Step-by-Step Malware Removal Instructions

PYRA Airdrop Scam
Phishing/Scam

PYRA Airdrop Scam

Our team has analysed the page (event-pyra[.]fun) and concluded that it imitates the original PYRA website, pyrachain.io. The fake site promotes a fake cryptocurrency giveaway, an airdrop to lure visitors into taking steps that could lead to permanent cryptocurrency loss. Thus, it is highly advisa

Search.ansiblealgorithm.com Redirect
Browser Hijacker

Search.ansiblealgorithm.com Redirect

We have inspected search.ansiblealgorithm.com and found that it is a fake search engine because it does not generate results. Moreover, it may collect various data. It is also important to mention that fake search engines are often associated with browser hijackers. Users should not trust search.a

Goyin Airdrop Scam
Phishing/Scam

Goyin Airdrop Scam

After reviewing the website (claim-goyim.pages[.]dev), we identified it as a scam. It falsely offers visitors the opportunity to join a cryptocurrency airdrop. The attackers behind this site aim to steal funds from users' crypto wallets, meaning that engaging with it could lead to serious financia

Xillen Stealer
Trojan

Xillen Stealer

Xillen is an information stealer often distributed through other malware, such as Amadey. Once executed on the device, it gathers various information and sends it to cybercriminals. Having the system infected with Xillen can result in issues such as identity theft and financial loss. Thus, if dete

Venere Ransomware
Ransomware

Venere Ransomware

We have tested the malware and found that it is ransomware belonging to the MedusaLocker family. Once executed, Venere encrypts files and appends the ".Venere1" extension (the included number might vary). For example, it renames "1.jpg" to "1.jpg.Venere1", "2.png" to "2.png.Venere1", and so forth.

Storage Usage Alert Email Scam
Phishing/Scam

Storage Usage Alert Email Scam

Our team has found that this is a phishing email designed to appear as a notification from the email service provider. It includes a link to a fake site created to trick visitors into disclosing personal information. Recipients should ignore this email to avoid account hijacking and further issues

Arsink RAT (Android)
Trojan

Arsink RAT (Android)

Arsink is a Remote Access Trojan (RAT) targeting Android operating systems. It is a sophisticated malware that allows attackers to remotely access/control devices and exfiltrate a variety of sensitive data. Arsink is distributed worldwide through opportunistic campaigns, under the guise of various

Zoho Mail Upgrade Email Scam
Phishing/Scam

Zoho Mail Upgrade Email Scam

After inspecting this "Zoho Mail Upgrade" email, we determined that it is fake. This spam message states that recipients must update their accounts to avoid deactivation. The purpose of this campaign is to lure users into disclosing their email log-in credentials to a phishing website. The

Clawdbot ($CLAWD) Scam Websites
Phishing/Scam

Clawdbot ($CLAWD) Scam Websites

"Clawdbot ($CLAWD) scam" refers to fraudulent and deceptive content that uses the "Clawdbot" name/branding as a disguise. Clawdbot was the original name of an AI (Artificial Intelligence) software project that was later renamed "Moltbot" and then rebranded as "OpenClaw". These scams have no affili

Trendstitchhub.com Ads
Notification Spam

Trendstitchhub.com Ads

Our researchers discovered trendstitchhub[.]com while investigating dubious websites. After examining this rogue page, we determined that it promotes browser notification spam and generates redirects to other (likely unreliable/dangerous) sites. Most visitors to trendstitchhub[.]com and similar w