Fake Invoice PDFs Install Action1 Remote-Access Agent
SANS traced fake payment and DHL PDFs to scripts that display a decoy document while installing Action1. Check what ran before treating the agent as malware.
Gridinsoft security desk
Fresh malware news, scam explainers, removal guides, browser fixes, and field notes from the Gridinsoft research team. Start with the alert, then move to the fix.
SANS traced fake payment and DHL PDFs to scripts that display a decoy document while installing Action1. Check what ran before treating the agent as malware.
Rapid7 found Linux implants using deleted executables, daemon disguises and SMTP control traffic. What mail-gateway operators should investigate.
New iCloud research explains how forged sender addresses passed SPF, DKIM and DMARC. The flaws were fixed in…
Received cronigame.exe from a Discord friend? See what the report establishes and what to do if you downloaded, blocked, or ran the…
Trace Windows Event Log high CPU or disk usage to the event source or querying tool, preserve useful evidence, and verify a…
Understand the exact Sabsik EN.B Defender alert, keep suspicious files quarantined, and use Gridinsoft Anti-Malware to investigate repeat detections.
Check Trojan:MSIL/Jalapeno!MTB by its file path and quarantine status. Separate browser-cache alerts from an installer that…
Gridinsoft studied 1,000 flagged store records. Compare domain ages for new records and updates, with date…
A cross-case investigation of how AsyncRAT, LimeRAT, and XWorm used Paste.tc raw pages as C2 resolvers…
Gridinsoft Labs observed plushiefun.xyz on nine endpoints where activity under Hewlett-Packard Diagnostics task identities led into…
Planet Search can route Chrome searches through hidden intermediaries to Nextgeeker. Verify its ID, remove it,…
Gridinsoft telemetry links 45 CoinMiner hashes across 34 Chinese Windows installations to rotating EXE names, signed…
Gridinsoft Labs identifies 22tuk.digital as a new high-confidence TookPS/OkoBot callback and analyzes its encoded PowerShell launcher,…
Static analysis of a suspicious Payment to Bank Details DOCX attachment with a broken altChunk/RTF import…
Security News
MetaMask is exiting affected validators after diverted rewards. The 0.36 ETH payment total and…
Security News
A documented Free Mobile phishing email uses a €9.99 debt and a disguised link…
Security News
A new investigation finds 70 fake crypto sites. Their reward vote opens a wallet…
Security News
Microsoft traces Star Blizzard’s RedFlick chain: document-looking shortcuts, remote applets and scheduled tasks delivering…
Security News
Northeastern tested 21 cars and 30 apps. Seven apps sent personal identifiers to trackers;…
Troubleshooting
Crypto address changes when pasted? Separate normal wallet rotation from clipboard malware, check the…
Troubleshooting
MicrosoftEdgeUpdate.exe keeps crashing or retrying? Verify Edge updates, check the file, repair safely, and…
Troubleshooting
Diagnose Defender’s Remediation incomplete warning by comparing the affected file, detection time, scan results,…
Troubleshooting
Browser closes when you search for antivirus, or installers disappear? Scan Windows with Gridinsoft…
Security News
Researchers found Poper Blocker collecting browser history and AI chats. The case shows how…
Security News
Microsoft traced fake invitations and PDF lures to MSP360, then ScreenConnect. Why UAC mattered…
Security News
A fake iPhone Duo offer loads DarkSword before the form is submitted. What the…