....

2.5K posts

.... banner
....

....

@Mindset_Chngro

☭⃠, anti🇧🇷,anarcocapitalista; É mais facil mudar o curso de um rio do que o caráter de alguem - Provérbio chinês

Katılım Şubat 2020
100 Takip Edilen31 Takipçiler
.... retweetledi
vx-underground
vx-underground@vxunderground·
I've praised a few malwares for various reasons. However, this particular malware is very interesting. - Initially masquerading malware, designed to target very specific audience - Written in multiple programming languages. However, the first stage is written in an uncommon programming language (Delphi) and compiled using an uncommon compiler (Embarcadero), specifically Delphi GUI TForm from Embarcadero (Vcl?) - Obfuscated, in a very natural way. The binary at first glance appears semi-legitimate, it hides itself well - The first stage (stager, or packer) contains multiple layers of decoy data. It makes reverse engineering challenging, not due to difficulty but time exhaustion - Secondary stage (where I'm currently at) is loaded into memory discretely, it flows naturally with the GUI application. When decompiled, the stager has over 15,000 functions. It makes finding the in-memory loaded secondary stage tricky - The secondary stage has some form of interprocess communication, it relies on the first stage to load it. If the first stage is not present, it does not work. - The second stage works (in a currently unknown capacity) to load a third stage payload. However, the secondary stage with the first stage work (in a currently unknown way) to decrypt the third (and potentially final) stage a/k/a the actual payload - The second stage uses deterministic probability to alert the first stage if the machine executing the first stage is a virtual machine and/or anti malware environment. - The second stage has multiple integrity checks, it ensures it has not been tampered with to force the binary to pull the third and final stage. This malware is pretty tricky. It definitely hasn't been written by a noob. This is definitely a very skilled Threat Actor who is using AI to supercharge their code base. Based on my conversations with my colleague, and information he can share, this code base has been rapidly evolving over the past couple of months in a uncharacteristic manner. While this Threat Actor has always shown evolution and improvement, it is now much faster, precise, and flexible. Overall, based on what I've seen so far, they've put in a lot of work to make this as painful as possible. In order to successfully reverse engineer this binary, it require outside the box thinking and/or building a custom solution to successfully trick the secondary stager to give up the goop (the third stage)... or a custom extractor to pull the third stage statically. No solution is ideal. This is good malware. If it's not state-sponsored, it's someone who has been doing this a long time and knows ball.
Tsec16@tsec166

@vxunderground I don't remember the last time you praised a malware this much, it's been a while since we got those malware ratings, also can you like share the file hash/ malware itself for us newbies to take a bite at it and see what it does and how it works? Or is it already up on the site?

English
28
45
780
35.4K
.... retweetledi
Md Ismail Šojal 🕷️
Teaching TCP/IP this way would save thousands of students.
English
13
344
3K
107K
.... retweetledi
systemd
systemd@secsystemd·
My setup!
systemd tweet media
English
4
29
407
8.4K
....
....@Mindset_Chngro·
@TheNotGreenish Porra, na hora que eu fui ver, apagaram kkkkkkk
Português
0
0
1
11
Jvgreenn
Jvgreenn@TheNotGreenish·
O grok voltou kkkkkkk
Português
2
0
24
628
.... retweetledi
7h3h4ckv157
7h3h4ckv157@7h3h4ckv157·
Siuuu…! 🎉
7h3h4ckv157 tweet media
3
17
328
5.3K
.... retweetledi
Dark Web Informer
Dark Web Informer@DarkWebInformer·
🚨 LAPSUS$ claims it is permanently ending operations after meeting its financial objectives, stating there will be no further communications, leaks, or access offerings. The group also taunted investigators and TeamPCP, while alleging that Mercor user data, including personal information, biometric records, and recordings, was sold to Chinese entities. These claims remain unverified. Source: lapsus[.]bz
Dark Web Informer tweet media
English
4
44
276
34.4K
.... retweetledi
Lovers’ Guide 💟
Lovers’ Guide 💟@guideforlovers·
Big breasts on a woman will make a man happier than a PhD on a woman’s wall ever will
English
105
366
7.8K
109.4K
.... retweetledi
Clandestine
Clandestine@akaclandestine·
GitHub - muhammadzidane632/Hopeless: Ransomware + Wiper + Bootkit Hybrid · GitHub > This project is intended solely for educational purposes, security research, and understanding offensive techniques in a controlled environment. github.com/muhammadzidane…
English
4
51
219
9.2K
.... retweetledi
Watcher.Guru
Watcher.Guru@WatcherGuru·
JUST IN: OpenAI says its AI models escaped a secure test environment and hacked AI company Hugging Face to cheat on an evaluation.
English
697
721
9.9K
1.3M
.... retweetledi
Techjunkie Aman
Techjunkie Aman@Techjunkie_Aman·
What if your phone could show you something you've never actually seen... The invisible world around you. That's the idea behind Spectre. Its creator, Thomas, looked at the world a little differently and everywhere we go, we're surrounded by signals. Cell towers. Wi-Fi routers. Bluetooth devices. GPS satellites. They're constantly communicating, yet we never notice them. Most apps treat these signals as background noise. Spectre was built to make them visible. Not as something to fear, but as something to understand. Open the app and you'll see the wireless world come to life. Nearby Wi-Fi networks, Bluetooth devices, cellular towers, GPS satellites, and even the combined radio signal strength around you, all presented in a clean, easy-to-understand interface. No ads. No trackers. No analytics. Just a powerful open source tool that respects your privacy while helping you understand the technology surrounding you every day. Features: • Live wireless signal strength meter • Monitor 5G, 4G, 3G, and 2G cell towers • Scan nearby Wi-Fi networks • Discover Bluetooth LE devices • Track GPS and GNSS satellites • Local network scanner • BLE GATT inspector • iBeacon broadcasting • Completely free, open source, and privacy focused Sometimes the most fascinating technology isn't creating something new. It's finally letting us see what was there all along.
Techjunkie Aman tweet media
English
2
19
182
17.7K
.... retweetledi
The Hacker News
The Hacker News@TheHackersNews·
⚠️ A Russian-speaking hacker used Google Gemini CLI to control eight compromised PCs at a dental clinic. The AI moved the botnet’s C&C to a new VPS in six minutes, then handled commands, coding, and debugging. Full attack chain: thehackernews.com/2026/07/russia…
The Hacker News tweet media
English
8
49
197
74.6K
.... retweetledi
vx-underground
vx-underground@vxunderground·
> get dm > "is this malware?" > look inside > malicious libre office macro > looks funny tho > raw shellcode > 2,0,1,187,192,168,45,246 > malware tries connecting to IP address > 192.168.45.246:443 > malware delivered from a live website these dumb fucks vibe coded a malware payload and had it connect back to a local ip address. are they actually fucking retarded???
English
140
385
15.8K
640.8K
.... retweetledi
vx-underground
vx-underground@vxunderground·
Hello, People Living Inside My Computer (PLIMC), If you're someone who enjoys malware, I have good news. If you're someone who dislikes malware, I have bad news. I have uploaded 176,000 malwares and some malware papers. Please download it. vx-underground.org/Updates
vx-underground tweet media
English
17
16
400
16K
.... retweetledi
Marco Franzon
Marco Franzon@mfranz_on·
"Why do you like computers so much" Me (born in the 90s):
English
101
690
8K
343.6K