SvcHostUpdate.exe in Startup: The MythicalsGames Backdoor
SvcHostUpdate.exe in Windows Startup matches a malicious web3-token-helper chain. Learn what the…
Joyfill npm Packages Compromised: Six Malicious Versions
Six prerelease versions of @joyfill/components and @joyfill/layouts carried an import-time RAT and…
TONResolver RAT Removal: Fake Booking.com Photo Trap
Learn how TONResolver reaches hotel PCs through fake guest-complaint photos, how to…
MedusaHVNC Hijacks Browser Sessions on a Hidden Desktop
BlackFog analyzed MedusaHVNC, a Windows RAT that opens a browser on an…
MarkiRAT Malware Removal: Fake VPNs and svehost.exe
MarkiRAT hides in fake VPN and media-player installers. Check svehost.exe, BITS jobs,…
TrickBot Uses DNS Tunneling to Hide Windows C2 Traffic
A current TrickBot variant hides C2 data in DNS queries and persists…
Trojan:Win32/Commando.A!ml: What It Means and How to Stop Repeated Alerts
Trojan:Win32/Commando.A!ml can be malicious or a false positive. Check the PowerShell command,…
OTTERCOOKIE Malware Hides in SVG Files in Fake Coding Tests
Fake coding-test repositories hide OTTERCOOKIE fragments in SVG flags. Here is what…
Starland RAT Hides in Fake Zoom and WebEx Installers
Starland RAT hides in trojanized Zoom, WebEx, and other Windows installers. Check…
Win32:Trojan-gen Avast Detection: Malware or False Positive?
Win32:Trojan-gen is a generic Avast or AVG trojan verdict. Use the file…
Trojan:Win64/Lazy.PGLI!MTB: Meaning and Removal
Trojan:Win64/Lazy.PGLI!MTB keeps returning? Read the affected item, separate file, process, and history…
Trojan:Win32/BypassUAC!rfn: Meaning and Removal
Defender found Trojan:Win32/BypassUAC!rfn? Check the affected path, quarantine status, false-positive signals, recurring…
