Step-by-Step Malware Removal Instructions

Devill Ransomware
Ransomware

Devill Ransomware

Devill is ransomware that we discovered while examining new file submissions to the VirusTotal website. It encrypts files, appends a randomly generated five-character extension to their filenames, changes the desktop wallpaper, and creates a text-file ransom note named Readme.txt. On our test mac

InterServer Ransomware
Ransomware

InterServer Ransomware

InterServer is ransomware our research team identified during a routine inspection of samples submitted to VirusTotal. It encrypts files, appends a variant-specific extension (e.g., .interserver12), and creates an HTML ransom note named RANSOM_NOTE.html. The attackers also claim to have stolen sen

Dolphin X RAT
Trojan

Dolphin X RAT

Dolphin X RAT is a multi-purpose Windows malware sold as a subscription service to cybercriminals. It combines a Remote Access Trojan (RAT), information stealer, cryptocurrency clipper, and distributed denial-of-service (DDoS) tool in a single package. Research published by Varonis Threat Labs do

NoMatter Ransomware
Ransomware

NoMatter Ransomware

NoMatter is ransomware discovered by our researchers during a routine inspection of new submissions to VirusTotal. It encrypts victims' files, changes the desktop wallpaper, and drops a ransom note in a text file named README.txt. Unlike most ransomware, NoMatter does not append any new extension

BlackWizard Ransomware
Ransomware

BlackWizard Ransomware

BlackWizard is ransomware that our researchers discovered during a routine inspection of new file submissions to VirusTotal. It encrypts victims' files and demands payment in exchange for a decryption key. The group behind it identifies themselves as "Ransomware Team" in the ransom message. On ou

FadeSEC Ransomware
Ransomware

FadeSEC Ransomware

FadeSEC is ransomware our research team discovered while examining malware samples submitted to VirusTotal. It encrypts victims' files and displays an interactive full-screen ransom message. Notably, restarting or re-logging into the system dismisses the screen lock, but files remain encrypted reg

MarkiRAT Malware
Trojan

MarkiRAT Malware

MarkiRAT is a Remote Access Trojan (RAT) used by an Iran-linked threat cluster to surveil Iranian civilians, dissidents, and diaspora communities. According to research published by Recorded Future, the malware is deployed by TAG-182, an Iran-nexus group with possible connections to the Ferocious

ClickLock Stealer (Mac)
Mac Virus

ClickLock Stealer (Mac)

ClickLock Stealer is a modular information stealer targeting macOS users. According to research published by Group-IB, it was discovered in June 2026 with zero initial detections on VirusTotal. Cybercriminals distribute it via ClickFix, tricking users into running a Terminal command that silentl

TELEPUZ Malware
Trojan

TELEPUZ Malware

TELEPUZ is a modular Malware-as-a-Service (MaaS) platform that combines Remote Access Trojan (RAT) functions with information-stealing capabilities. Written in C and deployed as a 64-bit Windows DLL, it runs silently in the background while giving attackers full remote control of infected systems.

Starland RAT
Trojan

Starland RAT

Starland RAT is a Remote Access Trojan (RAT) that lets cybercriminals secretly control an infected Windows computer, run commands on it, and push additional malware onto it without the victim noticing anything unusual. According to research published by Cisco Talos, Starland RAT is deployed by a