Cloudinary virus: why res.cloudinary.com shows up in malware alerts, and what to do if a loader fetched its pictures

Cloudinary is a legitimate image hosting service, not a virus, but criminals upload JPG pictures that hide malware and point loaders at them. In September 2026 URLhaus listed eleven such pictures on res.cloudinary.com, seven tagged RemcosRAT and one PureLogsStealer. If you only saw the address in a log, nothing is proven. If a program on your Windows PC fetched one, act now.

Facts checked October 8, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.

Automatic

Get a free scan and check if your PC is infected.

Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.

Programs like a script, loader or program that downloads JPG pictures from res.cloudinary.com usually arrive in groups; a free scan lists the companions that are easy to miss.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.

Do it yourself · free Remove Cloudinary virus (malware hidden in pictures on res.cloudinary.com) yourself 5 steps, about 15 minutes, no software needed.

Start the steps
Timeline of eleven URLhaus reports for pictures on res.cloudinary.com in September 2026 with account names and tags
The eleven URLhaus reports for res.cloudinary.com, September 2026. There is no screenshot of a site here: the service hosts pictures, and our check was a plain request from our server.

Cloudinary virus (malware hidden in pictures on res.cloudinary.com): summary

TypeA legitimate image service abused to host JPG pictures that hide Remcos and PureLogs malware
RiskHigh if a loader on your PC fetched one of the pictures. None if you only saw res.cloudinary.com in a log or on a website
SymptomsOften none. Unknown Run key entries, msbuild.exe or caspol.exe running with no reason, a Defender alert
How to get rid of itChange passwords from another device, run Microsoft Defender Offline, remove startup entries, reset Windows if unsure
Our check (8 October 2026)Plain request from our server: HTTP 404 from Cloudinary at the bare address. Reported pictures not requested
PlatformWindows. Nothing we read says Mac or phones are affected
Removal

Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged.

Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free.
Show 8 more facts
Detection namesMicrosoft uses Backdoor:Win32/Remcos for Remcos. We found no published Microsoft name for these eleven exact files; we did not scan them
NameCloudinary virus
Domain registered24 May 2011
Evidence11 write-ups by security sites; details still limited
First seen9 September 2026
DistributionTypically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps
DamageInstalls other malware, often several programs at once
Facts checked8 October 2026

Facts checked on 8 October 2026 against the URLhaus data for res.cloudinary.com in our job record, RDAP, one plain request from our server (no browser), Cloudinary's documentation and Acceptable Use Policy, and reports by Microsoft, MITRE ATT&CK, K7 Labs, Seqrite and ANY.RUN. We did not download the pictures and infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.

What Cloudinary is, and why its address shows up in malware reports

Cloudinary is not a virus. It is a legitimate image and video hosting service that many online shops, news sites and apps use to store and resize their pictures, and res.cloudinary.com is the address those pictures are served from. Anyone can open an account and upload files, and criminals sometimes do. They upload JPG pictures that hide malware code and then point a loader at the picture's address, because a download from a well known image service looks harmless.

In September 2026 the abuse.ch project URLhaus listed eleven such pictures on res.cloudinary.com, spread over six accounts. Seven were tagged RemcosRAT, a remote access trojan for Windows, one was tagged PureLogsStealer, and nine carried the tag stego, which means data hidden inside the picture. All eleven were offline when we read the data on 8 October 2026.

  1. 1

    What URLhaus lists

    Eleven JPG files on res.cloudinary.com, all under image/upload, named img_ followed by six digits and sometimes a short random suffix. They were added between 9 and 24 September 2026, all with the threat label malware_download and the reporter abuse_ch. Every one is marked offline.

  2. 2

    What the tags mean

    stego is short for steganography: code hidden inside another file, here a picture. RemcosRAT is a remote access trojan, a program that lets a stranger control a Windows PC. rat means the same. PureLogsStealer is a password and wallet stealer. One file carries no tag at all.

  3. 3

    What we could not confirm

    We did not download the pictures, so we cannot tell you what is inside them or where the trojans report to. We do not know which email or program made a victim's PC ask for these pictures. That first step is not visible from the server side.

  4. 4

    What this means for you

    If you only saw res.cloudinary.com in a log or a blocked request, nothing is proven: almost every request to it is a normal website loading a normal picture. The risk is for a PC where a loader already ran and fetched one of these files.

Kind of threat
Malware hidden in JPG pictures on a legitimate image service: seven tagged RemcosRAT, one PureLogsStealer
The service
Cloudinary, an image and video hosting service. cloudinary.com was registered on 24 May 2011 through GoDaddy.com, LLC (RDAP, read 8 October 2026)
Where the files were
hxxps://res.cloudinary[.]com/<account>/image/upload/v<upload time>/img_NNNNNN.jpg in six accounts: leowxn6s, slwv2ypq, tll9jvom, te9euryt, ohmsggn3 and rpfuztjy
URLhaus entries
11 file addresses, added 9 to 24 September 2026; all 11 offline on 8 October 2026
Delivery trick
Steganography: code hidden in a picture so the download looks like an image. A loader already on the PC fetches it
Platform
Windows. MITRE lists Remcos as Windows only. Nothing we read says these pictures affect Mac, iPhone or Android

What Cloudinary virus (malware hidden in pictures on res.cloudinary.com) does on an infected PC

What we checked on 8 October 2026, and what we could not

We sent one plain request from our server to https://res.cloudinary.com/ on 8 October 2026, with no browser and no clicks. It answered HTTP 404 from a server that names itself Cloudinary. That is normal: the bare address has no page, only the pictures under it do. It does not test the eleven reported files, and a quiet answer clears nothing.

Our check, 8 October 2026

  • The service answers normallyHTTP 404 at the bare address, server header Cloudinary, no redirect, no notification request.
  • Domain registrationcloudinary.com, registered 24 May 2011 through GoDaddy.com, LLC, with delete, renew, transfer and update locks. That is what a real company's domain looks like.
  • URLhaus listingEleven JPG files tagged RemcosRAT, PureLogsStealer, rat and stego, added 9 to 24 September 2026.
  • Are the files still served?All eleven are marked offline. That usually means the account or the file was removed.
  • What we did not doWe did not download the pictures or run anything. New accounts with new pictures can appear at any time.

Safe service, abused by some account holders res.cloudinary.com is a legitimate image service used by many websites. The danger is in specific pictures that criminals upload and that a loader on an infected PC fetches. Judge the full link and the program that asked for it, not the domain.

The eleven reports, in order

Every Cloudinary link carries a version number that the documentation says is the timestamp of the upload. Comparing it with the URLhaus date shows how fast the pictures were found. Times are UTC.

  1. 24 May 2011

    cloudinary.com is registered

    RDAP shows the domain registered on 24 May 2011 through GoDaddy.com, LLC.

  2. 9 September 2026

    Two pictures in the account leowxn6s

    Uploaded just after midnight UTC and added by abuse_ch at about 08:13 and 08:14 the same day. Both tagged RemcosRAT and rat, one also stego.

  3. 14 September 2026

    Five pictures in two accounts

    Four pictures in slwv2ypq, uploaded between about 02:02 and 08:01 UTC; two tagged RemcosRAT and stego, two only stego. One picture in tll9jvom, uploaded at about 05:54 UTC and tagged PureLogsStealer and stego.

    Timeline of eleven URLhaus reports for pictures on res.cloudinary.com between 9 and 24 September 2026 with account names and tags
    The eleven URLhaus reports for res.cloudinary.com, September 2026, in six accounts.
  4. 15 September 2026

    One picture with no tag

    In the account te9euryt, uploaded at about 10:52 UTC and added at about 15:38 UTC. URLhaus gives it no family tag.

  5. 22 September 2026

    Two pictures in ohmsggn3

    Uploaded on 21 and 22 September and added the same afternoon or the next day. Both tagged RemcosRAT, rat and stego.

  6. 24 September 2026

    The last one, in rpfuztjy

    Uploaded at about 05:19 UTC, added at about 13:47 UTC, tagged RemcosRAT, rat and stego.

  7. 8 October 2026

    All offline, and our check

    All eleven entries are offline. Our plain request to the bare address gets Cloudinary's normal 404.

Our reading of the pattern: six new accounts in two weeks, each used for one to four pictures and each found within hours, fits an operator who opens fresh free accounts as old ones are closed. That is an inference from the names and dates, not something a report states.

How criminals use Cloudinary, and why a picture is their choice

A picture that hides code cannot hurt you by being looked at. It works only when a loader that is already running reads the hidden part and starts it. Cloudinary is chosen because it is free to start, fast and trusted.

Four steps: a phishing attachment, a loader running on the PC, a JPG fetched from res.cloudinary.com, and Remcos or PureLogs running in memory
The picture trick in four steps, as vendors describe it. We did not see the first step for these files.
  1. 1

    An account makes a public address

    Cloudinary's documentation gives the delivery pattern res.cloudinary.com/<cloud_name>/<asset_type>/<delivery_type>/<version>/<public_id>.<extension>. The cloud name is the account, and the version is the upload timestamp. Any uploaded picture gets such a public link at once.

  2. 2

    A loader asks for the picture

    Seqrite (17 March 2025) described a phishing Excel file that leads to a script which downloads a JPG with base64 text between the markers <<BASE64 START>> and <<BASE64 END>>, decodes a loader from it and then injects Remcos into a trusted Windows program such as caspol.exe or msbuild.exe.

  3. 3

    The payload runs in memory

    K7 Labs (22 June 2026, updated 30 July) described a Remcos chain from an archive attached to a phishing email, with stages hidden in a .NET Bitmap and loaded in memory, ending in Remcos running inside the default browser process.

  4. 4

    It breaks Cloudinary's rules

    Cloudinary's Acceptable Use Policy, last updated 12 September 2024, forbids using the service to transmit malware or to upload content with viruses, Trojans or other harmful code, and asks people to report abuse.

What Remcos and PureLogs are

Seven of the eleven pictures were tagged RemcosRAT and one PureLogsStealer. Both are sold to criminals and both target Windows.

QuestionWhat the sources saySource
What is Remcos?A closed source tool marketed as remote control and surveillance software by a company called Breaking Security, seen in many malware campaignsMITRE ATT&CK S0332, modified 23 April 2026
What can Remcos do?Log keys, take screenshots, use the webcam and microphone, read the clipboard, move and delete filesMicrosoft Backdoor:Win32/Remcos; MITRE
How does Remcos stay?A registry Run key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run; K7 Labs also saw winlogon and userinit entries and a hidden copy in AppData\RoamingMITRE; K7 Labs
What is PureLogs?A stealer that takes browser data, saved passwords, crypto wallets, files, clipboard contents, screenshots and keystrokes, often delivered by the PureCrypter loaderANY.RUN malware trends
Which system?Windows. MITRE lists Remcos for Windows onlyMITRE

What Cloudinary virus (malware hidden in pictures on res.cloudinary.com) can steal or download

What these trojans can take from a Windows PC

A remote access trojan gives a stranger a seat at your computer. The list is what the sources say is possible, not what one build does automatically.

Reported as possible

  • Every key you type
  • Screenshots
  • Webcam pictures
  • Microphone audio
  • Clipboard contents
  • Saved browser passwords and cookies
  • Crypto wallets
  • Files moved or deleted
DataDetailSource
Keystrokes and screenKeylogging and automated screenshotsMITRE; Microsoft
Camera and soundWebcam pictures and microphone recordingMITRE; Microsoft
Browser loginsChrome logins and cookies, Firefox credentialsK7 Labs
Wallets and filesPureLogs takes wallets and files by folder and extensionANY.RUN

What this can cost you

Seeing the address costs nothing. These risks apply to a Windows PC where a loader fetched one of these pictures and the trojan ran.

  • High

    Passwords and accounts

    A keylogger records every password you type, including new ones set on the same PC.

  • High

    Someone using your PC live

    The controller can come back, watch the screen and act while you are logged in.

  • High

    Crypto and banking

    Wallet theft cannot be reversed, and a banking session opened on the PC can be watched.

  • Medium

    Private files, camera and microphone

    Documents can be taken, and the camera and microphone can be used.

  • Low

    Nothing, if you only saw the name

    A request to res.cloudinary.com in a log is almost always a normal website picture.

How to check the PC for Cloudinary virus (malware hidden in pictures on res.cloudinary.com)

How to tell a bad Cloudinary link from a normal one

The domain tells you nothing either way. Look at who asked for the picture and what the link looks like.

SignNormal useAbuse in the reports
Who asks for itYour browser, while showing a shop or news pageA script, PowerShell, wscript.exe or an unknown program
The account nameOften the brand's own nameEight random letters and digits, such as slwv2ypq
The file nameA product or article name, often with resize options in the pathimg_ plus six digits, sometimes with a random suffix
When you see itWhile a picture appears on a pageIn a firewall or antivirus alert with no page open
What followsNothingA new startup entry, a trusted program using the network, a Defender alert

Check your PC before you delete anything

The question that matters: did a program on this PC, not your browser, ask for one of these pictures, or did you open an unexpected attachment? If not, and you only saw the address in a log, you can stop here. If yes, or you are not sure, do these checks. None deletes anything.

Use another device for banking, email and work until you finish.

  1. 1

    Disconnect first

    Turn off Wi-Fi or unplug the cable. A remote access trojan needs the connection to be used.

  2. 2

    Look at Protection history

    Open Windows Security > Virus & threat protection > Protection history. A detection named Backdoor:Win32/Remcos or one naming PureLogs is a firm sign.

  3. 3

    Check the Run key

    Open Registry Editor and go to HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run. MITRE says Remcos adds itself there. Note any entry that points into AppData\Roaming with a random name.

  4. 4

    Check Startup apps and Task Manager

    Open Settings > Apps > Startup, then Task Manager. A trusted program such as msbuild.exe or caspol.exe running with no reason is worth a note, since Seqrite saw Remcos hidden in them.

  5. 5

    Look at recent attachments

    Think back to an archive, an Excel file or an invoice you opened around the time of the alert. That is the likely start.

How to remove Cloudinary virus (malware hidden in pictures on res.cloudinary.com)

How to remove Cloudinary virus

A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.

  1. Step 1: Delete scheduled tasks that bring it back

    Open Task Scheduler from the Start menu and click Task Scheduler Library. Select each task you do not recognise and read the Actions tab:

    • a task that starts a file in %AppData% or %Temp%
    • runs powershell with a long encoded line
    • opens a web address belongs to Cloudinary virus or a similar program

    Right-click such a task and choose Delete, and check the subfolders too. Leave tasks from Microsoft, your PC's maker and programs you use. Task Scheduler is the same in Windows 11 and Windows 10.

    Task Scheduler Library with a task selected and its Actions tab showing the program it starts
    Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  2. Step 2: Remove it from startup

    Whatever Cloudinary virus installed usually starts with Windows. Open Task Manager with Ctrl + Shift + Esc, go to Startup apps in Windows 11 or the Startup tab in Windows 10, and disable what you do not know, starting with entries that have an empty Publisher column.

    Open file location on the right-click menu shows the file, which helps you decide and tells you what to delete later. Disabling is safe: if something you need stops working, switch it back on.

    Full procedure with screenshots: Stop apps from opening at startup On uGetFix

  3. Step 3: Delete the folders left behind

    What the uninstaller leaves behind is usually in the user folders. Open File Explorer, switch on View > Show > Hidden items (in Windows 10 View > Hidden items), and go through %LocalAppData%, %AppData%, %ProgramData% and the two Program Files folders.

    Sort by Date modified and delete folders that appeared together with the problem and belong to no program you use. Folders with random names that hold .exe, .dll, .js or .ps1 files are the strongest sign.

    Full procedure with screenshots: Remove what malware leaves behind in Windows

  4. Step 4: Scan the PC, then run the offline scan

    Open Windows Security > Virus & threat protection > Scan options, run a Full scan and remove everything it finds. Then select Microsoft Defender Antivirus (offline scan) and click Scan now: the PC restarts and scans before Windows loads, which finds files that hide while Windows runs.

    Save your work first, because the offline scan takes about 15 minutes. Both scans are built into Windows 11 and Windows 10, and a second scanner from another vendor is a useful extra opinion.

    Windows Security Scan options with Microsoft Defender Antivirus offline scan selected
    Windows 11: Windows Security > Virus & threat protection > Scan options.

    Full procedure with screenshots: Run a Microsoft Defender Offline scan

  5. Step 5: Change passwords from another device and sign out other sessions

    Assume that the passwords saved in this PC's browsers, and the accounts that were open in them, are known to the attacker. From a phone or a clean computer, change the e-mail password first, then banking, shopping, social and gaming accounts.

    Use each service's option to sign out of all other sessions, because stolen cookies keep a session open even after a password change. Turn on two-step verification on each account. Wait with the infected Windows 11 or Windows 10 PC until the scans are clean.

    Full procedure with screenshots: Turn on two-step verification / secure a hacked account

If you use a Mac, an iPhone or an Android phone

The tags and the sources describe Windows. Cloudinary pictures load on every device, but only a Windows loader can use the hidden code in these files.

Your deviceWhat we knowWhat to do
MacMITRE lists Remcos for Windows onlyNothing to remove for this threat. Do not follow the Windows steps on a Mac
iPhone or iPadNo source describes these files on iOSNothing to remove. Pictures from Cloudinary in apps are normal
AndroidNo source mentions them on AndroidNothing to remove for this threat

After removal: passwords, accounts and prevention

Your passwords after Cloudinary virus

Removing Cloudinary virus does not undo what it may already have sent out while the PC showed A script, loader or program that downloads JPG pictures from res.cloudinary.com in the list of installed apps. Treat saved browser passwords and logged-in sessions on this PC as known to the attacker.

From another device, change the e-mail password first and end all its sessions. Then do the same for the bank, PayPal, Microsoft, Google and Apple accounts. Stolen session cookies keep working after a password change until you sign out everywhere.

Move crypto to a new wallet created on a clean device. A step-by-step order for every kind of account is in our guide to account security after an infection.

After a clean PC: protect what was taken

Cleaning the PC does not undo what was sent. Do the account steps from another device first.

Five steps in order: disconnect the PC, change passwords from another device, run Defender Offline, remove startup items, reset Windows if unsure
The order of actions after a loader fetched one of these pictures. Steps follow Microsoft's pages; we did not test them on an infected PC.
  1. 1

    Change passwords from a clean device

    Start with email, then bank, work, cloud storage and crypto. Anything typed on the PC while the trojan ran is known.

  2. 2

    Sign out every session

    Use each account's option to sign out of all devices, and turn on two step sign in.

  3. 3

    Run Microsoft Defender Offline

    Open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Antivirus (offline scan) and Scan now. The PC restarts and scans before Windows loads; results are in Protection history.

  4. 4

    Reset Windows if you are not sure

    A remote access trojan may have added more programs. Settings > System > Recovery > Reset this PC with Remove everything is the sure way.

Keep a PC out of this kind of chain

The picture is the late part of the chain. Every report starts with a file a person opened.

Do

  • Treat an unexpected archive, invoice or Excel file that asks you to enable content as an attack.
  • Show file endings in File Explorer so a program posing as a document is visible.
  • Keep Windows and Microsoft Defender updated.
  • Use a password manager and two step sign in.
  • Report a bad picture link to Cloudinary through its support channel, citing its Acceptable Use Policy.

Don't

  • Do not block the whole of res.cloudinary.com: many shops and sites will lose their pictures.
  • Do not open attachments you did not expect, even from a known name.
  • Do not change passwords on the PC you suspect.
  • Do not treat a clean quick scan as proof.

Questions about Cloudinary virus (malware hidden in pictures on res.cloudinary.com)

Is Cloudinary a virus?

No. Cloudinary is a legitimate image and video hosting service used by many shops, news sites and apps, and its domain has been registered since 2011.

It shows up in malware reports because criminals open free accounts and upload pictures that hide code. The service is safe; some uploaded files are not. Its own rules forbid malware.

Why did my antivirus block res.cloudinary.com?

Most likely it blocked one picture address, not the whole service. Look at the full link and at the program named in the alert.

If your browser was showing a normal page, it may be a false alarm on that file. If the program was a script, PowerShell or something you do not know, treat the PC as possibly infected.

What files were reported on Cloudinary?

URLhaus lists eleven JPG pictures on res.cloudinary.com, added between 9 and 24 September 2026 in six accounts. Seven were tagged RemcosRAT, one PureLogsStealer, nine stego and one had no tag.

All eleven were offline on 8 October 2026. We did not download them, so we cannot show what is inside.

Can a picture from Cloudinary infect me if I just look at it?

No source we read says so. The hidden code in these pictures is only data until a loader that is already running on the PC reads it and starts it.

Your browser shows the picture and ignores the rest. The danger is the attachment or program that started the loader in the first place.

What is Remcos?

Remcos is a closed source tool sold as remote control and surveillance software and widely used by criminals. Microsoft detects it as Backdoor:Win32/Remcos and says it collects keystrokes, webcam images, screenshots and passwords. MITRE says it stays by adding itself to the current user's Run registry key, and lists it as a Windows tool.

What is PureLogs Stealer?

PureLogs is a stealer of the Pure family of malware tools. ANY.RUN says it takes browsing history, cookies and autofill data, saved passwords, crypto wallets and files, and is often delivered by the PureCrypter loader.

One of the eleven Cloudinary pictures was tagged with it. It targets Windows PCs: ANY.RUN describes Run key persistence and PowerShell, and its samples ran on Windows 10. Phishing emails and fake downloads are the usual way in.

How do I remove Remcos from a Windows PC?

Disconnect the PC, change your passwords from another device, then run Microsoft Defender Offline from Windows Security, Scan options. Look in the Run registry key and Startup apps for entries you do not know. If you are unsure that everything is gone, reset Windows with Remove everything, because a remote access trojan can add more programs.

Can I block Cloudinary to be safe?

Blocking res.cloudinary.com will break pictures on many shops and websites. It also does not remove a loader that is already on a PC.

A better step is to keep unexpected attachments closed, keep Defender updated, and in a company to watch which programs, other than browsers, download pictures. A script or msbuild.exe fetching a JPG is a strong warning sign.

How do I report a malicious Cloudinary picture?

Cloudinary's Acceptable Use Policy forbids malware and asks people to report abuse, though it names no address; use its support contact and give the full link. You can also submit the link to URLhaus at abuse.ch, which shares it with security vendors and network operators. Include the date and the program that asked for the picture if you know it.

Will Fortect remove Cloudinary virus?

Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.

For Cloudinary virus, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.

Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.

Sources

More removal guides

Remove porterneuman.mx: PowerShell and JavaScript files tied to the AveMaria remote access trojan, and what to do

porterneuman.mx is a web address where URLhaus found five script files in a WordPress plugin folder on 30 September 2026: four PowerShell stubs and one JavaScript file. One stub is tagged AveMariaRAT, a remote access...TrojansHigh riskUgnius Kiguolis ·

Remove Memz virus

Memz virus is the custom-made trojan that overwrites Windows boot sequence with Nyan Cat meme animation Memz virus is the trojan originally created by Leurak as viewer-made malware forTrojansHigh riskLucia Danes ·

Remove qpwot.cfd: a server handing out scripts that lead to the MassLogger and VIP Keylogger stealers, and what to do if one ran

qpwot.cfd is a web address that URLhaus listed seven times on 6 October 2026 for JavaScript files and PowerShell files named secured_stub.ps1, tagged MassLogger and VIPKeylogger, two keyloggers that steal passwords...TrojansHigh riskUgnius Kiguolis ·

Remove www.beinke-aufzuege.de: a hacked website hosting FormBook PowerShell stubs, and what to do if a script fetched them

www.beinke-aufzuege.de is the address of a German website that URLhaus lists for four PowerShell files tagged Formbook, a password stealer for Windows, hidden in random folders inside the site's own Joomla media...TrojansHigh riskUgnius Kiguolis ·

Questions and experiences: Cloudinary virus (malware hidden in pictures on res.cloudinary.com)

Still seeing it, or found something we did not cover? Ask here: members and our editors answer. Reading is open; writing needs a free account.

0 comments

…

5,441 members already hereReading, writing, commenting and voting. 0 verified · 166 joined this year