Step-by-Step Malware Removal Instructions

WeedHack Malware
Trojan

WeedHack Malware

WeedHack malware is a Malware-as-a-Service (MaaS) campaign that combines an information stealer with Remote Access Trojan (RAT) features, and distributes both through fake Minecraft mods and game client programs. According to research published by McAfee Labs, the campaign has been active since J

Vitya Ransomware
Ransomware

Vitya Ransomware

Vitya Ransomware is ransomware that locks victims' files and demands payment for decryption. It appends the .vitek extension to encrypted filenames and displays a pop-up window containing the ransom demand and a countdown timer. On our test machine, Vitya Ransomware encrypted files and appended t

App Passwords Need To Be Updated Email Scam
Phishing/Scam

App Passwords Need To Be Updated Email Scam

We have examined this email and determined it is a phishing scam impersonating a Microsoft account security notification. The message falsely claims the recipient recently changed their password and must create new app passwords for two-step verification. It is designed to steal account credential

Telstra ID Sign-In Email Scam
Phishing/Scam

Telstra ID Sign-In Email Scam

We examined this email and determined it is a phishing scam disguised as a legitimate account security notification from Telstra. The message falsely claims the recipient's Telstra ID was used to sign in to their account and urges them to click a link to keep their password. That link leads to a f

Product Review Request Email Scam
Phishing/Scam

Product Review Request Email Scam

We examined this email and found that it is a phishing scam. Disguised as a legitimate business procurement inquiry, it tricks recipients into opening a malicious HTML file attachment. When opened, the attachment displays a fake email service login page designed to steal the victim's credentials.

Confirm Active Account Status Email Scam
Phishing/Scam

Confirm Active Account Status Email Scam

We have examined this email and determined it is a phishing scam. The message poses as an urgent notification from a webmail support team, claiming the recipient's account may be deactivated due to inactivity. Its goal is to trick recipients into visiting a fake login page and surrendering their e

WARDEN Stealer
Trojan

WARDEN Stealer

WARDEN Stealer is a multi-purpose information stealer, cryptocurrency address clipper, and malware loader built into a single Windows x64 executable. According to research published by KrakenLabs, the threat actor behind WARDEN promotes it on underground forums as a subscription service. The malw

Heisenberg RAT
Trojan

Heisenberg RAT

Heisenberg RAT is a Remote Access Trojan (RAT) that forms the centerpiece of the Heisenberg malware platform - a modular Windows toolkit sold to other criminals. Alongside the RAT, the platform bundles an information stealer, a loader, a dropper, a cryptor, a packer, a file manager, dual hidden-de

Kreepr Ransomware
Ransomware

Kreepr Ransomware

Kreepr is ransomware that our research team discovered while examining new samples submitted to the VirusTotal website. It encrypts victims' files using AES-256-GCM and presents its ransom demands through a pop-up window. Unlike most ransomware, Kreepr provides no contact information of any kind.

PicMo Ransomware
Ransomware

PicMo Ransomware

PicMo is ransomware our research team discovered during a routine inspection of new malware samples submitted to VirusTotal. It encrypts files on compromised systems, replaces original filenames with randomly generated strings, and appends a shared random extension. The ransom note also threatens