Step-by-Step Malware Removal Instructions

SNOWLIGHT Malware (Mac)
Mac Virus

SNOWLIGHT Malware (Mac)

SNOWLIGHT is a malware that targets Mac operating systems (macOS). It acts as a dropper (i.e., can cause chain infections) and has been observed being used to infiltrate the VShell malware into compromised devices. The SNOWLIGHT dropper has been used by a threat actor tracked as "UNC5174". It is

Stealc_v2 Stealer
Trojan

Stealc_v2 Stealer

Stealc_v2 is the second version of the Stealc stealer-type malware. This new variant was released in April 2025. Stealc_v2 is written in the C++ programming language. This malicious program is designed to extract and exfiltrate vulnerable data from infected systems and installed apps. At the time

Hudson Ransomware
Ransomware

Hudson Ransomware

Our researchers discovered Hudson ransomware while investigating new submissions to the VirusTotal website. This type of malware encrypts victims' files and demands ransoms for the decryption. After we executed a sample of Hudson ransomware on our testing system, it encrypted files and appended t

Binance - Urgent Security Alert Email Scam
Phishing/Scam

Binance - Urgent Security Alert Email Scam

Our inspection of the "Binance - Urgent Security Alert" email, revealed that it is spam. This phishing message claims a suspicious sign-in attempt has been detected on the recipient's Binance account. By trying to investigate the supposed sign-in, users are lured into disclosing their account log-

Mosdefender.co.in Ads
Notification Spam

Mosdefender.co.in Ads

Our researchers discovered the mosdefender.co[.]in rogue page while investigating dubious websites. This webpage is designed to promote browser notification spam and redirect users to other (likely untrustworthy/malicious) websites. Most visitors to mosdefender.co[.]in and similar pages access the

Beraborrow ($BERA) Rewards Scam
Phishing/Scam

Beraborrow ($BERA) Rewards Scam

During a routine investigative session, our research team discovered a fake "Beraborrow ($BERA) Rewards" website. It masquerades as Beraborrow (beraborrow.com) running a poll, the participants of which can receive rewards. The scam site aims to deceive users into exposing their digital wallets to

Hero Ransomware
Ransomware

Hero Ransomware

Hero is a ransomware discovered by our researchers during a routine inspection of new file submissions to VirusTotal. This malicious program is part of the Proton ransomware family. Malware within this classification encrypts data and demands payment for the decryption. On our testing system, Her

Forgive Ransomware
Ransomware

Forgive Ransomware

Our researchers discovered Forgive ransomware while browsing new submissions to the VirusTotal website. This malicious program encrypts files and demands ransoms for the decryption. After we executed a sample of Forgive on our test machine, it encrypted files and added a ".forgive" extension to t

Complexnetwork.co.in Ads
Notification Spam

Complexnetwork.co.in Ads

Complexnetwork.co[.]in is a rogue page discovered by our researchers during a routine inspection of suspicious websites. It operates by promoting browser notification spam and redirecting visitors to other (likely dubious/dangerous) sites. The majority of users access complexnetwork.co[.]in and an

PayForRepair Ransomware
Ransomware

PayForRepair Ransomware

While browsing new submissions to the VirusTotal website, our researchers discovered the PayForRepair ransomware. This malicious program is part of the Dharma ransomware family. The malware is designed to encrypt data and demand payment for the decryption. On our test machine, PayForRepair encryp