Step-by-Step Malware Removal Instructions

Chmicutuding.com Ads
Notification Spam

Chmicutuding.com Ads

Our research team found the chmicutuding[.]com rogue page while browsing dubious websites. Upon examination, we determined that this webpage endorses browser notification spam and redirects users to other (likely untrustworthy/malicious) sites. Most visitors to chmicutuding[.]com and similar pages

Cloud - Your Payment Method Has Expired Email Scam
Phishing/Scam

Cloud - Your Payment Method Has Expired Email Scam

Our inspection of the "Cloud - Your Payment Method Has Expired" email revealed that it is spam. This is a phishing email targeting recipients' financial information by claiming that they have run out of Cloud storage and recommending an upgrade. The spam email with the subject "Cloud Stora

PylangGhost RAT
Trojan

PylangGhost RAT

PylangGhost is a Remote Access Trojan (RAT) written in the Python programming language. This program enables remote access and control over infected devices. The trojan can cause chain infections and steal sensitive information. PylangGhost is used exclusively by Famous Chollima (also known as Wa

KimJongRAT Stealer
Trojan

KimJongRAT Stealer

KimJongRAT is malicious software designed to secretly infiltrate computers, steal sensitive data, and allow attackers to control them remotely. It has at least two variants: one built and executed using PowerShell and the other using a Portable Executable (PE) file. The malware collects browser da

Basta (Makop) Ransomware
Ransomware

Basta (Makop) Ransomware

Basta is ransomware that our team has discovered during analysis of malware samples uploaded to VirusTotal. Basta encrypts files and appends the victim's ID, an email address, and the ".basta" extension to files. For example, it renames "1.jpg" to "1.jpg.[2AF20FA3].[basta2025@onionmail.com].basta"

GolangGhost RAT (Mac)
Mac Virus

GolangGhost RAT (Mac)

GolangGhost is a RAT (Remote Access Trojan) targeting Mac operating systems. It is written in the Go programming language (Golang). This malware enables remote access/control over infected machines. It has backdoor and stealer-type functionalities. GolangGhost has been spread through job offer/

Spotify Payment Issue Notice Email Scam
Phishing/Scam

Spotify Payment Issue Notice Email Scam

We have inspected the email and discovered that it is a message posing as a notice from Spotify regarding a recent payment. The scammers behind this fraudulent email attempt to steal personal information from recipients. Whoever receives this email should ignore it. This scam email claims

Streamadsfeed.top Ads
Notification Spam

Streamadsfeed.top Ads

Our analysis of streamadsfeed[.]top shows that it is designed to deliver deceptive notifications. Since it requires user permission to do so, the site uses a clickbait tactic to trick visitors into allowing them. Pages like streamadsfeed[.]top are untrustworthy and should be closed immediately if

Blockchain.com Compensation Payments Scam
Phishing/Scam

Blockchain.com Compensation Payments Scam

We discovered this scam upon receiving a fraudulent email. This scheme is designed to steal unsuspecting individuals' money (and some information). The scam website is disguised as a legitimate Blockchain (blockchain.com) platform to appear legitimate. Users should not trust the page (and the asso