Step-by-Step Malware Removal Instructions

cPanel Policy Update Email Scam
Phishing/Scam

cPanel Policy Update Email Scam

We have inspected this email and found that it is a phishing scam. The message is designed to look like an official notice from cPanel, falsely claiming that account holders must verify their accounts due to a policy update. The scammers behind it want to steal hosting and email login credentials.

Vendor Registration And Partnership Process Email Scam
Phishing/Scam

Vendor Registration And Partnership Process Email Scam

We have examined this email and determined it is a scam. It is disguised as a vendor onboarding invitation from ExxonMobil Corporation, targeting businesses and professionals worldwide. The goal is to draw recipients into extended correspondence that eventually leads to requests for money, sensiti

Files Shared Using Google Drive Workspace Email Scam
Phishing/Scam

Files Shared Using Google Drive Workspace Email Scam

We have examined this email and found it to be a phishing scam. The message impersonates a Google Drive file-sharing notification, falsely claiming that a client has shared documents with the recipient's team. It carries an HTML file attachment that, when opened in a browser, displays a fake login

Pending Messages Awaiting Transfer Email Scam
Phishing/Scam

Pending Messages Awaiting Transfer Email Scam

We have inspected this email and determined it is a phishing scam. The message impersonates a generic email service notification, falsely claiming the recipient has pending messages that cannot be delivered until they take action. Its purpose is to trick recipients into clicking a link that leads

BambooToken Malware
Trojan

BambooToken Malware

BambooToken is a backdoor-type malware that gives attackers covert, remote access to infected Windows and Linux systems. It was uncovered by Black Lotus Labs, the threat research division at Lumen, and has likely been active since at least February 2023. The malware is used in targeted attacks, m

KREMLIN Banking Trojan
Trojan

KREMLIN Banking Trojan

KREMLIN Banking Trojan is a multi-stage banking trojan that secretly adds a malicious browser extension to Google Chrome and Microsoft Edge. The extension spies on online banking sessions, records what the victim types, steals cookies and saved passwords, and can even change what the victim sees o

SparroWocky Backdoor
Trojan

SparroWocky Backdoor

SparroWocky is a backdoor written in C++ and deployed by FamousSparrow, a China-aligned cyberespionage group. It establishes covert, persistent access to infected computers and lets operators run commands, transfer files, capture screenshots, and route network traffic through compromised machines.

ChainScript RAT
Trojan

ChainScript RAT

ChainScript is a Remote Access Trojan (RAT) written in Node.js that lets attackers secretly control infected Windows computers. It can run commands, handle files, take screenshots, look for cryptocurrency wallets, and install other malware. The RAT was documented in September 2026 by the Adversar

ClosedQuorum Malware
Trojan

ClosedQuorum Malware

ClosedQuorum is a Windows implant classified as a trojan that combines Remote Access Trojan (RAT) functionality with credential and cryptocurrency theft. What sets it apart is its use of commercial AI language models to autonomously decide which attack action to take next, without requiring a huma

Clearing Inactive Email Accounts Scam
Phishing/Scam

Clearing Inactive Email Accounts Scam

We have examined this email and determined it is a phishing scam. The message falsely claims the email provider is clearing inactive accounts and instructs the recipient to open an HTML file attachment to verify their address. The file displays a fake Zimbra webmail login page intended to steal em