vxunderground | Unsorted

Telegram-канал vxunderground - vx-underground

40629

The largest collection of malware source, samples, and papers on the internet. Password: infected https://vx-underground.org/

Subscribe to a channel

vx-underground

Chat, I don't want to sound like a schizo, but it sure is STRANGE how much data Microsoft collects with it's telemetry functionality. It's very odd Microsoft documents and records all of your web browser activity, and gaming, and can tie it to your social media, so they can improve your "Windows Experience".

Читать полностью…

vx-underground

Doctor: Take this medicine at night to help you sleep

Me: Okay

Doctor: Oh, and by the way, if you have a sudden erection which is painful and won't go away, it's from the medicine. Immediately seek medical attention. Go the Emergency Room

Me: Okay

Читать полностью…

vx-underground

I'm not going to lie, I saw the Mexican people going absolutely schizo when Mexico defeated Ecuador and I thought to myself, "wtf thats badass, i want to be proud of the united states and go crazy af in the streets with random people".

Читать полностью…

vx-underground

Thinking of hosting a private Minecraft server? Think again. That is ILLEGAL. You're operating A BLACK MARKET OF CRIME.

Do it and you could end up like this, buddy. It's all over for you and your band of criminal misfits *check notes* building a cool looking fort

Читать полностью…

vx-underground

Still thinking about the time I went to BestBuy. I was in a pinch and needed to buy some computer stuff fast.

The guy behind the counter tried making an up-sale and pitched me some anti-virus product. He said it's good and protects you from viruses

I looked him straight in his eyes and said, "What? But I want the computer viruses on my computer"

He looked right back at me and just said "Okay".

He looked at me like this:

Читать полностью…

vx-underground

"hey smelly, out of curiosity, how did you learn so much? have you read every paper on vxug?"

fuck no. i probably havent read 10% of the library. if you unironically read everything there you would be two things

1. ultra mega fuck off malware brain
2. profoundly depressed

Читать полностью…

vx-underground

this is me memeing captain crunch and phone phreakers

Читать полностью…

vx-underground

Oh yeah? You're a "hacker"?

Prove it. Hack the electrical grid and give yourself infinite electricity, then use your infinite electricity to hack Bitcoin and give yourself unlimited Bitcoins

Then hack the airport and give yourself 999999 airplanes and fly around the world

Читать полностью…

vx-underground

There is dangerously high levels of "hacker" larp on TikTok. As a healthcare professional, I heavily advise against using TikTok

Читать полностью…

vx-underground

Dear Telegram people, I need your assistance. I'm confused.

Today the Department of Justice announced the extradition of a Threat Actor named Peter Stokes a/k/a Bouquet. He is alleged to be a co-conspirator to Scattered Spider. He is being extradited from Finland to the United States. He is facing a litany of charges (like, 20 years in prison or more).

However, I had thought (based off of the photo released), this person had been arrested before? Am I crazy? Does anyone on Telegram recognize this name or moniker? The FBI is parading this arrest, but I swear I've seen this before.

Читать полностью…

vx-underground

> wake up
> take a shit
> get out of bed
> check beep boop machine
> everyone calling me names
> crazy cat malware man
> mfw

Читать полностью…

vx-underground

Please forgive me, European colleagues and friends, how hot is -120c? Should we be concerned?

Читать полностью…

vx-underground

Goodnight tiny people living inside my phone

Читать полностью…

vx-underground

It's 2026 bro, fuck it.

It's time to go to court and sue people over TUNG TUNG SAHOR and U DIN DIN DIN DIN DUN MA DIN DIN DIN DUN, intellectual property of AI slop brainrot, and Roblox mini-games.

Читать полностью…

vx-underground

>get dm
>smelly there is MALWARE for FREE on REDDIT
>mac subreddit
>ad for some goop
>look inside
>VIBE CODED MALSLOP

YOU LEFT NOTES IN YOUR BASE64 ENCODED STAGER, WHAT THE FUCK IS ACTUALLY WRONG WITH YOU

Читать полностью…

vx-underground

> Peter Stokes
> Scattered Spider guy
> Arrested
> Microsoft helps FBI
> Read court documents
> Page 12
> Microsoft tracks Stokes from GDID
> Microsoft Global Device Identifier (GDID)
> Stokes used Windows
> Page 34
> GDID assigned to each OS install
> GDID unique to each device
> GDID only change if OS wiped
> Stokes GDID 6755467234350028
> GDID reported internet activity to Microsoft
> GDID showed Stokes using Ngrok
> GDID reported Stokes IP address
> GDID showed Stokes web activity
> GDID showed timestamps of web activity
> GDID mapped with video game activity
> GDID showed games played
> GDID undocumented
> GDID only mentioned in one MSDN document
> Azure UCDOStatus
> Azure Monitor Logging

Читать полностью…

vx-underground

Honestly, if you're wanting to get into malware development and malware reverse engineering (specifically in regards to Windows), I think the most important thing you can learn is the concept of a file.

1. What is a file extension? This is pretty obvious, .exe, .pdf, .mp3, etc.

2. How are file extensions handled? This would introduce the idea of the Windows registry and how extension querying is handled vs. the Windows loader

3. Which file extensions (or file types, rather) are used for payload delivery? e.g. .exe, .dll, .xll, .vbs, .ps1, .py, .lua, .docx, .vcproj, etc. The .exe, .dll, (and other native types, like .sys) will be sort of self-explanatory, but the others would introduce different malware delivery mechanisms (malicious files) and potentially wiggle in the concept of payload smuggling.

4. Each of the previous listed file types are different. How are they different? .exe and .dll (and many others) are native to Windows and handled by the Windows loader. Why are the others still considered executable files? This is when you slowly step into interpretive languages and VM dependency (JVM, PVM, etc).

Somewhere in this you would eventually stumble into the Windows PE format, how the PE format is different for .NET binaries, how Electron .JS executables act differently, weird stuff like .docx file internals, etc.

Basically, I think understanding files and how they're handled is an excellent starting point and sets the stage for what will happen next.

pic unrelated

Читать полностью…

vx-underground

I'm not sure what's going, but from my European and South American colleagues, I have developed a sudden interest in the FIFA World Cup.

It might be over for me. I can feel the Europeans draining the cheeseburger from my blood (I don't know anything about FIFA).

Читать полностью…

vx-underground

On Tuesday, June 30th, Jennifer Gibbons, Vice President of State Government Affairs for ESA (Entertainment Software Association) testified before the United States California Senate regarding Minecraft and Call of Duty private servers, which she claims are actually piracy.

Gibbons told the California Senate these private servers are unsanctioned. She is representing the video game industry in the United States and vehemently opposes the recently introduced Protect Our Games Act, the United States version of Stop Killing Games.

She referred to Minecraft private servers as "The Black Market".

Читать полностью…

vx-underground

Dawg, the Peter Stokes affadavit (nerd from Scattered Spider who was arrested) is fucked

This dude was on Snapchat sending people pictures of him with stacks of money, expensive hotels, jewelry, etc.

My Brother in Christ, they've got you dead to rights because of your flexing. You're going to do 40 years in prison now, 20 years if you beg for forgiveness. Why did you flex on Snapchat?

When he's released from prison he's going to be 40 years old (if he's lucky) and all of his Telegram homies are going to be gone. Telegram, Discord, Snapchat, etc may not even exist anymore.

Think of how much changes in 20 to 40 years. Now imagine that time being passed while sitting in a box with all white walls and steel bars.

Читать полностью…

vx-underground

Hello,

I continue to receive requests to make the malware collection static HTML like it was from 2019 - 2023.

While I too like and prefer static HTML, VXUG is very large in scope and has many moving parts.

As of July 2nd, 2026, VXUG has:
- 233,151 files
- 38,212 sub-directories
- 13.1TB 7z ultra compressed

Do you have any idea how large and nested these HTML files would be?

Читать полностью…

vx-underground

old head nerds will DM me telling me they used to squeeze a fart out their ass cheeks to make a free call to japan in 1969 (it was a perfect 2600-hertz tone)

wtf am i supposed to do with this info bro

Читать полностью…

vx-underground

I lied, I'm not a healthcare professional. But still, the larp is crazy

Читать полностью…

vx-underground

This is the photo that is all over social media and distributed from the government (or something, I can't recall the details, but it's the photo being used).

Читать полностью…

vx-underground

I keep seeing large tech companies discussing the dangers of AI and AI models. They think regular people should not be able to possess AI or AI models, or be able to run them on home computers. In essence, they're too dangerous for a regular person to possess.

It is for our safety that Google, Meta, OpenAI, Anthropic, Palantir, X, etc have AI models but we don't. They are protecting us by paying them $19.99/month. If we don't let them control the AI stuff then someone could do bad things with it.

They care about protecting the people. They are definitely not doing it to make more money and collect more data from consumers. Large tech companies would not use their money to influence politicians and government to make more money and fearmonger

Читать полностью…

vx-underground

HOLY SHIT

If you leave in the Eastern part of the United States, call into work today because it's NUCLEAR WINTER.

Fuck a sweater, buy a lead vest IMMEDIATELY. It's -184f IN JULY

Читать полностью…

vx-underground

Chat, I don't want to sound like a hater, but I think this meteorologist is using AI. Something about the image seems incorrect.

Читать полностью…

vx-underground

tl;dr
really effective malware multi-staged, multiple programming languages, use as many dependencies as possible. AI making this easier to do. AVs struggling

Historically, in regards to malware development, the end goal was minimalism. It was in your best interest to strip as many dependencies, shred the file size down, and make it position independent.

I think, as of ... now ... we need to take a different approach.

I think instead of stripping binaries, we (Red Team, Threat Emulation, malware developers) should intentionally introduce dependencies.

I have witnesses two unique things in the malware landscape since the AI boom.

1. Increase in malware slop. I continue to see stagers which contain notes in them. This is not intentional and this does not "trick" the analyst. This is a colossal mistake on the malware developers part. However, despite it being slop, AI has made malware more diverse. I am seeing more and more malware in Lua, Node JS (including SEA and nexe), Java, and Python. I am seeing more and more malware doing inter-process communication across multiple programming languages. Of course all of these have existed prior to AI, but I am seeing an explosion in these languages. This also has resulted in malware researchers creating new tools to combat this malware diversity.

2. Anti-malware services struggling. When I encounter a binary that is a Node JS SEA blob (Electron JS .exe, self-contained using SEA), which extracts a .JS payload, which uses obfuscated Java or heavily obfuscated Lua, all of these languages require a VM (PVM, LVM, JVM, whatever) for interpretation. Thus, with heavy obfuscation and multistaging, static analysis fails and the heavy abstraction makes it difficult for traditional hooking or minifilters to be effective, in essence there is too much noise. Many of these payloads with heavy dependencies easily avoid static analysis and even some emulation systems because they fail to account for the necessary dependencies which are required to emulate it correctly.

pic maybe related idk

Читать полностью…

vx-underground

the stager gives you a apple applescript thingy. its not obfuscated. its just the raw src code.

i uploaded to vt, but here is the goopus (free malware source code)

https://gist.github.com/vxunderground/a211579dc084f2e430d7f0dda424bf14

Читать полностью…

vx-underground

THEYRE PREVENTING THE PEOPLE FROM GETTING MALWARE!!!!!!

Читать полностью…
Subscribe to a channel