vxunderground

@vxunderground · Twitter ·

> be me > get dm > "smelly i found goop" > wtf i love goop (malware) > "I lost the goop... but I found a weird file on my computer" > sends file > malware log file > ??? > examine log > lots of debug information > lmfao wtf > see discord web hooks, hardcoded steam api key > ??? > no identifiers really on VT > beep boop search internet > find the same steam api key in threat zone > see a SHA256 hash > look up on VT > first seen june, 2026 > hmmm > download file (hehe asked a friend) > look inside file > electron js malware > heavily obfuscated > skim file for anything that stands out > references VirusTotal VM BlackList on GitHub > lol ok > clear text c2 > url inside referencing their Telegram > ??? > go to their Telegram > everything visible > cite their Discord > ??? > showing all their aliases > showing draining crypto wallets > showing stealing roblox items > stealing counter strike items > shows stealing emails, social media, credit cards > shows when they started wtf are you actually doing bro? youve documented EVERYTHING and handed it over in plain text. are you out of your mind???

Post media