью…

vx-underground

Concerning website updates:

We have migrated all of our content over to our new data host. However, we are unhappy with the current look of the website and the difficulty of maintaining it.

The current theme (?) of the website is all of the data encapsulated into a singular HTML form, with some javascript to enable searching. This has resulted in the website index file being a staggering 16MB, and continually growing larger.

This is not a viable long-term solution. We have decided to allocate this down time now to pursuing an actual web application which will permanently act as the new vx-underground website. It will be dynamic, allow searching, and allow us to easily add new content. It will also contain a site map so you nerds can scrape it to your hearts content.

The reality of the situation though is developing something like this will be time consuming, hence we have not made any new updates the current site because eventually all of these new additions would need to be ported over to the new website.

Sit tight, we're using your donor money, sponsor money, swag money, and book money to have an actually talented person develop something nice that we can all enjoy. Until that days arrives, we will just be hoarding data.

Sorry about the downtime, but we'd rather (try) to do things right (we normally don't do things right the first time, but we try 😂).

Читать полностью…

vx-underground

Unrelated to malware, there is a person who livestreams his kitty cats online. It is important to watch the new born kittens play.

https://www.kittycatcam.com/

Читать полностью…

vx-underground

Also, how do these dangerous desperados have 27TB of storage? We have roughly 7TB and it is monstrous.

Who is paying for this?

Читать полностью…

vx-underground

Well how about that 🤠


September 26th: 5PM
September 27th: 3PM

Читать полностью…

vx-underground

Found DoggieTV exposed on Shodan. DoggieTV is really, really good TV, potentially better than ChickenTV

*It's a dog daycare center

Читать полностью…

vx-underground

Please tell all of your trauma, fears, inner thoughts and feelings, personal identifiable information, and mental health issues to ChatGPT, owned by OpenAI, which is owned by Microsoft.

Hush, tell all your secrets to Microsoft. It'll be okay.

Читать полностью…

vx-underground

Deranged nerd meme time on a beautiful Tuesday

Читать полностью…

vx-underground

Today someone operating under the name "MajorNelson", a nod to the former Director of Programming for the Microsoft gaming network Xbox Live, asserts RansomVC is lying.

He then released all the content RansomVC claimed to have into the general public.

tl;dr another Sony leak?

Читать полностью…

vx-underground

Hello, apologies - we believe this post lacks clarity.

They did not ransom* SickKids, as in deploy ransomware, we meant they're extorting SickKids because they exfiltrated sensitive data.

To be the best of our knowledge no ransomware payload was deployed.

Читать полностью…

vx-underground

cl0p ransomware group has ransomed SickKids, one of the largest pediatric healthcare facilities in the world.

They've exfiltrated 13 years of data related to fertility, pregnancy, and healthcare information on children (including newborns).

https://techcrunch.com/2023/09/25/decade-of-newborn-child-registry-data-stolen-in-moveit-mass-hack/

Читать полностью…

vx-underground

It's always important to practice computer hygiene. We recommend washing your computer daily with soap and warm water.

This can help prevent viruses and bacterial infections!

Читать полностью…

vx-underground

We have received another paycheck from Twitter. This time they paid us $239.92.

We have used this money to donate to the Electronic Frontier Foundation and The Tor Project.

We donated $66.95 to EFF and $250 to Tor. It exceeded our Twitter paycheck, but EFF and Tor are badass.

Читать полностью…

vx-underground

Will someone PLEASE tell Indian scammers that nobody uses the word "kindly"

Читать полностью…

vx-underground

Richard Stallman, the man behind GNU, copyleft, and way too many others accolades to even list, announced at GNU 40 that he has cancer.

Fortunately, he reports that it is slow growing and completely manageable. He says he isn't going anywhere.

He is 70.

Читать полностью…

vx-underground

Thank you syr0_ for this wordlist, it will help many people.

https://github.com/0xsyr0/vx-underground-wordlist

Читать полностью…

vx-underground

Hello,

Thank you to the many people who volunteer their services or wish to be a intern. Unfortunately, we are not an official entity on paper and our work is primarily aggregating samples and papers.

For students asking about interning: what we do is trivial (and painful) work which we do not believe would be beneficial for a student to do. We believe real world exercises, in actual cooperate environments (or startups, pick your poison), is far more important than helping some goofy website online.

For those wishing to volunteer: our work is simple, send us cool papers you enjoy, send us malware samples you found. It is nothing special. If we think what you discovered is cool, we will happily add it. We will also happily add your own research or papers. However, this is no full time position unless you intend of doing nothing by reading papers all day - which we do not believe is beneficial for anyone:)

Regardless, it is always heartwarming seeing so many young people offering (or asking) if they can help. We wholeheartedly appreciate your messages. It is very kind of you. Thank you for the love so many of you show us daily. It means a lot.

Читать полностью…

vx-underground

We got hit with a copyright strike from a tweet in 2020.

Читать полностью…

vx-underground

Today Johnson Controls, an ICS/SCADA vendor, confirmed they were a victim of Dark Angels ransomware group.

Dark Angels claims to have have exfiltrated 27TB of sensitive data from Johnson Controls

We are unfamiliar with Dark Angels ransomware group.

Читать полностью…

vx-underground

Thank you for the shout out, Threat Actor(s) which keep compromising large Twitter accounts.

Читать полностью…

vx-underground

Found the ChickenTV exposed on Shodan. ChickenTV is the best TV

Читать полностью…

vx-underground

Please for the love of God, if you e-mail us or DM us, please keep your message as succinct as possible.

We make sure to read everyones messages, but it is not necessary to send us a 10 paragraph essay and backstory and anime lore on a simple question or request.

Thank you.

Читать полностью…

vx-underground

Conduent has been compromised for the past 3 months and nobody has noticed yet.

A Threat Actor today expressed frustration with the company after he phished several employees via text messaging.

He expressed his frustration in the Breached telegram chatroom, as well as our e-mail address, by sending us a lengthy e-mail with dozens of pictures and hundreds of documents as proof.

tl;dr phished some employees, pivoted into HR, read company e-mails, read chatrooms, scraped everything he could get access to from the users

Читать полностью…

vx-underground

Today McDonalds Point-of-Sale system setup and executables were leaked online. An unidentified Threat Actor claims to have stolen the executables, installation scripts, etc. by pivoting off of McDonalds Free Wifi

Читать полностью…

vx-underground

Interesting side note: In 2022 this facility was ransomed by Lockbit ransomware group. Subsequently Lockbit ransomware group administrative staff apologized (for the first time) and gave the decryption key for free (for the first time).

Let's hope cl0p does the same.

Читать полностью…

vx-underground

Because nerds keep asking us about alleged Sony ransomware incident

tl;dr Threat Actors did not deploy ransomware, no corporate data was stolen, services not impacted. Data was exfiltrated from Jenkins, SVN, SonarQube, and Creator Cloud Development. They're extorting Sony

Читать полностью…

vx-underground

Today Basssterlord, a member of National Hazard Agency (a subgroup of Lockbit ransomware group) deleted his Twitter profile.

He requested that we note that it was not due to harassment or law enforcement.

He said they're very busy and now is not a good time to meme online😂😂

He was spending too much time memeing and shit posting 😂😂😂

Читать полностью…
Subscribe to a channel