Step-by-Step Malware Removal Instructions

Insufficient Email Capacity Scam
Phishing/Scam

Insufficient Email Capacity Scam

We have examined the email and concluded that it is a scam. The message is designed to appear as an automated storage warning from an email service provider. The scammers behind it seek to trick unsuspecting recipients into entering their email login credentials on a fraudulent website. This scam

Mail Security Notice Scam
Phishing/Scam

Mail Security Notice Scam

We examined this email and determined that it is a phishing scam. It is disguised as a routine security notice from an email account's IT support team, urging recipients to re-verify their account to avoid losing mailbox access. In reality, the message is designed to steal email login credentials.

Mailbox Quarantine Alert Email Scam
Phishing/Scam

Mailbox Quarantine Alert Email Scam

We have inspected the email and found that it contains a fake notification claiming the recipient's mailbox has incoming messages stuck in quarantine due to oversized attachments. It is a phishing email designed to steal email account login credentials from unsuspecting individuals. This message s

Account Not Validated Email Scam
Phishing/Scam

Account Not Validated Email Scam

We have inspected the email and found that it contains a fake notification claiming that the recipient's mailbox has not been validated and could be suspended. It is a phishing email designed to steal email account login credentials from unsuspecting recipients. It should be ignored to avoid havin

SWIFT Confirmation Copy Email Scam
Phishing/Scam

SWIFT Confirmation Copy Email Scam

We have inspected the email and found that it contains a fake notification about a SWIFT wire transfer confirmation copy supposedly attached for review. It is a phishing email designed to steal email account credentials from unsuspecting recipients through a fraudulent login page that imitates whi

FlutterShell Backdoor (Mac)
Mac Virus

FlutterShell Backdoor (Mac)

FlutterShell is a backdoor targeting macOS users. It is delivered inside fake-but-working Mac apps (a podcast player and PDF viewers) and gives attackers remote control of an infected Mac through a hidden browser window. Researchers at Palo Alto Networks Unit 42 documented the malware as part of

$ETHFI Vote Rewards Scam
Phishing/Scam

$ETHFI Vote Rewards Scam

We have inspected the website vote-ethfi[.]app and found that it imitates the official ether.fi platform, presenting a fake "$ETHFI Rewards Allocation Proposal" governance vote. The page is designed to trick visitors into connecting their cryptocurrency wallets, which can lead to the theft of digi

Kinetiq Vote Rewards Scam
Phishing/Scam

Kinetiq Vote Rewards Scam

We have inspected the website reward-kinetiq[.]xyz and found that it impersonates Kinetiq, a liquid staking platform, by promoting a fake voting rewards proposal. It is designed to trick visitors into connecting their cryptocurrency wallets, which can result in financial losses. IMPORTANT NO

Searchtoggler.com Redirect
Browser Hijacker

Searchtoggler.com Redirect

Our researchers discovered the Search Toggler browser hijacker while reviewing extensions promoted through their own dedicated websites. Despite its description promising an easier way to switch between search engines, Search Toggler quietly reassigns the browser's search settings to searchtoggler

Viewmenuprices.com Redirect
Browser Hijacker

Viewmenuprices.com Redirect

Our researchers inspected the View Menu with Prices browser extension and found that it carries the traits of a browser hijacker. Once installed, it quietly changes the browser's default search engine to viewmenuprices.com. View Menu with Prices is presented as a handy way to look up restaurant m