Malware

Remove “American Express – ChargeBack Payment” email scam

The “American Express – ChargeBack Payment” email is part of a phishing campaign that aims to steal users’ American Express account login credentials. The email falsely claims that a chargeback of $1218.16 has been successfully adjusted and can be reviewed by clicking on the provided button. However, if users click on the button, they will be taken to a fake…

Remove SwaetRAT malware

SwaetRAT malware is a remote access trojan that has many malicious features that can put users’ computers and data in jeopardy. If it successfully infects a device, it gives its operators unauthorized control over the device. The trojan can monitor users’ activities, steal highly sensitive information, and more. In short, it’s a very serious infection that, if unnoticed, can have…

Remove Held ransomware

Held ransomware is a type of malware that encrypts files. It comes from the Djvu/STOP ransomware family. The malicious actors behind this ransomware family release new versions regularly, and Held ransomware is one of the more recent ones. The versions can be differentiated by the extensions they add to encrypted files. This ransomware adds .held to all files it encrypts. Unfortunately,…

Remove GURAM ransomware

GURAM ransomware is a file-encrypting type of infection that essentially takes files hostage. The ransomware targets all personal files, encrypts them, and demands payment for their recovery. The ransomware can be identified by the extension it adds to encrypted files. Specifically, it adds a .{victims’ IDs}.GURAM to file names. Files that have this extension will not be openable unless you…

Remove PlainGnome Android trojan

PlainGnome Android malware is a stealer trojan that targets Android devices. The trojan is believed to be operated by Gamaredon, a threat actor affiliated with the Federal Security Service of the Russian Federation (FSB). The malware appears to target Russian-speaking users in former USSR states, such as Uzbekistan, Kazakhstan, and Kyrgyzstan. The malware intends to steal information like call logs,…

Remove “Removal Of Dormant/Inactive Accounts” email

The “Removal Of Dormant/Inactive Accounts” email is part of a phishing campaign targeting users’ email account credentials. The email falsely informs the recipient that they must confirm that their account is still active by clicking the provided button. Otherwise, the email account will supposedly be deleted if it’s not confirmed. However, if users engage with the email, they will get…

Remove SteelFox trojan

SteelFox trojan is a malicious infection with a large range of features. Specifically, it’s a malicious bundle that contains a dropper, a loader, a miner, and a stealer infection. Users’ computers get infected primarily via popular software cracks, which users download via torrents, forums, and blogs. The malware operates as a miner and uses the device’s resources to mine for…

Remove WezRat stealer trojan

WezRat malware is a stealer trojan, a dangerous infection that aims to steal highly sensitive information from infected devices. The trojan has a wide range of capabilities, including data theft, keylogging, command execution, file upload, screenshot capture, and more. The malware is distributed through phishing emails urging users to update their Chrome browsers.