Step-by-Step Malware Removal Instructions

Harvard.edu ClickFix Malware
Trojan

Harvard.edu ClickFix Malware

Our team has discovered that cybercriminals compromised the official Harvard website (harvard.edu) and injected ClickFix. By exploiting access to a trusted, reputable domain, the attackers were able to host malicious content that appears legitimate, increasing the likelihood that visitors would in

Social Security Administration (SSA) eStatement Email Scam
Phishing/Scam

Social Security Administration (SSA) eStatement Email Scam

We have examined the message and determined that it is designed to deceive recipients into believing that they have to review their accounts as soon as possible. This scam email includes a link to a phishing website. Typically, scams like this are used to harvest personal information. This and sim

RAM Shipment On Hold Email Scam
Phishing/Scam

RAM Shipment On Hold Email Scam

We have inspected the email and found that it is designed to look like a delivery update from a legitimate company. However, this message is fraudulent, as it contains fake details and includes a link to a deceptive page. The scammers behind this email likely seek to steal money and personal infor

STX RAT
Trojan

STX RAT

STX is a remote access Trojan (RAT) that cybercriminals were observed spreading through fake or trojanized software installers. The RAT steals passwords, browser data, crypto-wallet details, and other sensitive information after connecting to its command-and-control server. It also uses anti-detec

Hnx911 Ransomware
Ransomware

Hnx911 Ransomware

Hnx911 is ransomware from the Xorist family. Our team discovered it during an inspection of malware samples uploaded to VirusTotal. Once executed, Hnx911 encrypts the victim's files and appends the ".hnx911" extension. It also creates a ransom note "HOW TO DECRYPT FILES.txt" and displays another o

Cloud Storage Plan Has Been Paused Email Scam
Phishing/Scam

Cloud Storage Plan Has Been Paused Email Scam

Our team has reviewed the email and found that it is disguised as a notification regarding the recipient's cloud storage plan. It urges the recipient to solve the "issue" through the provided link as soon as possible. The included link leads to deceptive websites. This scam email should be ignored

Cooked Ransomware
Ransomware

Cooked Ransomware

Our team discovered Cooked while analyzing samples submitted to VirusTotal. Our examination has shown that this is ransomware designed to encrypt files, provide a ransom note ("Readme.txt"), and add its extension (".cooked") to files. For example, it renames "1.jpg" to "1.jpg.cooked", "2.png" to "

Cloud Account Scheduled For Deletion Email Scam
Phishing/Scam

Cloud Account Scheduled For Deletion Email Scam

Our analysis indicates that this is a scam email intended to deceive recipients into thinking their cloud account has been scheduled for deletion. It directs users to fraudulent websites. All claims made in the email and on the linked sites are false and should not be trusted. If you receive this

Document Status Update Email Scam
Phishing/Scam

Document Status Update Email Scam

We have reviewed the email and determined that it is a phishing message containing a link to a fake website. The scammers behind this email seek to steal personal information that can be misused to hijack accounts. Stolen accounts can be misused for malicious purposes. Overall, this scam email sho