Collection of malware source code for a variety of platforms in an array of different programming languages. Mirror - smells less like Micro$oft over here.
You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
vxunderground c5d2f3c6a0
Create Win32.TitanStealer.7z
1 month ago
Android updates and additions 1 year ago
Engines Add files via upload 3 years ago
Java Add files via upload 1 year ago
Javascript Add files via upload 2 months ago
LegacyWindows push 1 year ago
Libs add 1 year ago
Linux updates and additions 1 year ago
MSDOS mov fix 1 year ago
MacOS updates and additions 1 year ago
Other Add files via upload 10 months ago
PHP Delete Cythosia.7z 3 years ago
Panel Add files via upload 2 months ago
Perl Delete Virus.Perl.WhiteNoise.a 3 years ago
Phishing Add files via upload 1 year ago
PointOfSales mov 1 year ago
Python Update HackTool.Python.Doxing.a 1 year ago
Ruby Delete Virus.Ruby.Badbunny.a 3 years ago
Win32 Create Win32.TitanStealer.7z 1 month ago Update 1 year ago
logo.png Changed the picture used for logo 3 years ago

VXUG logo managed by vx-underground | follow us on Twitter | download malware samples at the VXUG/samples page

Liability Disclaimer:

To the maximum extent permitted by applicable law, vx-underground and/or affiliates who have submitted content to vx-underground, shall not be liable for any indirect, incidental, special, consequential or punitive damages, or any loss of profits or revenue, whether incurred directly or indirectly, or any loss of data, use, goodwill, or other intangible losses, resulting from (i) your access to this resource and/or inability to access this resource; (ii) any conduct or content of any third party referenced by this resource, including without limitation, any defamatory, offensive or illegal conduct or other users or third parties; (iii) any content obtained from this resource


All source code which is packaged may or may not be set with the password 'infected' (without the '). Individual files are likely not packaged. Please do not comment asking for the password - it was placed all over and the official vx-underground Twitter account.

File structure

  • Android
    • Generic Android OS malware, some leaks and proof-of-concepts
  • Engines
    • BAT
    • Linux
    • VBS
    • Win32
  • Java
    • Some java infectors, proof-of-concept ransomware
  • Javascript
    • In-browser malware
  • Legacy Windows
    • Win2k
    • Win32
    • Win95
    • Win98
    • Win9x
    • WinCE
  • Libs (libraries)
    • Bootkits
    • DDoS proof-of-concepts
    • Win32 libraries (disassemblers, etc).
  • Linux
    • Backdoors
    • Botnets
    • Infectors
    • Mirai-Family (related and/or spin-offs)
    • Rootkits
    • Tools
    • Trojans
  • MSIL
  • MacOS
  • Other
    • Acad malware
    • FreeBSD malware
    • SunOS malware
    • Symbian OS malware
    • Discord-specific malware
  • PHP
    • Albania family
    • C99 family
    • Crewcorp family
    • Defacement Tools
    • PHP Infectors
    • Lanker family
    • Macker family
    • PhpSpy family
    • R57-shell family
  • Panel (web panel collections)
  • Perl
    • Various backdoors, hack tools, and infectors
  • Phishing
    • Collection of various phishing pages
  • Point of Sales malware
  • Python
    • Hacktools, various exotic-malware (such as chastity belt ransomware)
  • Ruby
  • Win32
    • Binders
    • Botnets
    • Crypters
    • Exploit kits
    • Infectors
    • Internet worms
    • Malware families
    • Ransomware
    • Rootkits
    • Stealers


Marius 'f0wL' Genheimer
Jan 'Duchy' Neduchal
Eduardo P. Gomez
Bruce Ediger
Alan Wake