PeckBirdy Hides Malware Control Behind Casino Websites
Infoblox traced casino decoys to a hidden PeckBirdy control channel. The script evidence, fake-update history and why DNS queries do not prove infection.
Gridinsoft security desk
Fresh malware news, scam explainers, removal guides, browser fixes, and field notes from the Gridinsoft research team. Start with the alert, then move to the fix.
Infoblox traced casino decoys to a hidden PeckBirdy control channel. The script evidence, fake-update history and why DNS queries do not prove infection.
Florida traced a government data breach to one police employee’s credentials on a personal device. Here is what…
CISA lists CVE-2026-84869 as exploited. Check ScreenConnect 26.6.5, host clients, access agents and suspicious file-execution events.
Remove a fake SimpleSwap bonus userscript, check browser persistence, and respond safely if a crypto address changed or you already sent funds.
Found Music.exe in Task Manager, startup, or on a USB drive? Identify the file, keep threats quarantined, and check why it returns…
Check Trojan:MSIL/Jalapeno!MTB by its file path and quarantine status. Separate browser-cache alerts from an installer that ran, then verify cleanup.
Gridinsoft studied 1,000 flagged store records. Compare domain ages for new records and updates, with date…
A cross-case investigation of how AsyncRAT, LimeRAT, and XWorm used Paste.tc raw pages as C2 resolvers…
Gridinsoft Labs observed plushiefun.xyz on nine endpoints where activity under Hewlett-Packard Diagnostics task identities led into…
Planet Search can route Chrome searches through hidden intermediaries to Nextgeeker. Verify its ID, remove it,…
Gridinsoft telemetry links 45 CoinMiner hashes across 34 Chinese Windows installations to rotating EXE names, signed…
Gridinsoft Labs identifies 22tuk.digital as a new high-confidence TookPS/OkoBot callback and analyzes its encoded PowerShell launcher,…
Static analysis of a suspicious Payment to Bank Details DOCX attachment with a broken altChunk/RTF import…
Old Favorites and .url shortcuts can be flagged when saved sites become phishing, scam, or adware…
Troubleshooting
A_Navi.exe reports that MAXKERNL.dll is missing? Identify the file and startup source, check for…
Troubleshooting
BlueSuite.exe appears after a suspicious download? Check its path, signature and startup entry, distinguish…
Security News
SideSwap reopened BTC deposits on September 11 while Liquid peg-outs remain disabled. How unbacked…
Security News
A genuine Carnival booking email led to deceptive downloads through a lapsed domain. A…
Security News
Adobe expands StyleSmuggler hotfix support. See how a failed-payment email leads to a server…
Security News
An attacker’s coding agent exposed instructions, keys and history to a research honeypot. How…
Security News
LG disputes TV listening claims. Check optional agreements and voice settings, and understand why…
Security News
Gigabud uses Vwork and Android work profiles to separate banking apps from malware. Learn…
Troubleshooting
Check SnakeBiteAgent RAT exposure, remove unauthorized remote access, scan Windows, and secure accounts after…
Troubleshooting
Check why MBAMService.exe uses RAM or disk, distinguish scanning from persistent idle growth, and…
Security News
Deceptive reward apps can hide behind private Early Access feedback. Check the developer, payout…
Troubleshooting
Check atkexComSvc.exe errors or high CPU, identify the ASUS utility behind it, and repair…