40629
The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/
We've updated the vx-underground InTheWild malware collection. We've added InTheWild.0088 - InTheWild.0094. It is 120,000 new malware samples available for bulk download.
Have a nice day.
https://vx-underground.org
Exchange this desktop with a Gateway computer, with the weird cow commercials, and a 50lbs (22kg) CRT monitor.
Читать полностью…
Dharma ransomware (alternatively referred to as Crysis ransomware) creates payloads which work on Windows 2000.
Читать полностью…
Dark Angels ransomware group hasn't even finished their payment portal for victims. The Johnson Controls page is just Lorem Ipsum 😭
Image via malwrhunterteam
It should be noted however that the leaker, kapuchin0, states he (Hello Kitty ransomware?) no longer need this and they intend on developing something superior to Lockbit ransomware group.
Читать полностью…
We're uploading 228,030 new malware samples to our VXDB (223GB uncompressed).
Reminder that our malware database is free. You can search through our entire malware collection and download to your hearts content =D
Total samples available: 18,995,422
https://virus.exchange
We recommend reading "The Lazarus Heist: From Hollywood to High Finance: Inside North Korea's Global Cyber War" by Geoff White.
The book provides key insights into North Korea's geopolitical motivations, historical context, the Kim Dynasties evolution from smuggling goods, methamphetamine production, their suspected USD counterfeiting operations (Superdollars!) to the present Lazarus Group as we know it.
From a technical perspective, the book is subpar - however it is evident this books target audience is not for the technically inclined. This is not a malware analysis book.
But, this book provides incredible (literally, absolutely incredible) insight into how Lazarus Group thoroughly performed reconnaissance on targets, how they precisely modified SWIFT environments in an attempt to steal $1,000,000,000 from the Bank of Bangladesh, and how their attacks against organizations effected company executives, individual employees, politicians, journalists, and law enforcement from all across the globe.
10/10
We received quite a few e-mails today from the Red Cross of Italy - compromised e-mails. The compromised e-mails come from an unknown individual asserting that the Red Cross of Italy is stealing (and laundering?) money
They also say they're not going to ransom them
¯\_(ツ)_/¯
Someone made this and requested we post it. Zoomers gonna be zoomers
Читать полностью…
Thank you to our friends at TheTorProject for the super cool shirt and stickers =D
Читать полностью…
YouTuber Mr. Beast is warning his users about scammers who are using DeepFakes of him to scam his users.
Читать полностью…
We have a Discord server which gives updates on recent ransomware group blog postings, government notifications, and other nerd stuff.
It also has 5,520 members. No talking is allowed though. It is a nice and quiet place.
https://discord.gg/MSjAQe4PUy
"I've never installed GNU/Linux" - Richard Stallman
Читать полностью…
POV: You visit http://vx-underground.org one time
Читать полностью…
A man on Twitter has created the dumbest post (and thread) in all of Twitter history. This is not an easy achievement either.
!!! Caution: reading this thread may result in spontaneous combustion !!!
tl;dr random guy writes erotic hacker fiction, says incomprehensible nonsense, normies foam out the mouth at the epic 1337ness
https://twitter.com/PatrickByrne/status/1711440905943572918
We've updated the vx-underground malware sample collection
- NokoyawaRansomware
- RhadamanthysLoader
- RoyalRansomware
- Vidar
- BoldMove
- DarkBitRansomware
- BlackSnakeRansomware
- ParadiseRansomware
- GigabudRAT
and more...
Check it out here: https://www.vx-underground.org/
If exploit developers, reverse engineers, and malware developers were alive in the medieval era they'd be the crazy person living out in the woods trying to perform alchemy spells like turning wood into gold
Читать полностью…
Sebastien Raoult, known online as Sezyo Kaizen, an affiliate (or as the courts write, 'co-conspirator') to the ShinyHunters data broker group, has plead guilty in the United States for conspiracy to commit wire fraud and aggravated identity theft
He is facing 27 years in prison
Hello Kitty ransomware group, the group most known for ransoming video game publisher CD Projekt Red, had their source code leaked online today.
Information and data via 3xp0rtblog
You can view the source code here: https://github.com/vxunderground/MalwareSourceCode
When developing malware it is important to inform any potential analysts the code is not malicious. Leave them a simple message, leave a string in the code as simple as "this is not malware, go away".
Читать полностью…
August 29, 2023 the United States Federal Bureau of Investigation announced the takedown (or dismantling?) of the infamous and long reigning botnet, Qakbot.
Qakbot is believed to have started in 2007, or 2008. Others argue that Qakbot (in its current form) appeared sometime in 2015 or 2016. Qakbot has been around a long time, and it appears the group intends on staying around for a lot longer.
Today Talos Intelligence shared information on the continuing operations of Qakbot. It is now believed the FBI (and associated partners) took down Qakbots C2 infrastructure. They did not takedown their spam delivery infrastructure. Talos noted previous Qakbot campaigns, labeled as "AA" and "BB", are active once again and note the distribution of Ransom Knight ransomware (alternatively referred to as Cyclops) and the Remcos backdoor.
You can read the full writeup- IOCs, further analysis of Qakbot AA/BB campaign, and more, here:
https://blog.talosintelligence.com/qakbot-affiliated-actors-distribute-ransom/
Thank you to our friend John Hammond for the new logo design
Читать полностью…
We are now selling the ARREST WAZAWAKA shirt. The front of the shirt says "Arrest Wazawaka" in English and Russian. The back contains his FBI Most Wanted Poster. The sides of the shirt contain the ransomware groups he was most known to be part of (omit Babuk).
ARREST WAZAWAKA!
Thursday and Friday vx-underground staff members DuchyRE and f0wlsec will be present at Hacktivity Conference. They'll be distributing limited edition shiny vx-underground UwU stickers
Читать полностью…
October 4th the United States Federal Communications Commission will be running a nationwide emergency alert test.
Every TV, radio, and cell phone will receive an alert at the same time at 2:20pm EDT.
However, the far more interesting news in relation to this is the conspiracy theorists asserting this is the United States government vaccine activation protocol.
tl;dr something something FTE 5G nanobots activate?
Throw back to when Richard Stallman put out a "personal ad" looking for a romantic partner. This is from 2009, he has archived the ad and noted he is no longer single.
Читать полностью…
Just kidding, the new site isn't live. We shot ourselves in the foot again. This is probably our 3rd or 4th botched migration attempt.
We need your help.
vx-underground is exceptional large, and continues growing at an alarming rate. We need someone who is talented in CSS and HTML.
If you would like a chance to suffer alongside us, please DM us on Twitter.
tl;dr redesign vx-underground, make it not super bloated and heavy, not an ugly amalgamation of ugly HTML files.
We finished VXDB, we published Black Mass Volume II. We want to finish this so we can take a break.
Someone sent us a message with a proposal. They said they know a vulnerable company. They proposed that we compromise the company, exfiltrate the data, and ransom it.
They want 50% of the payout.
50% FOR WHAT LOL YOU'RE ASKING US TO DO EVERYTHING
1. We're not criminals
2. This is a horrible deal. Who the hell would even possibly accept this?! 50% of an IDEA?!