Step-by-Step Malware Removal Instructions

Product Review Request Email Scam
Phishing/Scam

Product Review Request Email Scam

We examined this email and found that it is a phishing scam. Disguised as a legitimate business procurement inquiry, it tricks recipients into opening a malicious HTML file attachment. When opened, the attachment displays a fake email service login page designed to steal the victim's credentials.

Confirm Active Account Status Email Scam
Phishing/Scam

Confirm Active Account Status Email Scam

We have examined this email and determined it is a phishing scam. The message poses as an urgent notification from a webmail support team, claiming the recipient's account may be deactivated due to inactivity. Its goal is to trick recipients into visiting a fake login page and surrendering their e

WARDEN Stealer
Trojan

WARDEN Stealer

WARDEN Stealer is a multi-purpose information stealer, cryptocurrency address clipper, and malware loader built into a single Windows x64 executable. According to research published by KrakenLabs, the threat actor behind WARDEN promotes it on underground forums as a subscription service. The malw

Heisenberg RAT
Trojan

Heisenberg RAT

Heisenberg RAT is a Remote Access Trojan (RAT) that forms the centerpiece of the Heisenberg malware platform - a modular Windows toolkit sold to other criminals. Alongside the RAT, the platform bundles an information stealer, a loader, a dropper, a cryptor, a packer, a file manager, dual hidden-de

Kreepr Ransomware
Ransomware

Kreepr Ransomware

Kreepr is ransomware that our research team discovered while examining new samples submitted to the VirusTotal website. It encrypts victims' files using AES-256-GCM and presents its ransom demands through a pop-up window. Unlike most ransomware, Kreepr provides no contact information of any kind.

PicMo Ransomware
Ransomware

PicMo Ransomware

PicMo is ransomware our research team discovered during a routine inspection of new malware samples submitted to VirusTotal. It encrypts files on compromised systems, replaces original filenames with randomly generated strings, and appends a shared random extension. The ransom note also threatens

Golden Woolf Ransomware
Ransomware

Golden Woolf Ransomware

Golden Woolf is ransomware our researchers discovered while inspecting new malware samples submitted to VirusTotal. It encrypts files on the victim's computer, appends the .wolf extension to filenames, and opens a pop-up window with ransom demands. On our test machine, Golden Woolf encrypted file

DHL Express - Shipment Arrived Email Virus
Phishing/Scam

DHL Express - Shipment Arrived Email Virus

After inspecting this email, we determined that it is malspam. The message pretends to be a shipment notification from DHL Express, urging recipients to open an attached file that supposedly contains shipping documents. In reality, the attachment is designed to deliver malware, so the email should

DocuSign Document For Review And Signature Email Scam
Phishing/Scam

DocuSign Document For Review And Signature Email Scam

After inspecting this email, we determined it is a phishing scam. The message is disguised as a notification from DocuSign, a legitimate electronic signature service, claiming the recipient has a document pending review and signature. Clicking the link inside leads to a fake email login page desig