vx-underground (automated mirror)

@vxundergroundre.bsky.social

The largest collection of malware source code, samples, and papers on the internet. Password: infected (unofficial, this is a bot! Maintained by a private individual, the bot can't handle retweets or replies, support soonish)

Hello, One of my colleagues is looking for a job. She is a smart lady. Unfortunately, she does not do malware stuff (no idea why), she is searching for a job doing one of the following: - SecOps Leadership - IR Leadership - SOC Leadership - Security Awareness Leadership - CTI What do

Bild

The fundamental problem with this "hack" is it requires three things being true. 1. An attacker must possess the device 2. An attacker must be able to unlock the cell phone 3. The cell phone must be "rooted", all additional cell phone security already bypassed In the event all three of

Big drama in the EU today. I'm not a mobile device security nerd, so I can't comment too much. However, it seems extremely odd all configurations (including the "encrypted pin") are stored in a .xml file. Mobile nerds, ... is this standard practice? Or did the EU make an incredibly poor

Yeah, so basically I'm trying to make my own "ClickFix" but for Windows binaries by abusing the Windows Runtime, Component Object Model, and whatever Windows grants me from a limited user profile (see attached image) I saw some research on Windows Toast Notifications by @ipurple, but

Bild

Say what you want about TeamPCP, but they have certainly made attribution much easier. I can't recall a time a Threat Group specified the malware campaign and malware delivery mechanism that resulted in a compromise. Is TeamPCP lying about how how they compromised these organizations?

Bild

A long, long, long time ago I read a paper on how the United States Central Intelligence Agency intentionally introduced conflict, distrust, and resentment into the inner circle of Julian Assange. Being unable to physically touch him, they had hoped if they made his life chaotic enough

Bild

Final post about the RockStar Games compromise because (as I have now learned) there are a lot of people who are extremely passionate about RockStar Games. ShinyHunters extortion group successfully compromised RockStar Games through a third-party vendor called "Anodot". Anodot is used

Sweet baby Jesus, the RockStar Games nerds are going spazzo online. I'm not a RockStar Game nerd, I don't really care about GTA V or GTA V Online, but because nerds won't shut up: First documented sale: DATE: 2014-11-12 PLATFORM: Xbox One REGION: Asia E: BULL TOTAL: $9.99 Last updated

Over 200 media outlets are blocking Internet Archive. Media outlets say because AI, or something, but also (and TOTALLY UNRELATED) since they're blocking Internet Archive there is no way to tell if the government or media outlet has deleted or change something. However, they say this is

This is very good malware. This is solid-solid-SOLID B+ malware, very close to A- malware. APT37 is using a old-school playbook. They're doing EPO (Entry Point Obfuscation) on a self-delivered binary for evasion. They also unironically are using something akin to cavity infection ...

THE CIA USED WHAT TO SEND MESSAGES I thought this was bullshit, NSO Group was supposed to be blacklisted by the United States Department of Commerce. But upon investigation, L3Harris purchased a controlling power of NSO Group and the Trump administrations former Israel Ambassador now