Step-by-Step Malware Removal Instructions

KansasGroup Ransomware
Ransomware

KansasGroup Ransomware

KansasGroup is ransomware our research team identified while analyzing new file submissions on VirusTotal. Like most ransomware, it encrypts files on the infected machine and demands payment in exchange for decryption. On our test machine, this ransomware appended the ".kansas4life" extension to

Own Ransomware
Ransomware

Own Ransomware

Own Ransomware is a ransomware-type program discovered by our researchers during a routine inspection of new submissions to the VirusTotal website. It encrypts files on the infected device and demands payment in exchange for decryption. On our test machine, Own Ransomware appended each filename w

Proposal Evaluation Completed Email Scam
Phishing/Scam

Proposal Evaluation Completed Email Scam

After inspecting this email, we determined that it is a phishing scam. It is disguised as a management portal notification claiming that a proposal evaluation has been completed and the recipient's review is required. The link inside leads to a fake email login page designed to steal account crede

msaRAT Malware
Trojan

msaRAT Malware

msaRAT is a Remote Access Trojan (RAT) written in the Rust programming language, linked to the Chaos ransomware group. According to research published by Talos Intelligence, it uses an unusual "living off the browser" technique to keep its communications with the attacker's server hidden. Rather

CrashStealer Malware (Mac)
Mac Virus

CrashStealer Malware (Mac)

CrashStealer Malware is an information stealer targeting macOS users, discovered by Jamf Threat Labs in May 2026. It disguises itself as Apple's native crash-reporting tool to blend in with legitimate macOS processes. CrashStealer targets saved passwords, Keychain entries, browser cookies, and

Two-step Verification Was Enabled Email Scam
Phishing/Scam

Two-step Verification Was Enabled Email Scam

We have inspected this email and determined that it is a phishing scam. The message falsely claims that two-step verification was recently enabled on the recipient's account and urges them to review their security settings immediately. It leads to a fake login page designed to steal email account

Damaged Package Email Virus
Phishing/Scam

Damaged Package Email Virus

After inspecting this email, we determined that it is malspam. The message is crafted to look like a routine customer complaint about a damaged shipment and contains a link that redirects to a malicious website. That site delivers a harmful file to the visitor's device. This email should be ignore

Canada Revenue Agency (CRA) Benefit Statement Email Scam
Phishing/Scam

Canada Revenue Agency (CRA) Benefit Statement Email Scam

We have examined this email and determined that it is a phishing scam. It impersonates the Canada Revenue Agency (CRA) and falsely claims that an official benefit statement is ready for download. The real goal is to trick recipients into surrendering their email login credentials on a fraudulent w

Email Migration Notice Scam
Phishing/Scam

Email Migration Notice Scam

We examined this email and determined it is a phishing scam. The message masquerades as an automated notice from the recipient's email service provider and tricks recipients into submitting their login credentials on a fake website. This email should be deleted without taking any action. T

Devill Ransomware
Ransomware

Devill Ransomware

Devill is ransomware that we discovered while examining new file submissions to the VirusTotal website. It encrypts files, appends a randomly generated five-character extension to their filenames, changes the desktop wallpaper, and creates a text-file ransom note named Readme.txt. On our test mac