DLL Search Order Hijacking: How It Works and How to Prevent It
Learn how DLL search order hijacking works, why malicious DLLs load inside trusted Windows processes, and what to check, detect, and harden.
Threat research notebook
Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.
305 lab recordsLearn how DLL search order hijacking works, why malicious DLLs load inside trusted Windows processes, and what to check, detect, and harden.
A fake Microsoft Security Warning with a phone number is browser scareware, not a real Microsoft...
Huawei, Honor, or Vivo phone says the Google app or Google Play Services is Android:TrojanSMS-PA? Learn...
Over the past few weeks, Google's Threat Analysis Group (TAG) has reported a worrying trend. Experts...
Computer viruses really resemble real ones. They can infect thousands of computers in a matter of minutes, which is why we call their outbreak...
Aluc Service and Aluc App are names users report seeing in Task Manager, Services, or installed apps when a suspicious program is active on...
Exim Internet Mailer, a program massively used as a basis for mailing servers, appears to have a remote code execution vulnerability. By overflowing the...
Cybercriminals who stand behind RedLine and Vidar stealers decided to diversify their activity. Now, crooks deploy ransomware, using the same spreading techniques as they...
As a part of the GridinSoft team, I am proud to announce the public release of our own online virus scanner service! Now, you...
In the ever-evolving landscape of cyber threats, crooks continually find new and inventive ways to exploit vulnerabilities and target valuable assets. One such threat...
Recent attacks on US military systems and Taiwan companies are distinctive not only by the brave target choosing, but also for the used toolkit....
Threat actors started using compromised websites for phishing purposes much more frequently. Such worrying statistics popped up in several recent researches. This is not...
Think an info-stealer is on your PC? Clean the device, revoke sessions, reset passwords from a trusted device, and secure accounts in the right...
FIN8, an infamous group of cybercriminals, has updated its backdoor malware to avoid being detected. They made improvements and prepared to release a new...
On July 11, 2023, Microsoft published an article about addressing the CVE-2023-36884 vulnerability. This breach allowed for remote code execution in Office and Windows...
Wise Remote Stealer is a potent and malicious software that operates as an infostealer, Remote Access Trojan (RAT), DDoS bot, and ransomware. It has...
Proxyjacking turns your device, router, or home IP into a hidden residential proxy. Learn the signs, first checks, removal steps, and how to stop...
Over the past few months, researchers have been monitoring the activity of a Chinese threat actor using PlugX malware to target foreign and domestic...
Researchers have discovered a new form of malware called RedEnergy Stealer. It is categorized as Stealer-as-a-Ransomware but is not affiliated with the Australian company...
Dark web malware now runs on stealer logs, stolen credentials, MaaS tools, and ransomware access. Learn the risks and what to do after a...