Step-by-Step Malware Removal Instructions

Oyster Malware
Trojan

Oyster Malware

Oyster (also known as Broomstick, CleanUpLoader) is a backdoor and loader type malware. It has been around since at least the summer of 2023 and has received several significant updates. Oyster is offered as MaaS (Malware-as-a-Service) and is thus available to various cyber criminals. It has been

LOTTO AMERICA Email Scam
Phishing/Scam

LOTTO AMERICA Email Scam

We have examined the email and found that it poses as a winning notification from "LOTTO AMERICA". Essentially, it is a scam email designed to steal money and (or) information from unsuspecting recipients. Emails like this one should be ignored and deleted immediately. This is a fraudulent

Utility Coin ($UTILITY) Airdrop Scam
Phishing/Scam

Utility Coin ($UTILITY) Airdrop Scam

Our team has inspected the website (utility.soldex[.]trade) and found that it imitates the original Utility Coin site (theutilitycoin.com). The fake site promotes an airdrop to lure visitors into taking actions allowing fraudsters to steal their cryptocurrency holdins. It should be avoided to prev

Chethomarie.com Ads
Notification Spam

Chethomarie.com Ads

We have analysed chethomarie[.]com and found that it tries to deceive visitors into agreeing to get its notifications. Once permission is granted, the site can send fake alerts and other misleading messages, which may lead users to potentially malicious pages (e.g., scam websites). Thus, chethomar

NovaShadow Stealer
Trojan

NovaShadow Stealer

NovaShadow is marketed as a stealthy remote access Trojan (RAT) that can evade antivirus detection using advanced obfuscation and polymorphic code. It uses AES‑256 encrypted communications, does not keep logs, and has spying features like live screen sharing, a keylogger, webcam access, and broad

Routine Cleanup Of Unused Accounts Email Scam
Phishing/Scam

Routine Cleanup Of Unused Accounts Email Scam

During our examination, we found that this is a phishing email. The message is disguised as a notification from an email service provider and includes a link to a fake website. Its purpose is to trick recipients into opening a fake web page and entering personal information. Such emails should be

SharkStealer Malware
Trojan

SharkStealer Malware

SharkStealer is a type of malware called an infostealer, written in the Golang programming language. It steals information from infected devices. It uses the BNB Smart Chain (BSC) Testnet to communicate with its control servers. This method, called "EtherHiding", helps hide its network activity.

Undelivered Mail Returned To Sender Email Scam
Phishing/Scam

Undelivered Mail Returned To Sender Email Scam

Our inspection of the "Undelivered Mail Returned To Sender" email revealed that it is a phishing scam. This spam message claims that multiple emails sent by the recipient have failed delivery. The goal of this spam campaign is to deceive recipients into exposing their email account log-in credenti

cPanel - Webmail Update Required Scam
Phishing/Scam

cPanel - Webmail Update Required Scam

After examining this "cPanel - Webmail Update Required" email, we determined that it is fake. This is a phishing message that targets email account log-in credentials (passwords). It must be emphasized that this spam campaign is not associated with the actual cPanel, L.L.C. This spam email

CastleLoader Malware
Trojan

CastleLoader Malware

CastleLoader is a piece of malicious software categorized as a loader. This program is designed to download/install additional malware (i.e., cause chain infections). CastleLoader has been around since at least early 2025. It has been observed being used to target governmental entities in the Unit