
vx-underground
@vxunderground • 437,177 subscribers
The largest collection of malware source code, samples, and papers on the internet. Password: infected
Shorts
Videos

Did your slop Python script accidentally transfer $10,000,000 to a stranger? Did your vibe coded app accidentally leaked 300,000 peoples phone numbers, e-mail addresses, and passport? Don't worry, fam. The folks over there at ... Corgi ... now provide AI insurance.
vx-underground120,769 просмотров • 29 дней назад

I don't care what those nerds at Kaspersky say, I stand by my opinion STX Rat is a solid B- malware. Yeah, the cpuid-dot-com operation was a gigantic fumble, but the malware is pretty neat, far superior to the generic crimeware you find online. I'm happy LTT included the cat
vx-underground113,264 просмотров • 1 месяц назад

Toronto Police launched Project Lighthouse in November, 2025 after police were tipped off about an unknown person(s) operating an SMS Blaster in downtown Toronto. Watch the video for an actual explanation. The fancy Detective lady gives a run down on what happened. tl;dr three chinese dudes some how built a custom made portable cell phone tower thingie in a van, drove around toronto with it. peoples cell phones automagically connected it to (its literally a cell phone tower thingie). when a cell phone connected to their portable cell tower thingie it would automatically send the connected phone a text which appeared to be from their bank or somewhere important. they interupted real cell phone towers 13m times lmfao. they were trying to steal passwords and stuff. no details released on how three random nerds managed to do this
vx-underground75,249 просмотров • 1 месяц назад

A woman's rant is going semi-viral in political circles on Twitter and Facebook. Some are citing her rant as evidence of potential electoral interference during the 2024 Presidential election. The woman's opening remarks claim she possesses a CCIE (Cisco Certified Internetwork Expert) — a very prestigious certification which is often possessed by truly dedicated people. Currently there are only 45,000 active CCIE holders worldwide. Only 3% of Cisco cert holders attempt it ... and only 26% pass — it has a 74% failure rate. Now it should be stated that no one in our group possesses a CCIE. We do not claim to be network experts, we're just malware nerds. However, despite our lackluster understanding of networking (beyond the computer science basics of the OSI model), we can confidently say this woman does not possess a CCIE and we believe she is lying. Additionally, we would like to note we did indeed watch this entire video. Despite this woman's jargon and clear ... plainly wrong information... we decided to give her a chance to speak her mind and opinion. We do not recommend watching the entire 8 minute video. You will have no benefit from it. At roughly 4 minutes you will see, very clearly, this is not a technical person.
vx-underground636,504 просмотров • 1 год назад

Yesterday a video game streamer named rastaland.TV inadvertently livestreamed themselves being a victim of a cryptodraining campaign. This particular spearphishing campaign is extraordinarily heinous because RastaLand is suffering from Stage-4 Sarcoma and is actively seeking donations for their cancer treatment. They lost $30,000 of the money which was designated for their cancer treatment. In the steam clip their friend tries to console them while they cry out, "I am broken now." They were contacted by an unknown person who requested they play their video game demo (downloadable from Steam). In exchange for RastaLand playing their video game demo on stream, they would financially compensate them. Unfortunately, the Steam game was actually a cryptodrainer masquerading as a legitimate video game.
vx-underground260,258 просмотров • 8 месяцев назад

This video is all over social media right now. This is a VERY silly video. I audibly laughed out loud several times. Elon Musk and co. are not experts in DFIR (Digital Forensics and Incident Response). No matter how much of a sycophant you are for him or his organizations, Musk has no background in malware reverse engineering, identification, or development. What I suspect Kristi Noem is referring to in this conversation is the installation of an EDR (Endpoint Detection and Response) system. An EDR is basically an anti-virus that a system administrator can make rules for, add custom detection logic, etc. This is used in enterprise environments and installed on user managed endpoints (computers, electronic devices). Some people worry about EDRs because they monitor the device for any potential malware or compromise. Yes, EDRs can be incredibly invasive, but you should not expect privacy when using company equipment or government devices. The reason why I suspect she is referring to an EDR system is she states, "Elon and his team helped me identify some of my own employees in my department had downloaded software on my phone, and on my laptop, to spy on me, record our meetings, ... they had done that to several other politicals" If an employee, working with the United States Department of Homeland security, was actively working as an Insider Threat and performing ESPIONAGE, spying on politicians and people of power, it would be all over the news. Musk and/or Trump would have been SCREAMING about whoever had done it. Additionally, this would be a VERY serious charge to whoever was identified doing this. It would have been a massive scandal. The second super silly thing Noem says is she complains she was unable to email a PowerPoint presentation to someone because it was too large ("over six pages long"). She is implying here this is a technological problem, but it is NOT. This is done intentionally to prevent data exfiltration. The idea is network administrators put data size restrictions in place to prevent data theft. If someone successfully compromised the United States government, and was unable to steal data by traditional means (tunneling, C2, etc), a common exfiltration tool is email. They take the stolen data, and send it to a disposable email address to receive it. Hence, if they restrict the size of data allowed to be sent outbound, it makes it substantially more difficult for data exfiltration to occur. If a Threat Actor tries to send an email with a large attachment the EDR flags it as a potentially suspicious event and notifies network operations. She is comparing standard cybersecurity policies to ... lack of technology ... ? And also somehow saying this has something to do with the "deep state" (an ominous unidentified threat, or something). Regardless if you believe there is a "deep state" (???), cybersecurity policy and network restrictions are NOT a technological disadvantage. I also want to give a big shoutout to RT (Russian Today) for blasting this all over social media. RT knows this video and conversation is ridiculous. Russian Intelligence is probably giggling right not at the absurdity of it. They are loving the fact they can spit this video all over social media and (using Noems own words) imply the United States government has SPYS actively present from THE DEEP STATE. It sows distrust and misinformation. Bravo, RT.
vx-underground96,424 просмотров • 3 месяцев назад

Cybersecurity classes crazy nowadays. We never learned this stuff
vx-underground326,329 просмотров • 1 год назад

Last time on Dragon Ball Z: The United States government threatened to destroy Iranian critical infrastructure, notably bridges and electrical grids. Today the Iranian government responded by publishing (an incredibly dramatic) video threatening United States tech bros
vx-underground46,500 просмотров • 1 месяц назад
0:51
Sensitive content
This media may contain sensitive content.

Windows 10 support ends October 14th, 2025. It is the calling of the Linux nerds.
vx-underground202,951 просмотров • 1 год назад
0:24
Sensitive content
This media may contain sensitive content.

The vx-underground admin Discord account received a Discord 3rd party breach notification. I thought this was unusual because this account has nothing of value on it. It uses a generic vx-underground e-mail, it doesn't have access to anything, it doesn't have a credit card or any sort of government identification on file. Then I discovered someone (or someones?) submitted 255,620 complaints on the account trying to get it banned. This is strange because this account, as stated previously, literally have NOTHING of value on it. NOTHING. It is just a way for people to contact us. Look at this fuckin' e-mail bro, it was almost 1MB in size.
vx-underground106,209 просмотров • 8 месяцев назад

young man documents himself having difficulties with his graphics card installation
vx-underground226,543 просмотров • 1 год назад