Step-by-Step Malware Removal Instructions

NovaShadow Stealer
Trojan

NovaShadow Stealer

NovaShadow is marketed as a stealthy remote access Trojan (RAT) that can evade antivirus detection using advanced obfuscation and polymorphic code. It uses AES‑256 encrypted communications, does not keep logs, and has spying features like live screen sharing, a keylogger, webcam access, and broad

Routine Cleanup Of Unused Accounts Email Scam
Phishing/Scam

Routine Cleanup Of Unused Accounts Email Scam

During our examination, we found that this is a phishing email. The message is disguised as a notification from an email service provider and includes a link to a fake website. Its purpose is to trick recipients into opening a fake web page and entering personal information. Such emails should be

SharkStealer Malware
Trojan

SharkStealer Malware

SharkStealer is a type of malware called an infostealer, written in the Golang programming language. It steals information from infected devices. It uses the BNB Smart Chain (BSC) Testnet to communicate with its control servers. This method, called "EtherHiding", helps hide its network activity.

Undelivered Mail Returned To Sender Email Scam
Phishing/Scam

Undelivered Mail Returned To Sender Email Scam

Our inspection of the "Undelivered Mail Returned To Sender" email revealed that it is a phishing scam. This spam message claims that multiple emails sent by the recipient have failed delivery. The goal of this spam campaign is to deceive recipients into exposing their email account log-in credenti

cPanel - Webmail Update Required Scam
Phishing/Scam

cPanel - Webmail Update Required Scam

After examining this "cPanel - Webmail Update Required" email, we determined that it is fake. This is a phishing message that targets email account log-in credentials (passwords). It must be emphasized that this spam campaign is not associated with the actual cPanel, L.L.C. This spam email

CastleLoader Malware
Trojan

CastleLoader Malware

CastleLoader is a piece of malicious software categorized as a loader. This program is designed to download/install additional malware (i.e., cause chain infections). CastleLoader has been around since at least early 2025. It has been observed being used to target governmental entities in the Unit

Hyperliquid Rewards Program Scam
Phishing/Scam

Hyperliquid Rewards Program Scam

Our research team found this fake "Hyperliquid Rewards Program" page during a routine investigative session. This scam masquerades as the official website of Hyperliquid (hyperfoundation.org). It operates as a cryptocurrency drainer – by stealing digital assets from exposed cryptowallets. IM

Fake Regent of the North Winds ($REGENT) Website Scam
Phishing/Scam

Fake Regent of the North Winds ($REGENT) Website Scam

While investigating suspect websites, our researchers discovered this fake "Regent of the North Winds ($REGENT)" page. It closely impersonates the official website of Regent (regentsol.io). Upon examination, we determined that it is a phishing scam targeting cryptowallet log-in credentials.

Early Spark Adopters Rewards Scam
Phishing/Scam

Early Spark Adopters Rewards Scam

We have analyzed the website (sparkrewards[.]finance) and found that it imitates the original Spark site (spark.fi) to deceive users. The site is fraudulent and uses a malicious tool to drain wallets (steal crypto funds). It should not be trusted or accessed, as interacting with it can result in p

Fake Jito MEV Rewards Scam
Phishing/Scam

Fake Jito MEV Rewards Scam

When browsing suspicious sites, our research team discovered this fake "Jito MEV Rewards" scam. It masquerades as Jito Network's official website (jito.network) and promises rewards to eligible users. This scam aims to deceive users into exposing their digital wallets to a crypto drainer. IM