Exploited now
6 this week
Data breaches
Neogen
Is it safe?
check a site
Browser updates
Chrome 155.0.8059.40
Scam emails
examples
12,230
guides
5,455
members
Removal guides
Pop-ups & adware
Browser hijackers
Ransomware
Trojans & backdoors
Spyware & keyloggers
Rogue anti-spyware
Malware
Unwanted programs
Scams
Scam alerts
Fake alerts
News
Malware news
Data breaches
Exploited flaws
Browser security
Security
Browsers & vulnerabilities
General
Software
Files
System files
Spyware-related files
Log in
Exploited now
6 this week
Data breaches
Neogen
Is it safe?
check a site
Browser updates
Chrome 155.0.8059.40
Scam emails
examples
Now
10 Oct
service@paypal scam: fake PayPal invoices with a callback number, and what to do
10 Oct
McDonald's Monopoly scam: the 2001 fraud, fake prize messages and what to do
10 Oct
FedEx scam: fake delivery texts, e-mails and calls and what to do
10 Oct
armoniamiddleeast.ae: a site that served fake Chrome installers for Windows, and what to do
10 Oct
royalcuts.co.uk: a barber shop site that served fake Chrome installers and CoinMiner files, and what to do
10 Oct
0807.st: archives tagged SmartLoader and Stealc, and what to do if you ran one on Windows
10 Oct
cablewireltd.site: a Windows VIP Keylogger host serving Crypted.ps1 PowerShell files, and what to do if one ran
10 Oct
Facebook Messenger Malware Flaw: 2026 Status and Safety
2-Spyware — page 10
Top today
TYPE
General
FILED
Oct 7, 2026
General
Discord Blocked in Russia and Turkey: 2026 Status and Risks
General
Discord Blocked in Russia and Turkey: 2026 Status and Risks
Discord is still blocked in Russia and Turkey in 2026. Why both bans happened, the timeline, VPN rules, fake unblocker malware and safe steps.
2-Spyware Editorial Team ·
Oct 7, 2026
URL
hxxp://aqclqkcfjwbgknkwnvmm[.]supabase[.]co
TYPE
Trojans
RISK
High
HITS
Windows
FILED
Oct 6, 2026
Trojans · High risk
aqclqkcfjwbgknkwnvmm
[.]supabase
[.]co
Trojans
High risk
Remove aqclqkcfjwbgknkwnvmm.supabase.co: a Supabase storage bucket that served SilentNet .jar files, and what to do if you ran one on Windows
aqclqkcfjwbgknkwnvmm.supabase.co is one customer project on Supabase, a legitimate cloud storage service. On 5 October 2026 URLhaus listed three .jar files in its public…
Ugnius Kiguolis ·
Oct 6, 2026
URL
hxxp://www[.]tmcksa[.]com
TYPE
Trojans
RISK
High
HITS
Windows
FILED
Oct 6, 2026
Trojans · High risk
www
[.]tmcksa
[.]com
Trojans
High risk
Remove www.tmcksa.com: a hacked site serving a PowerShell stub for the Formbook stealer, and what to do if your PC ran it
www.tmcksa.com is a website registered in 2013 that URLhaus listed three times on 5 October 2026 for a PowerShell script, secured_stub.ps1, tagged Formbook. Formbook is a Windows…
Ugnius Kiguolis ·
Oct 6, 2026
URL
hxxp://astroliper[.]ac
TYPE
Trojans
RISK
High
HITS
macOS
FILED
Oct 6, 2026
Trojans · High risk
astroliper
[.]ac
Trojans
High risk
Remove astroliper.ac: a botnet file server for Linux machines entered through SSH, and what to do
astroliper.ac is a web address that URLhaus lists four times for nodewatchd, one Linux program built for four processor types and tagged ssh: the kind of file botnets put on…
Ugnius Kiguolis ·
Oct 6, 2026
TYPE
Security
FILED
Oct 6, 2026
Security
Why Am I Getting Russian Ads on YouTube? What to Do (2026)
Security
Why Am I Getting Russian Ads on YouTube? What to Do (2026)
Why you get Russian ads on YouTube: Google language, location and history signals, the real signs of adware, and the settings that change what you see.
2-Spyware Editorial Team ·
Oct 6, 2026
URL
hxxp://click[.]liftoff[.]io
TYPE
AD
RISK
Medium
HITS
Windows
FILED
Oct 6, 2026
AD · Medium risk
click
[.]liftoff
[.]io
AD
Medium risk
Remove click.liftoff.io on iPhone and Android: what it is and how to stop Liftoff ads
Ugnius Kiguolis ·
Oct 6, 2026
URL
hxxp://thisisafalsepositive[.]st
TYPE
Trojans
RISK
High
HITS
Windows
FILED
Oct 6, 2026
Trojans · High risk
thisisafalsepositive
[.]st
Trojans
High risk
Remove thisisafalsepositive.st: a SilentNet stealer server behind fake Minecraft mods, and how to clean a Windows PC
Ugnius Kiguolis ·
Oct 6, 2026
URL
hxxp://www[.]beinke-aufzuege[.]de
TYPE
Trojans
RISK
High
HITS
Windows
FILED
Oct 6, 2026
Trojans · High risk
www
[.]beinke-
aufzuege
[.]de
Trojans
High risk
Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them
Ugnius Kiguolis ·
Oct 6, 2026
URL
hxxp://flocmaterials[.]shop
TYPE
Trojans
RISK
High
HITS
Windows
FILED
Oct 6, 2026
Trojans · High risk
flocmaterials
[.]shop
Trojans
High risk
Remove flocmaterials.shop: a new server that handed out PowerShell scripts for VIP Keylogger, and what to do if one ran
Ugnius Kiguolis ·
Oct 6, 2026
URL
hxxp://qpwot[.]cfd
TYPE
Trojans
RISK
High
HITS
Windows
FILED
Oct 6, 2026
Trojans · High risk
qpwot
[.]cfd
Trojans
High risk
Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran
qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger,…
Ugnius Kiguolis ·
Oct 6, 2026
URL
hxxp://fujeigroup[.]com
TYPE
TR
RISK
High
HITS
Windows
FILED
Oct 6, 2026
TR · High risk
fujeigroup
[.]com
TR
High risk
Remove fujeigroup.com: a server handing out picture files that hide AsyncRAT, and what to do if a loader fetched them
fujeigroup.com is a web address that URLhaus lists seven times in one week for picture files (img_*.png on port 8888) tagged stego, and four of them tagged AsyncRAT, a remote…
Ugnius Kiguolis ·
Oct 6, 2026
URL
hxxp://aksiyononline[.]best
TYPE
Trojans
RISK
High
HITS
Windows
FILED
Oct 6, 2026
Trojans · High risk
aksiyononline
[.]best
Trojans
High risk
Remove aksiyononline.best: a server handing out PowerShell stubs for MassLogger and VIP Keylogger, and what to do if a script fetched them
aksiyononline.best is a web address that URLhaus lists thirteen times for PowerShell and JavaScript files named Crypted.ps1 and secured_stub.ps1, three of them tagged MassLogger…
Ugnius Kiguolis ·
Oct 6, 2026
URL
hxxp://loop-lumen[.]com
TYPE
TR
RISK
High
HITS
macOS
FILED
Oct 6, 2026
TR · High risk
loop-
lumen
[.]com
TR
High risk
Remove loop-lumen.com: a Mac stealer download site (AMOS, ClickFix) and what to do if you pasted its command
loop-lumen.com is a website that URLhaus lists for serving Mac malware tagged AMOS (Atomic macOS Stealer) and ClickFix, and it answered our test with a Cloudflare 520 error. If…
Ugnius Kiguolis ·
Oct 6, 2026
TYPE
Data breaches
FILED
Oct 6, 2026
Data breaches
Pentagon DMDC Data Breach 2026: Who Is Affected, What To Do
Data breaches
Pentagon DMDC Data Breach 2026: Who Is Affected, What To Do
Pentagon DMDC breach: 2.76M living and 294K deceased people hit, Social Security numbers exposed. See who is affected and the free steps to take now.
2-Spyware Editorial Team ·
Oct 6, 2026
URL
hxxp://foritatoginia[.]com
TYPE
Adware
RISK
Medium
HITS
Windows
FILED
Oct 16, 2025
Adware · Medium risk
foritatoginia
[.]com
Adware
Medium risk
Remove Foritatoginia.com ads
Alice Woods ·
Oct 16, 2025
TYPE
Malware
RISK
High
HITS
Windows
FILED
Oct 16, 2025
Malware · High risk
Account Validation Request email scam
Malware
High risk
Remove Account Validation Request email scam
Olivia Morelli ·
Oct 16, 2025
URL
hxxp://dopotics[.]com
TYPE
Adware
RISK
Medium
HITS
Windows
FILED
Jun 9, 2025
Adware · Medium risk
dopotics
[.]com
Adware
Medium risk
Remove Dopotics.com ads
Linas Kiguolis ·
Jun 9, 2025
TYPE
Malware
RISK
High
HITS
Windows
FILED
Jun 5, 2025
Malware · High risk
"Take Immediate Action" email scam
Malware
High risk
Remove "Take Immediate Action" email scam
Olivia Morelli ·
Jun 5, 2025
URL
hxxp://hotbzitoza[.]today
TYPE
Adware
RISK
Medium
HITS
Windows
FILED
Jun 4, 2025
Adware · Medium risk
hotbzitoza
[.]today
Adware
Medium risk
Remove Hotbzitoza.today ads
Hotbzitoza.today push ads may redirect users to dangerous and misleading websites Hotbzitoza.today is another scam website that aims to misuse browser push notifications for…
Lucia Danes ·
Jun 4, 2025
URL
hxxp://prumphortry[.]com
TYPE
Adware
RISK
Medium
HITS
Windows
FILED
Jun 3, 2025
Adware · Medium risk
prumphortry
[.]com
Adware
Medium risk
Remove Prumphortry.com ads
Prumphortry.com tricks users into enabling disruptive push notifications through misleading prompts Prumphortry.com is part of a growing network of websites designed to abuse the…
Olivia Morelli ·
Jun 3, 2025
URL
hxxp://warhesageltil[.]com
TYPE
Adware
RISK
Medium
HITS
Windows
FILED
Jun 2, 2025
Adware · Medium risk
warhesageltil
[.]com
Adware
Medium risk
Remove Warhesageltil.com ads
Warhesageltil.com misleads users into enabling intrusive push notifications with deceptive prompts Warhesageltil.com is part of a broader tactic involving misleading websites that…
Jake Doevan ·
Jun 2, 2025
TYPE
Adware
RISK
Medium
HITS
Mac
FILED
May 29, 2025
Adware · Medium risk
OperativeNavigation Mac
Adware
Medium risk
Remove OperativeNavigation Mac virus
OperativeNavigation is a malicious Mac application that can take over your device to push ads OperativeNavigation is a potentially unwanted application and browser extension that…
Julie Splinters ·
May 29, 2025
URL
hxxp://stylegridconnect[.]com
TYPE
Adware
RISK
Medium
HITS
Windows
FILED
May 28, 2025
Adware · Medium risk
stylegridconnect
[.]com
Adware
Medium risk
Remove Stylegridconnect.com scam
Stylegridconnect.com is a fake website that claims your system has been infected with viruses Stylegridconnect.com is a phishing website that mimics real security alerts, falsely…
Olivia Morelli ·
May 28, 2025
URL
hxxp://hastenupdevice[.]co[.]in
TYPE
Adware
RISK
Medium
HITS
Windows
FILED
May 27, 2025
Adware · Medium risk
hastenupdevice
[.]co
[.]in
Adware
Medium risk
Remove Hastenupdevice.co.in scam
Gabriel E. Hall ·
May 27, 2025
URL
hxxp://enhancechain-flow[.]com
TYPE
Adware
RISK
Medium
HITS
Windows
FILED
May 26, 2025
Adware · Medium risk
enhancechain-
flow
[.]com
Adware
Medium risk
Remove Enhancechain-flow.com ads
Ugnius Kiguolis ·
May 26, 2025
TYPE
Malware
RISK
High
HITS
Windows
FILED
May 22, 2025
Malware · High risk
Resolv Discord Verification scam
Malware
High risk
Remove Resolv Discord Verification scam
Lucia Danes ·
May 22, 2025
URL
hxxp://croursem[.]co[.]in
TYPE
Adware
RISK
Medium
HITS
Windows
FILED
May 21, 2025
Adware · Medium risk
croursem
[.]co
[.]in
Adware
Medium risk
Remove Croursem.co.in ads
Jake Doevan ·
May 21, 2025
Loading…
No more articles
Could not load, try again
Try again
« Previous
1
…
8
9
10
11
12
…
472
Next »
5,455 members already here
Reading, writing, commenting and voting. 0 verified · 180 joined this year
All members
Join
News
Members
Publish
Me