Register and share your invite link to earn from video plays and referrals.

vx-underground
@vxunderground
The largest collection of malware source code, samples, and papers on the internet. Password: infected
369 Following    443.5K Followers
Some dork on Instagram is accusing me of being behind the whole Mecca Chameleon steam malware thingie and says @IntCyberDigest labeled me the criminal, or something, I don't know. I'm not even mad they called me a criminal, I'm mad they would accuse me of making weak malware. I've got a family now, I'm basically a born again Christian, I drive the speed limit, wear socks with sandals, and tuck my shirt into my cargo shorts. I don't do anything even close to illegal. However, if I was going to switch it up and become a full fledged Threat Actor, I am NOT going to do something half-baked like this Mecca Chameleon thing, I'm going to develop an information stealer, partially AI generated, written in like five different programming languages, and storing the payload on something goofy like a Billie Eilish instagram comment. Then I am going to sell it online on some place like Tier1 and deal strictly in XMR. I am insulted you would think I would stoop so low to do something like a malicious Steam game (or hijack).
Show more
0
43
1.2K
33
Forward to community
FREE THEM. THEY DID NOTHING WRONG
❗️ The world's biggest anime piracy site HiAnime's suspected operators have been arrested in Vietnam. Vietnamese police say the group ran 100+ piracy sites since 2020, uploaded 26,000+ films, and pulled in roughly $12.85 million in ad revenue. Four suspects are in custody; three are under travel restrictions. The arrests follow a multi-year investigation supported by US Homeland Security Investigations, the DOJ, and anti-piracy coalition ACE.
Show more
A lot of malware campaigns use CloudFlare to mask their C2 infrastructure. They do this for a few reasons, but the primary reason is that it delays the inevitable of their C2 being taken down. The malware developers using CloudFlare isn't necessarily bad, and it isn't necessarily good, it's just a known thing that people abuse. Yes, CloudFlare did their job. CloudFlare takes down malware infrastructure a lot, despite people saying CloudFlare doesn't take any action, because CloudFlare is inundated with both legitimate and illegitimate takedown requests and reports daily. The daily reports they receive are (probably) in the millions daily. If they didn't want to hide behind CloudFlare, the malware developers could also have used a compromised website (very common), or Discord, or Google docs, or Spotify, or ... basically pick a website and service and it can be abused with enough elbow grease. The easiest, fastest, and easily configurable method is generic host with CloudFlare. When the domain is taken down, or CloudFlare takes it down, they simple spin up new infrastructure with a new CloudFlare account and operations resume as normal.
Show more
@vxunderground @Cloudflare So basically, what you’re saying is that Cloudflare did their job? Or that the malware authors are shit? What should the malware authors have done instead? 🤔💭
I'm on the weird part of the internet reading about Termite microbiomes Now I'm frustrated scientists haven't conducted more research into biotechnologies that allow humans to extract nutrition from woody stuff like lignin tldr why science man no let us eat wood wtf
Show more
Chat, today is a good day. Look at this "Grand Theft Auto 6 BETA for FREE" advertisement that fell onto my lap. It delivers a .rar that has a .exe inside. I am so happy. I am elated. It is free malware.
Show more
We're slowly convincing the youth to autismmax via silly pictures of cats.
The United States is 250 years old. To celebrate this occasion, we will be giving everyone two hundred and fifty (250) malwares. God Bless
0
32
1.3K
46
Forward to community
Doctor: Take this medicine at night to help you sleep Me: Okay Doctor: Oh, and by the way, if you have a sudden erection which is painful and won't go away, it's from the medicine. Immediately seek medical attention. Go the Emergency Room Me: Okay
Show more
0
38
1.9K
28
Forward to community
Honestly, if you're wanting to get into malware development and malware reverse engineering (specifically in regards to Windows), I think the most important thing you can learn is the concept of a file. 1. What is a file extension? This is pretty obvious, .exe, .pdf, .mp3, etc. 2. How are file extensions handled? This would introduce the idea of the Windows registry and how extension querying is handled vs. the Windows loader 3. Which file extensions (or file types, rather) are used for payload delivery? e.g. .exe, .dll, .xll, .vbs, .ps1, .py, .lua, .docx, .vcproj, etc. The .exe, .dll, (and other native types, like .sys) will be sort of self-explanatory, but the others would introduce different malware delivery mechanisms (malicious files) and potentially wiggle in the concept of payload smuggling. 4. Each of the previous listed file types are different. How are they different? .exe and .dll (and many others) are native to Windows and handled by the Windows loader. Why are the others still considered executable files? This is when you slowly step into interpretive languages and VM dependency (JVM, PVM, etc). Somewhere in this you would eventually stumble into the Windows PE format, how the PE format is different for .NET binaries, how Electron .JS executables act differently, weird stuff like .docx file internals, etc. Basically, I think understanding files and how they're handled is an excellent starting point and sets the stage for what will happen next. pic unrelated
Show more
0
42
2.4K
133
Forward to community
Still thinking about the time I went to BestBuy. I was in a pinch and needed to buy some computer stuff fast. The guy behind the counter tried making an up-sale and pitched me some anti-virus product. He said it's good and protects you from viruses I looked him straight in his eyes and said, "What? But I want the computer viruses on my computer" He looked right back at me and just said "Okay". He looked at me like this:
Show more
0
36
1.9K
48
Forward to community
Dawg, the Peter Stokes affadavit (nerd from Scattered Spider who was arrested) is fucked This dude was on Snapchat sending people pictures of him with stacks of money, expensive hotels, jewelry, etc. My Brother in Christ, they've got you dead to rights because of your flexing. You're going to do 40 years in prison now, 20 years if you beg for forgiveness. Why did you flex on Snapchat? When he's released from prison he's going to be 40 years old (if he's lucky) and all of his Telegram homies are going to be gone. Telegram, Discord, Snapchat, etc may not even exist anymore. Think of how much changes in 20 to 40 years. Now imagine that time being passed while sitting in a box with all white walls and steel bars.
Show more
"hey smelly, out of curiosity, how did you learn so much? have you read every paper on vxug?" fuck no. i probably havent read 10% of the library. if you unironically read everything there you would be two things 1. ultra mega fuck off malware brain 2. profoundly depressed
Show more
Hello, I continue to receive requests to make the malware collection static HTML like it was from 2019 - 2023. While I too like and prefer static HTML, VXUG is very large in scope and has many moving parts. As of July 2nd, 2026, VXUG has: - 233,151 files - 38,212 sub-directories - 13.1TB 7z ultra compressed Do you have any idea how large and nested these HTML files would be?
Show more
Someone just sent me this You're all a bunch of god damn hooligans