Collection of malware source code for a variety of platforms in an array of different programming languages. Mirror - smells less like Micro$oft over here.
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
vxunderground 2f5aced29c
Add files via upload
5 days ago
Android updates and additions 6 months ago
Engines Add files via upload 2 years ago
Java Add files via upload 5 months ago
Javascript Add files via upload 1 year ago
LegacyWindows push 5 months ago
Libs add 5 months ago
Linux updates and additions 6 months ago
MSDOS mov fix 5 months ago
MacOS updates and additions 6 months ago
Other Add files via upload 2 months ago
PHP Delete Cythosia.7z 2 years ago
Panel Add files via upload 5 days ago
Perl Delete Virus.Perl.WhiteNoise.a 2 years ago
Phishing Add files via upload 6 months ago
PointOfSales mov 9 months ago
Python Update HackTool.Python.Doxing.a 4 months ago
Ruby Delete Virus.Ruby.Badbunny.a 2 years ago
Win32 Add files via upload 5 days ago Update 4 months ago
logo.png Changed the picture used for logo 2 years ago

VXUG logo managed by vx-underground | follow us on Twitter | download malware samples at the VXUG/samples page

Liability Disclaimer:

To the maximum extent permitted by applicable law, vx-underground and/or affiliates who have submitted content to vx-underground, shall not be liable for any indirect, incidental, special, consequential or punitive damages, or any loss of profits or revenue, whether incurred directly or indirectly, or any loss of data, use, goodwill, or other intangible losses, resulting from (i) your access to this resource and/or inability to access this resource; (ii) any conduct or content of any third party referenced by this resource, including without limitation, any defamatory, offensive or illegal conduct or other users or third parties; (iii) any content obtained from this resource


All source code which is packaged may or may not be set with the password 'infected' (without the '). Individual files are likely not packaged. Please do not comment asking for the password - it was placed all over and the official vx-underground Twitter account.

File structure

  • Android
    • Generic Android OS malware, some leaks and proof-of-concepts
  • Engines
    • BAT
    • Linux
    • VBS
    • Win32
  • Java
    • Some java infectors, proof-of-concept ransomware
  • Javascript
    • In-browser malware
  • Legacy Windows
    • Win2k
    • Win32
    • Win95
    • Win98
    • Win9x
    • WinCE
  • Libs (libraries)
    • Bootkits
    • DDoS proof-of-concepts
    • Win32 libraries (disassemblers, etc).
  • Linux
    • Backdoors
    • Botnets
    • Infectors
    • Mirai-Family (related and/or spin-offs)
    • Rootkits
    • Tools
    • Trojans
  • MSIL
  • MacOS
  • Other
    • Acad malware
    • FreeBSD malware
    • SunOS malware
    • Symbian OS malware
    • Discord-specific malware
  • PHP
    • Albania family
    • C99 family
    • Crewcorp family
    • Defacement Tools
    • PHP Infectors
    • Lanker family
    • Macker family
    • PhpSpy family
    • R57-shell family
  • Panel (web panel collections)
  • Perl
    • Various backdoors, hack tools, and infectors
  • Phishing
    • Collection of various phishing pages
  • Point of Sales malware
  • Python
    • Hacktools, various exotic-malware (such as chastity belt ransomware)
  • Ruby
  • Win32
    • Binders
    • Botnets
    • Crypters
    • Exploit kits
    • Infectors
    • Internet worms
    • Malware families
    • Ransomware
    • Rootkits
    • Stealers


Marius 'f0wL' Genheimer
Jan 'Duchy' Neduchal
Eduardo P. Gomez
Bruce Ediger
Alan Wake