Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

297 lab records

Latest note ·

FBI Issues Online File Converter Malware Scam Warning

The FBI Denver Field Office has warned about a growing scam involving free online file converter tools, which appears to be a significant cybersecurity concern. These tools, while converting files as advertised, often distribute...

Field note ·

Trojan:Win64/RustyStealer.DSK!MTB

Trojan:Win64/RustyStealer.DSK!MTB is a sophisticated malware designed to infiltrate 64-bit Windows systems, primarily focusing on stealing sensitive...

Field note ·

TrojanProxy:Win32/Acapaladat.B

TrojanProxy:Win32/Acapaladat.B is a type of malware that hides in free, unauthorized VPN applications, turning infected computers...

Field note ·

OneStart Browser

OneStart is a rogue program that is presented as a Chromium-based browser with AI features, such...

Research log

01

EpiBrowser (EpiStart)

Record ·

Should you remove EpiBrowser? You should remove EpiBrowser or EpiStart if it appeared without clear consent, replaced your default browser, redirected searches, or came...

02

The Alarming Rise of DeepSeek Scams

Record ·

The release of DeepSeek AI chatbot gave a push for an enormous number of DeepSeek scams that trick users in a variety of shady...

04

Jupiter Airdrop Scam

Record ·

Jupiter Airdrop scam is an alleged crypto-airdrop campaign that promises free crypto tokens, yet in return only empties users’ crypto wallets. Parasiting on the...

06

AlrustiqApp.exe Virus (Alrustiq Service)

Record ·

AlrustiqApp.exe, also shown as Alrustiq Service, can indicate a miner-like unwanted app. Learn what to check in Task Manager, Services, Startup Apps, and how...

07

Nnice Ransomware

Record ·

Nnice ransomware is a malware strain that aims at encrypting user files and demanding ransom payment for their decryption. Detected on January 14, 2025,...

09

Contacto Ransomware

Record ·

Contacto virus is a newly identified ransomware strain that encrypts victims’ files and demands a ransom for their decryption. We identified this sample on...

11

RDPLocker Ransomware

Record ·

RDPLocker is a virus that encrypts the files and demands for a ransom payment for their decryption. It was first detected on malware analysis...

13

Audiodg.exe High CPU: What It Is and How to Fix It

Record ·

Audiodg.exe is the Windows Audio Device Graph Isolation process. It is a legitimate Microsoft component that lets Windows run audio effects, enhancements, spatial sound,...

14

Are AI Deepnude Sites Safe?

Record ·

AI deepnude sites can expose photos, accounts, payments, installs, and consent-sensitive images. Check privacy, scam, malware, and reporting risks before uploading anything.

15

MicrosoftHost.exe

Record ·

MicrosoftHost.exe is a malicious process that the malware creates to disguise itself as a benign process. Users may witness high CPU load coming from...

16

AlienWare Ransomware

Record ·

AlienWare is a type of ransomware designed to lock your files and hold them hostage until you pay up. It’s sneaky and frustrating, leaving...

AI Assistant

Hello! 👋 How can I help you today?