vx-underground (automated mirror) @vxundergroundre.bsky.social · 17/04/2026Jjaemu will never get mad ever again. 0121
vx-underground (automated mirror) @vxundergroundre.bsky.social · 17/04/2026> popular browser game in japan > brush kitty cat > wtf i love it > play game > lose > get mad > look inside > html iframe > loads index.pck > gdpc header > realize im reverse engineering html game > html game for brushing kitty cat im a loser dawg fr lmfao 1322
vx-underground (automated mirror) @vxundergroundre.bsky.social · 17/04/2026exhausted, crawl into bed, put on weird esoteric youtube videos like elder scrolls lore, dark souls lore, history of religion, or 8 hour long youtube essay 04:00am: wake up randomly from nightmare or panic attack (no idea why), have cigarette to calm nerves 040
vx-underground (automated mirror) @vxundergroundre.bsky.social · 17/04/2026resume working (coding, reversing, reading documentation) 10:00pm: shower? (depends on mood tbh) 11:00pm: extremely hungry, eat random food in house. sometimes have ramen noodles mixed with random canned foods, sometimes order food, sometimes just eat more animal crackers 12:00am: 130
vx-underground (automated mirror) @vxundergroundre.bsky.social · 17/04/2026drinks 04:00pm: brain exhausted, need food, eat giant bag of animal crackers next to desk 04:30pm: frustrated about code, resume working (coding, reversing, reading documentation) 08:30pm: heart palpitations from excessive caffeine, take anti-depressants and sleep medication 09:00pm: 130
vx-underground (automated mirror) @vxundergroundre.bsky.social · 17/04/2026What's it like being a malware researcher? Here is my day. 09:30am: wake up (depends on how bad sleep is) 10:00am: drink energy drink, check news 10:30am: check MISP, see world imploding 11:30am: read random papers from MISP 12:30pm: continue malware research project, chug energy 1170
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026Hello, One of my colleagues is looking for a job. She is a smart lady. She is searching for a job doing one of the following: - SecOps Leadership - IR Leadership - SOC Leadership - Security Awareness Leadership - CTI Please let me know if you anyone is hiring. Thanks. 0218
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026Conversely, my resume is unironically like "lol i like malware and cats and stuff" and it's barely one page. 050
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026these fancy job titles mean? I have no idea. She has a large and comprehensive resume with lots of big words and a Bachelors degree from a large university in the United States (no idea why). Her resume is large, has lots of words, lots of experience, and jammed in two pages. 140
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026Hello, One of my colleagues is looking for a job. She is a smart lady. Unfortunately, she does not do malware stuff (no idea why), she is searching for a job doing one of the following: - SecOps Leadership - IR Leadership - SOC Leadership - Security Awareness Leadership - CTI What do 191
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026give yourself unlimited verifications. 020
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026these conditions are true, you have far greater issues than someone modifying the PIN on your age verification app or... verify they're an adult using your stuff. If you want to do this, for whatever reason, using this you can now reset the PIN on your age verification app arbitrarily or 150
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026The fundamental problem with this "hack" is it requires three things being true. 1. An attacker must possess the device 2. An attacker must be able to unlock the cell phone 3. The cell phone must be "rooted", all additional cell phone security already bypassed In the event all three of 170
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026software design choice? Why is it limited how times you can perform an age verification? But why is that also stored locally in the .xml file? I don't understand 080
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026Big drama in the EU today. I'm not a mobile device security nerd, so I can't comment too much. However, it seems extremely odd all configurations (including the "encrypted pin") are stored in a .xml file. Mobile nerds, ... is this standard practice? Or did the EU make an incredibly poor 193
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026Another zero day exploit released by some nerd (can't remember name right now) because they're annoyed with Microsoft. It's been confirmed by other nerds. It is yet another legit zero day. Whew. 1110
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026the general layout done... it's just typing out the code and debugging. It's tiring. I also planned on stripping the headers and making the binary as lightweight as possible. Why? I have no idea. It is totally unnecessary and ass backward logic. 030
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026Notification callbacks. When "Update" is clicked my binary is notified and appropriate action is taken. Again, this is all totally normal functionality, but it's being used for social engineering. The only caveat here is I am trying to do it as painful and convoluted as possible. I have 120
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026extremely easy. You literally can just specify "button go to website ooga booga" and that's it. Because I couldn't find a URI to execute a binary my only option left is using INotificationActivationCallback. Basically, I have to register my malicious code in the registry to receive Toast 110
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026prevents FILE://, and I can't find a URI to abuse to deliver file execution (I tried). I assume the inability to find a Windows URI to abuse for file execution is why the original authors ended up doing ToastNotification -> ClickFix. Making the Toast Notification go to a web domain is 110
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026RoInitialize (technically CoInitializeEx). In the attached image I've successfully impersonated Windows Security. However, "update" doesn't work the way I'd like to. The easiest thing to do in this scenario is trying to abuse a Windows Scheme URI. Unfortunately, WinRT sandboxes and 110
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026the way Windows wants you to. I said, "well, I've done WinRT in C before, why not do this in C?" Why not make something mildly annoying 200% more difficult? It has been a challenge. I decided to do EVERYTHING with the WinRT / COM. I didn't want to make ANY WinAPI invocations omit 110
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026to do registry entries so Windows knows where to send Toast stuff to. In C# or Powershell this is still relatively simple, just kind of annoying. In C, it still isn't too bad. Unfortunately, I am a person who knows only pain. I didn't want to do C#, or .NET, or do anything with WindowsRT 120
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026well documented for something like C#. Making a simple notification on Windows which impersonates Windows Defender and runs a .exe (or whatever) is pretty shrimple. But.... there is a massive asterisk next to shrimple because it requires some* pain and suffering. In extreme summary, need 110
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026their paper and code was in C# and Powershell. Their technique displayed a fake update and directed the user to a website which then did ClickFix So it's like, WindowsClickFix -> ClickFix I said, "wtf? why not just run program there?" It turns out you can, it's totally possible and 120
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026Yeah, so basically I'm trying to make my own "ClickFix" but for Windows binaries by abusing the Windows Runtime, Component Object Model, and whatever Windows grants me from a limited user profile (see attached image) I saw some research on Windows Toast Notifications by @ipurple, but 190
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026addicted to Phencyclidine a/k/a Angel Dust? Find out on the next action packed episode of Dragon Ball Z 020
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026Is it the result of a different malware campaign? Did they actually steal internet projects and "secrets" from S&P Global? How bad is the Guesty compromise? Will these companies succumb to the ransom demands? What the fuck does PCP stand for in this context? Is TeamPCP suggesting they're 240
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026Say what you want about TeamPCP, but they have certainly made attribution much easier. I can't recall a time a Threat Group specified the malware campaign and malware delivery mechanism that resulted in a compromise. Is TeamPCP lying about how how they compromised these organizations? 280
vx-underground (automated mirror) @vxundergroundre.bsky.social · 16/04/2026Day Two of working on really silly malware proof-of-concept. Is there an easier way to write this code? Yes. Is it worth investing this much effort into? Probably not, no Is it a lot of fun bonking Windows with a stick and reading obscure documentation? Yes Am I a cat? No 1131
vx-underground (automated mirror) @vxundergroundre.bsky.social · 15/04/2026hoping the criminals betray the other criminals, or make an OPSEC mistake 0100
vx-underground (automated mirror) @vxundergroundre.bsky.social · 15/04/2026conflicts with other Threat Actors on forums, chatroom, social media, etc. Ultimately, this conflict does very little for Threat Actors except fog their logic and result in poor decision making. tl;dr I wonder if the FBI unironically just sits there, talking shit, making up fake drama, 1100
vx-underground (automated mirror) @vxundergroundre.bsky.social · 15/04/2026he would commit suicide. Knowing that the CIA will do this... it makes me wonder if the Federal Bureau of Investigation (or other law enforcement agencies) intentionally inject conflict into the circles of Threat Actors. I can't even count how many times I've seen Threat Actors have 180
vx-underground (automated mirror) @vxundergroundre.bsky.social · 15/04/2026A long, long, long time ago I read a paper on how the United States Central Intelligence Agency intentionally introduced conflict, distrust, and resentment into the inner circle of Julian Assange. Being unable to physically touch him, they had hoped if they made his life chaotic enough 1132
vx-underground (automated mirror) @vxundergroundre.bsky.social · 15/04/2026Oh yeah? You're a "hacker"? Prove it. Send a stool sample and a copy of your Birth Certificate to Sam Altman. 1130
vx-underground (automated mirror) @vxundergroundre.bsky.social · 15/04/2026Vulnerable AV drivers from China Did I miss anything or am I good? 060
vx-underground (automated mirror) @vxundergroundre.bsky.social · 15/04/2026malware stuff - Malware AI slop - Booking dot com drama, even though it's been poop forever - More web compromises - Kraken being extorted - GitHub stars as a service - Something about CloudFlare and OpenAI - Something with malicious FireFox extensions - Google hires Philosopher for AI - 1101
vx-underground (automated mirror) @vxundergroundre.bsky.social · 15/04/2026I was pretty busy today. From what I saw when skimming the internet: - More AI hot takes - More laws about age verification - Arguments about age verification - Some cool new malware found - Drama about fake ledger in Apple Store - PUBG CEO used ChatGPT for business advice - More 1122
vx-underground (automated mirror) @vxundergroundre.bsky.social · 14/04/2026Working on some real silly code. Is it special? No. Is it silly? Yes, extremely. 0180
vx-underground (automated mirror) @vxundergroundre.bsky.social · 14/04/2026> ramp up cyber defenses > look inside > change password to include ! > pay for nord vpn (protects from hackers) > re-up norton antivirus subscription > ask 7 year old nephew for help with ipad we are cybersecurityied now dawg 2234
vx-underground (automated mirror) @vxundergroundre.bsky.social · 14/04/2026It appears I have made a series of mistakes when reviewing some of the financial data from RockStar Games. What does this mean? I've spread misinformation and I will be burned at the stake by gamers. It was nice knowing all of you 0192
vx-underground (automated mirror) @vxundergroundre.bsky.social · 14/04/2026BREAKING: New intelligence from the United States Department of War suggest cars go all like VRRROOOOOM, SKRRRT, and PFFFTBLOOOOSH. Donald Trump is being briefed on the situation now. 0111
vx-underground (automated mirror) @vxundergroundre.bsky.social · 13/04/2026PlayStation 4 - MEGALODON - $98,886.72 Champion in Russia/CIS: - 2015-06-13 - PC (Social Club) - GREAT_WHITE - $9,814.97 000
vx-underground (automated mirror) @vxundergroundre.bsky.social · 13/04/2026Central/South America: - 2017-12-25 - PlayStation 4 - MEGALODON - $30,662.38 Champion in EMEA: - 2025-12-10 - PlayStation 5 - MEMBERSHIP_MEGALODON - $563,273.69 Champion in North America: - 2020-12-25 - Xbox One - MEGALODON - $1,030,926.23 Champion in Oceania: - 2021-07-21 - 110
vx-underground (automated mirror) @vxundergroundre.bsky.social · 13/04/2026stuff. The leak is actually pretty interesting, and it proves how much money they make, but RockStar clearly isn't phased by this leak because ... we all knew they made money. Most money spent by region: Champion in Asia: - 2017-06-13 - PlayStation 4 - MEGALODON - $90,568.29 Champion in 220
vx-underground (automated mirror) @vxundergroundre.bsky.social · 13/04/2026and some weird numbers about people cheating in video games (possibly money lost?). It also has some stuff about how fast support tickets are handled ... blah blah blah. Everything from this leak is something that would probably be shown to investors, management, etc about money and 120
vx-underground (automated mirror) @vxundergroundre.bsky.social · 13/04/2026data and they knew this leak would only unveil one thing: they make a shit load of money. However, it doesn't take a mathematical genius to understand RockStar Games makes a ton of money. The leak is primarily financial data. It does contain some stuff about pricing models per region, 141
vx-underground (automated mirror) @vxundergroundre.bsky.social · 13/04/2026even record the gamertag or anything like that. I presume RockStar does this because they do not want to be liable for collecting and storing peoples private FINANCIAL information. RockStar Games, as you can tell, did not pay the $200,000 ransom. I assume it is because RockStar scrubs 130