Windows Security Certificate Expired/Invalid Pop-Up Scam: XWorm RAT Warning
Seeing a Windows Security Certificate Expired/Invalid page? It is a fake certificate…
Millenium RAT v4 Hits 62K Devices via Telegram C2
Group-IB says Millenium RAT v4 infected more than 62,000 Windows devices through…
ScreenConnect Client Scam: Remove Unexpected Remote Access
Found ScreenConnect Client or ConnectWise Control after a call, email, or fake…
Social Security Statement Email Scam Uses ScreenConnect
A June 2026 fake Social Security Statement email used a t.co link,…
Tiflux RMM Malware: Unauthorized Remote Access Cleanup
Unexpected Tiflux RMM after a service-agreement email can mean unauthorized remote access.…
Potemkin Loader Turns ClickFix Into 11-Host Intrusion
A ClickFix command dropped Potemkin Loader, RMMProject and EtherRAT across 11+ hosts.…
Argamal RAT in Game Archives
Kaspersky found Argamal RAT hidden in trojanized adult-game downloads. Check ZIP archives,…
Nimbus RAT Teams Vishing
Nimbus RAT now rides a Teams vishing and Quick Assist chain. See…
DesckVB RAT Malspam
DesckVB RAT malspam abuses DoubleClick redirects before dropping a ZIP, script loader,…
nethost.dll ProtonVPN Cleanup
Found nethost.dll beside ProtonVPN.exe or a fake VPN folder? Learn how to…
DenoRAT Malware: ClickFix, DinDoor and NightshadeC2
DenoRAT is a Deno-based RAT and stealer delivered through ClickFix, DinDoor, and…
KongTuke Uses Microsoft Teams Help-Desk Lures to Drop ModeloRAT
KongTuke moved from web-based ClickFix lures into external Microsoft Teams chats, using…
