TGViewer
Channel Public Channel
vx-underground

vx-underground

@vxunderground

The largest collection of malware source, samples, and papers on the internet.

Password: infected

https://vx-underground.org/
Subscribers
52.2K
Photos
4.6K
Videos
505
Links
1.6K
Recent Posts 20 shown
Post #9458 3.21K
vx-underground Yeah, so I decided to check out the Steam goop people were DMing me about. Basically there is something called People's Playground (I have no idea what that is) and they started discussing a malicious Steam mod thingie surrounding it. However, the malware…
Write-up which is factually accurate and cool

https://studiominus.nl/ppg-september-incident/red_analysis.html
studiominus.nl People Playground Workshop Malware Analysis: FPS++++ Worm Breakdown Detailed technical analysis of the People Playground Steam Workshop malware worm (FPS++++). Explore its execution control flow, propagation, and payload breakdown.
  • ❤‍🔥 35
  • ❤ 4
  • 👍 2
  • 😢 1
Post #9457 3.09K
Yeah, so I decided to check out the Steam goop people were DMing me about.

Basically there is something called People's Playground (I have no idea what that is) and they started discussing a malicious Steam mod thingie surrounding it. However, the malware is not specific to them but is a much more broad issue.

Interestingly, this is a Steam mod worm. I have never seen anything like this before. I found it very silly.

What I did not find silly, and I actually found it very ... confusing ... was the payload in all of this. Once this Steam worm thingie is detonated on your machine it

- Deletes browser cookies (???)
- Deletes photos from "MyPictures" on Windows
- Deletes videos from "MyVideos" on Windows
- Tries to "destroy" Steam friends, apps, etc

Throughout the entire payload I was looking for something else, like data exfiltration, or a broader malware campaign, ... but all this does is try to fuck up Steam, delete gunk off your computer, and then self-spreads by making the Steam user publish a mod.

Some gamer nerd guy person did a write-up on it. I'll link it. I verified everything they wrote and they're correct on it.

I just don't get it though. This guy could have had a semi-successful information stealer campaign, or pay-per-install campaign, ... or crypto theft, ... or anything. but all it does is fuck up your Steam locally.

Like, all you need to do is reinstall Steam. I don't understand.
  • 🤣 62
  • ❤‍🔥 19
  • ❤ 8
  • 😢 1
Post #9456 3.95K
vx-underground Big news for malware enthusiasts: I've uploaded an additional 170,000+ malwares to the internet Bigger news for silly pictures of cats enthusiasts: I've attached one to this post
My bad, I forgot to attach the upload log thingie

https://vx-underground.org/Updates
  • 🥰 55
  • 🤓 14
  • 🙏 4
  • ❤ 1
  • 😢 1
Post #9455 4.01K
Big news for malware enthusiasts: I've uploaded an additional 170,000+ malwares to the internet

Bigger news for silly pictures of cats enthusiasts: I've attached one to this post
  • 🤩 105
  • ❤ 52
  • 🔥 4
  • 🙏 4
  • 😁 3
  • 👍 1
  • 😢 1
  • 🤝 1
Post #9454 4.7K
Hello, Little People Living Inside My Computer,

I have made a YouTube account to discuss malware reverse engineering and development. It will primarily target noobs. It will be lighthearted, poorly produced, and spontaneous.

https://www.youtube.com/@MalwareForFun
  • ❤ 216
  • 🤔 19
  • 🎉 13
  • 🤓 9
  • ❤‍🔥 8
  • 🥰 4
  • 💯 2
  • 😢 1
Post #9453 5.21K
> "Two sources familiar with the matter ..."

Dawg, they defaced the fucking FBIs website and published a letter online THREATENING THEM. They're EXTORTING the United States government.

Only TWO sources??? 99% of cybersecurity nerds have seen the letter. But .. TWO SOURCES???
  • 🤣 199
  • ❤ 12
  • 😁 11
  • 🤓 5
  • 🎉 1
Post #9452 6.63K
vx-underground fbi job portal defaced and compromised? oh yeah, it's a silly tuesday
crime is illegal and for nerds. this is bad and it is criminal. don't compromise the fbi and extort them. that is bad
  • 🤣 180
  • 🤓 33
  • ❤ 21
  • 🤔 4
  • 😱 4
  • 🤯 3
  • 😢 3
  • 👍 2
  • 🎉 1
Post #9451 11.7K
fbi job portal defaced and compromised? oh yeah, it's a silly tuesday
  • 🤣 214
  • ❤ 33
  • 🔥 14
  • 🎉 9
  • 🥰 8
  • 😍 2
  • 😢 1
Post #9450 6.32K
> wake up
> take a shit
> get out of bed
> get on computer
> check xitter
> pornography all over timeline
> ???
> wtf i dont horny on xitter
> realize reposts
> colleague horny posting on main
  • 🤣 248
  • ❤ 19
  • 😍 10
  • ❤‍🔥 9
  • 🥰 6
  • 🎉 3
  • 🤔 2
  • 😱 2
  • 😢 2
Post #9449 6.22K
vx-underground Seeing a lot of people online discussing the rapidly rising cost of gasoline due to some made up place called Bab El Mandeb and Hormuz. I'll give you a pro tip to save a few bucks at the pump: credit card fraud You're welcome
For the record this is a joke. Do not commit identity theft. That is very bad. Crime is bad and illegal
  • 🤓 112
  • 🤣 36
  • 👍 12
  • 😢 7
  • 🎉 5
  • 🤝 4
  • ❤ 1
  • 🤯 1
  • 😱 1
  • 😇 1
  • 🫡 1
Post #9448 6.26K
Seeing a lot of people online discussing the rapidly rising cost of gasoline due to some made up place called Bab El Mandeb and Hormuz.

I'll give you a pro tip to save a few bucks at the pump: credit card fraud

You're welcome
  • ❤ 99
  • 🤣 79
  • 💯 10
  • 🔥 8
  • 🥰 5
  • 😁 4
  • 🤯 3
  • 🎉 2
  • 😇 2
Post #9447 6.33K
Chat, you're never going to believe it.

Over the weekend I visited a family members child's birthday party.

Fast forward approx. 48 hours and I am sick.

Who could have imagined a dozen children would have been a vector for disease?
  • 🤣 189
  • 😢 23
  • ❤‍🔥 10
  • ❤ 7
  • 👍 6
  • 🤓 6
  • 🤯 3
  • 😁 2
  • 🎉 2
  • 💯 1
Post #9446 6.69K
I'm "done" with the first video. I ended up substantially trimming it down and, per some feedback I received, focusing more on the secondary in-memory payload.

It has taken me little over a week to make a video on a malware payload which would normally would only take me like... 30 minutes (or less)

I can't spend over a week discussing a fairly common Malware-as-a-Service payload. I also don't have time to discuss Lumma internals. I initially planned on it, but it's too much for me at the moment.

We have more malware to bonk with a stick.

This is a "demo" run of me bonking malware with a stick videos. I'm weighing on whether or not I want to continue producing videos. It is fun, however it considerably slows me down on other malware thingies I want to look at it.

I dunno.

Here is the final cut:
  • ❤ 204
  • 🔥 34
  • 😢 7
  • 🥰 6
  • 👍 4
  • ❤‍🔥 2
Post #9445 10.2K
  • 🤣 335
  • ❤ 14
  • 😢 9
  • 😁 5
  • ❤‍🔥 2
  • 🥰 2
  • 👏 2
  • 🤔 2
  • 🎉 2
  • 💯 2
  • 🤓 2
Post #9444 9.81K
Behind the scenes update on malware reverse engineering explained for noobs.

We're at the 16 minute marker and we've got quite a bit ways to go. This video will probably be 30 minutes or longer when it's done.
  • ❤ 164
  • ❤‍🔥 30
  • 🔥 15
  • 😢 3
  • 👍 2
  • 😎 2
Post #9443 9.39K
Randomly remembered when RaidForums got taken down and tons of similar forums appeared to try to fill the vacuum.

One of the first to appear was kkkforum.

The creators were from Brazil, and in Brazil "kkk" essentially means "lol". They didn't realize "kkk" meant something else for native English speakers
  • 😁 133
  • 🤣 67
  • ❤ 10
  • 🤔 5
  • 💯 4
  • 😱 2
  • 🎉 2
  • 😢 1
Post #9442 9.01K
You're all a bunch of God damn degenerates and you CANNOT be trusted.

I asked if anyone had any video requests (implying the subject would be malware), because I'm beginning to find video creation kind of fun, and everyone immediately just starts talking about making videos about femboys and documentaries about cats

I don't even know why I ask you stinky nerds anything

Pic unrelated
  • 🤣 180
  • ❤ 33
  • 😁 11
  • 🎉 4
  • 😱 3
  • 🥰 2
  • 😇 1
Post #9440 8.65K
vx-underground Yes, I see your messages. I am still working on the malware bonking video. Making a bonking video is extremely time consuming because I have to take pictures (or videos) of everything, schizo rant into a microphone, and document everything without getting…
I guess it's also possible the resource section segment is decoy data, I haven't finished bonking this with a stick, I'm literally just documenting it as I go. It is as much a mystery to me as it is you (I have no idea what's going on)
  • ❤ 72
  • 🤝 9
  • 👏 1
  • 😢 1
Post #9439 8.63K
Yes, I see your messages. I am still working on the malware bonking video. Making a bonking video is extremely time consuming because I have to take pictures (or videos) of everything, schizo rant into a microphone, and document everything without getting overly technical.

I literally just read a random DM, then started documenting my entire bonking routine. This bonking could have been done in like, 30 minutes probably, I don't know, but making it a video out of it has taken me HOURS.

I am nowhere near complete, and it needs refinement, but if you seriously want to see what I've created over the past couple of days here it is:
  • ❤ 187
  • 👏 19
  • ❤‍🔥 9
  • 🔥 6
  • 🤣 4
  • 👍 3
  • 🤯 3
  • 🥰 2
  • 😢 2
Post #9438 7.52K
For several months now I've been slowly, but surely, working behind the scenes to dramatically enhance vx-underground.

I still don't have a definitive timeline, but I would like to share some stuff coming.

1. All source code will be moved from GitHub to vx-underground. The new vx-underground will have functionality to search through code bases by keywords for research, filter by language type, yada yada yada.

2. Enhanced malware paper searching. It'll be easier to search for stuff now.

3. API access to verified individuals. This is designed for researchers, or organizations, who may want the ability to perform large downloads programmatically.

4. Paid tier. vx-underground will remain free for everyone. However, if you're an organization which makes more than $1,000,000/year you will have to pay for some functionality (malware sample API downloads). I will not charge thousands of dollars, I'm not greedy, but some of you large companies are jerks and need to pay up for scraping the site for AI and samples. API access will be free for individual researchers, small businesses, students, non-profits, and government institutions. Unfortunately, I've learned the hard way large for-profit organizations will not donate.

5. I've heard your complaints for YEARS. We are looking for a HTML-only vx-underground implementation, probably as a subdomain or something. I'm well aware you hardcore nerds hate JavaScript. I will continue investigating this.

6. We're working on our 4th book, Black Mass Volume IV.

I have more to announce, but some details are still up in the air. These changes likely won't appear until ... I don't know, bro. I've got a full time job and a family. I'm thinking probably late 2026, early 2027.

Thank you to our donors and sponsors that make this possible. I'm not as speedy as I used to be with updates, but I'm still cooking.

Cheers
-smelly
  • ❤ 192
  • ❤‍🔥 45
  • 🔥 13
  • 👍 11
  • 🫡 8
  • 🤯 2
  • 😱 1
  • 😢 1
  • 💯 1
Older posts →

About this channel

How can I read @vxunderground without a Telegram account?
TGViewer shows the public web preview Telegram publishes for vx-underground: recent posts, photos, videos and the subscriber count, with no app, login or account.
How many subscribers does vx-underground have?
vx-underground (@vxunderground) has 52.2K subscribers on Telegram, refreshed roughly every 30 minutes.
Does vx-underground know I viewed it here?
No. Public channel previews carry no viewer identity, and TGViewer has no accounts or tracking of what you look up.
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →