Threat research notebook

Gridinsoft Security Lab

Fresh malware notes, phishing samples, scam redirects, ransomware observations, and field reports from Gridinsoft research. No gallery, no filler: date, case, finding, next read.

291 lab records

Latest note ·

MassJacker Malware

Cybersecurity researchers have found MassJacker, a new, previously undocumented malware. It targets a predominantly freebie-seeking audience, i.e. users of pirated content. MassJacker Malware Targets Piracy Users MassJacker is a recently discovered malware that targets...

Field note ·

Jupiter Airdrop Scam

Jupiter Airdrop scam is an alleged crypto-airdrop campaign that promises free crypto tokens, yet in return...

Research log

02

AlrustiqApp.exe Virus (Alrustiq Service)

Record ·

AlrustiqApp.exe, also shown as Alrustiq Service, can indicate a miner-like unwanted app. Learn what to check in Task Manager, Services, Startup Apps, and how...

03

Nnice Ransomware

Record ·

Nnice ransomware is a malware strain that aims at encrypting user files and demanding ransom payment for their decryption. Detected on January 14, 2025,...

04

What is Unsecapp.exe and Should I Remove It?

Record ·

Unsecapp.exe is a legitimate Windows process tied to WMI (Windows Management Instrumentation). It often appears in Task Manager only when another app uses WMI,...

05

Contacto Ransomware

Record ·

Contacto virus is a newly identified ransomware strain that encrypts victims’ files and demands a ransom for their decryption. We identified this sample on...

07

RDPLocker Ransomware

Record ·

RDPLocker is a virus that encrypts the files and demands for a ransom payment for their decryption. It was first detected on malware analysis...

09

Audiodg.exe High CPU: What It Is and How to Fix It

Record ·

Audiodg.exe is the Windows Audio Device Graph Isolation process. It is a legitimate Microsoft component that lets Windows run audio effects, enhancements, spatial sound,...

10

Are AI Deepnude Sites Safe?

Record ·

AI deepnude sites can expose photos, accounts, payments, and consent-sensitive images. Learn the privacy, scam, malware, and reporting risks before uploading anything.

11

MicrosoftHost.exe

Record ·

MicrosoftHost.exe is a malicious process that the malware creates to disguise itself as a benign process. Users may witness high CPU load coming from...

12

AlienWare Ransomware

Record ·

AlienWare is a type of ransomware designed to lock your files and hold them hostage until you pay up. It’s sneaky and frustrating, leaving...

13

Trojan:Win32/Pomal!rfn Removal

Record ·

Defender flagged Trojan:Win32/Pomal!rfn? Learn how to check the file path, source, signature, false-positive signs, MSERT scan, and safe removal steps.

14

Novalock Ransomware

Record ·

Novalock is a sophisticated form of malware designed to encrypt your files and then demand payment for their release. It belongs to the Globeimposter...

15

Locklocklock Ransomware

Record ·

Locklocklock is a ransomware virus designed to lock your files and demand payment to restore access. Victims can identify encrypted files by the addition...

16

Trojan:Win32/Patched

Record ·

Trojan:Win32/Patched refers to a detection for modified versions of legitimate programs. Often such modifications are made to add malicious functionality to a program. Trojan:Win32/Patched...

AI Assistant

Hello! 👋 How can I help you today?