vx-undergroundYeah, so I decided to check out the Steam goop people were DMing me about. Basically there is something called People's Playground (I have no idea what that is) and they started discussing a malicious Steam mod thingie surrounding it. However, the malware…
Yeah, so I decided to check out the Steam goop people were DMing me about.
Basically there is something called People's Playground (I have no idea what that is) and they started discussing a malicious Steam mod thingie surrounding it. However, the malware is not specific to them but is a much more broad issue.
Interestingly, this is a Steam mod worm. I have never seen anything like this before. I found it very silly.
What I did not find silly, and I actually found it very ... confusing ... was the payload in all of this. Once this Steam worm thingie is detonated on your machine it
- Deletes browser cookies (???) - Deletes photos from "MyPictures" on Windows - Deletes videos from "MyVideos" on Windows - Tries to "destroy" Steam friends, apps, etc
Throughout the entire payload I was looking for something else, like data exfiltration, or a broader malware campaign, ... but all this does is try to fuck up Steam, delete gunk off your computer, and then self-spreads by making the Steam user publish a mod.
Some gamer nerd guy person did a write-up on it. I'll link it. I verified everything they wrote and they're correct on it.
I just don't get it though. This guy could have had a semi-successful information stealer campaign, or pay-per-install campaign, ... or crypto theft, ... or anything. but all it does is fuck up your Steam locally.
Like, all you need to do is reinstall Steam. I don't understand.
vx-undergroundBig news for malware enthusiasts: I've uploaded an additional 170,000+ malwares to the internet Bigger news for silly pictures of cats enthusiasts: I've attached one to this post
I have made a YouTube account to discuss malware reverse engineering and development. It will primarily target noobs. It will be lighthearted, poorly produced, and spontaneous.
> wake up > take a shit > get out of bed > get on computer > check xitter > pornography all over timeline > ??? > wtf i dont horny on xitter > realize reposts > colleague horny posting on main
vx-undergroundSeeing a lot of people online discussing the rapidly rising cost of gasoline due to some made up place called Bab El Mandeb and Hormuz. I'll give you a pro tip to save a few bucks at the pump: credit card fraud You're welcome
For the record this is a joke. Do not commit identity theft. That is very bad. Crime is bad and illegal
I'm "done" with the first video. I ended up substantially trimming it down and, per some feedback I received, focusing more on the secondary in-memory payload.
It has taken me little over a week to make a video on a malware payload which would normally would only take me like... 30 minutes (or less)
I can't spend over a week discussing a fairly common Malware-as-a-Service payload. I also don't have time to discuss Lumma internals. I initially planned on it, but it's too much for me at the moment.
We have more malware to bonk with a stick.
This is a "demo" run of me bonking malware with a stick videos. I'm weighing on whether or not I want to continue producing videos. It is fun, however it considerably slows me down on other malware thingies I want to look at it.
You're all a bunch of God damn degenerates and you CANNOT be trusted.
I asked if anyone had any video requests (implying the subject would be malware), because I'm beginning to find video creation kind of fun, and everyone immediately just starts talking about making videos about femboys and documentaries about cats
I don't even know why I ask you stinky nerds anything
vx-undergroundYes, I see your messages. I am still working on the malware bonking video. Making a bonking video is extremely time consuming because I have to take pictures (or videos) of everything, schizo rant into a microphone, and document everything without getting…
I guess it's also possible the resource section segment is decoy data, I haven't finished bonking this with a stick, I'm literally just documenting it as I go. It is as much a mystery to me as it is you (I have no idea what's going on)
Yes, I see your messages. I am still working on the malware bonking video. Making a bonking video is extremely time consuming because I have to take pictures (or videos) of everything, schizo rant into a microphone, and document everything without getting overly technical.
I literally just read a random DM, then started documenting my entire bonking routine. This bonking could have been done in like, 30 minutes probably, I don't know, but making it a video out of it has taken me HOURS.
I am nowhere near complete, and it needs refinement, but if you seriously want to see what I've created over the past couple of days here it is:
For several months now I've been slowly, but surely, working behind the scenes to dramatically enhance vx-underground.
I still don't have a definitive timeline, but I would like to share some stuff coming.
1. All source code will be moved from GitHub to vx-underground. The new vx-underground will have functionality to search through code bases by keywords for research, filter by language type, yada yada yada.
2. Enhanced malware paper searching. It'll be easier to search for stuff now.
3. API access to verified individuals. This is designed for researchers, or organizations, who may want the ability to perform large downloads programmatically.
4. Paid tier. vx-underground will remain free for everyone. However, if you're an organization which makes more than $1,000,000/year you will have to pay for some functionality (malware sample API downloads). I will not charge thousands of dollars, I'm not greedy, but some of you large companies are jerks and need to pay up for scraping the site for AI and samples. API access will be free for individual researchers, small businesses, students, non-profits, and government institutions. Unfortunately, I've learned the hard way large for-profit organizations will not donate.
5. I've heard your complaints for YEARS. We are looking for a HTML-only vx-underground implementation, probably as a subdomain or something. I'm well aware you hardcore nerds hate JavaScript. I will continue investigating this.
6. We're working on our 4th book, Black Mass Volume IV.
I have more to announce, but some details are still up in the air. These changes likely won't appear until ... I don't know, bro. I've got a full time job and a family. I'm thinking probably late 2026, early 2027.
Thank you to our donors and sponsors that make this possible. I'm not as speedy as I used to be with updates, but I'm still cooking.
How can I read @vxunderground without a Telegram account?
TGViewer shows the public web preview Telegram publishes for vx-underground: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does vx-underground have?
vx-underground (@vxunderground) has 52.2K subscribers on Telegram, refreshed roughly every 30 minutes.
Does vx-underground know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.