ikovrsps.com: a server handing out Java game files and an EXE tagged stealer and CoinMiner, and what to do if you ran them
ikovrsps.com is a web address that URLhaus lists three times in two days for game style files (Ikov.jar, Mina.jar and gamefiles/image.exe), all tagged stealer and runelite, two also tagged CoinMiner. If you only saw the name in a log or a warning, nothing is proven.
If you downloaded and ran one of these files, treat the Windows PC as compromised: change your passwords from another device, then scan with Microsoft Defender Offline and clean or reset Windows.
Facts checked October 11, 2026. Removal steps tested on Windows 11 (26H2) and checked against Microsoft's and the browser makers' current documentation.
Automatic
Get a free scan and check if your PC is infected.
Fortect finds malware, unwanted programs and the Windows damage they leave behind, and repairs it in one pass.
Programs like a file called Ikov.jar, Mina.jar or image.exe that came from ikovrsps.com usually arrive in groups; a free scan lists the companions that are easy to miss.
Do it yourself · free Remove ikovrsps.com (stealer and CoinMiner files) yourself 5 steps, about 15 minutes, no software needed.
Start the steps
Ikovrsps.com (stealer and CoinMiner files): summary
| Type | A malware server: URLhaus tags its three files stealer and runelite, and two of them CoinMiner |
|---|---|
| Risk | High if you ran one of the files: logins, tokens, wallet data and processor time may be taken. Low if you only saw the name |
| Symptoms | Often none. A hot, slow PC with high processor use and an unknown javaw.exe are the signs the tags suggest |
| How to get rid of it | Change passwords and sign out all sessions from another device, run Microsoft Defender Offline, delete the files, and reset Windows if you are not sure |
| Our check (11 October 2026) | One plain request from our server: a 307 redirect to another host. That clears nothing; the danger rating comes from URLhaus |
| Running since / first seen | Domain registered 22 January 2026; first file reported 6 October 2026 |
| Removal | Scan the PC with security software to find and remove the malware and anything installed with it. Fortect scans Windows for malware and repairs the system files and settings it damaged. Remove it nowTo use the full-featured product, you have to purchase a license for Fortect. The scan is free. |
Show 9 more facts
| Platform | Windows for image.exe; the jar files run wherever Java does, but the stealers vendors describe target Windows |
|---|---|
| Detection names | No Microsoft detection name is known for these files because we did not open them. Other vendors name similar Java stealers Trojan.Java.Fractureiser.* (Bitdefender) and Java/DiscordSteal.gen (Intego) |
| Name | Ikovrsps.com |
| Domain registered | 22 January 2026 |
| Evidence | 3 write-ups by security sites; details still limited |
| First seen | 6 October 2026 |
| Distribution | Typically fake installers, cracked programs, e-mail attachments, fake "verify you are human" pages and ads for popular apps |
| Damage | Installs other malware, often several programs at once |
| Facts checked | 11 October 2026 |
Facts checked on 11 October 2026 against the URLhaus data for ikovrsps.com held in our database, RDAP, one plain request from our server, and published reports by Check Point Research, Bitdefender, Intego, the OSRS Wiki and Microsoft Learn. We did not download the files and we infected no PC; the removal steps follow Microsoft's pages and were not tried on a live infection.
What ikovrsps.com is, and what we know about it
ikovrsps.com is not a program on your PC. It is a web address that the abuse.ch project URLhaus lists as a place where malware was served. The three files are named like parts of a game download, and the tags mention runelite, which is the name of a well known add on client for the game Old School RuneScape. We found no public write up of this address, so this page uses what URLhaus shows, what our server saw, and vendor reports on similar Java stealers.
- 1
What URLhaus lists
Three file addresses on ikovrsps.com: /Ikov.jar, /Mina.jar and /gamefiles/image.exe. Ikov.jar was added on 6 October 2026 at about 16:19 UTC, Mina.jar and image.exe on 7 October at about 04:41 UTC. All three carry the threat label malware_download and the same reporter, rc4. When we read our copy of the data, only image.exe was marked online; the two jar files were marked offline.
- 2
What the tags mean
stealer means the file is said to steal data such as passwords. CoinMiner (on the two jar files) means it is said to use your processor to mine cryptocurrency for someone else. runelite names the game client the files imitate or hide behind. runelure is a tag we cannot explain: we found no vendor page that defines it, so we do not claim to know whether it is a family name or a label the reporter made up.
- 3
What we could not confirm
We did not download any of the three files, so we cannot tell you what they do, what they connect to, or which Microsoft detection name they carry. URLhaus shows tags, not proof. We also do not know how a victim is sent to this address; the first step is not visible from the server side.
- 4
What this means for you
If you only saw the name in a firewall log, a blocked request or a warning, you are not infected by that alone. The risk is for a Windows PC where someone downloaded and ran Ikov.jar, Mina.jar or image.exe, or where a program fetched them. Our reading of the file names is that they target players of a game server called Ikov; that is a guess from the names, not a finding.
- Kind of threat
- A server that hands out two Java archives and one Windows program, tagged stealer; the two jar files are also tagged CoinMiner
- Where the files are
- hxxps://ikovrsps[.]com/Ikov.jar, hxxps://ikovrsps[.]com/Mina.jar and hxxps://ikovrsps[.]com/gamefiles/image.exe
- Domain registered
- 22 January 2026, registrar Ultahost, Inc., status active (RDAP, read 7 October 2026)
- URLhaus entries
- 3 file addresses, added 6 and 7 October 2026; 1 online (image.exe) and 2 offline in our copy of the data
- Delivery
- Not known. Game files that people download by hand or through a launcher are the likely route, which is our reading of the names
- Platform
- Windows for image.exe. A .jar file runs on any system with Java, so Mac and Linux users who ran a jar are also in question; the stealer part that the tags describe has only been documented for Windows
What ikovrsps.com (stealer and CoinMiner files) does on an infected PC
What we checked on 11 October 2026, and what we could not
We made one plain request to https://ikovrsps.com/ from our server, with no browser and no clicks. The server answered with a redirect to a different address. That clears nothing: a plain request is exactly what a cloaking server can answer differently from a real visitor.
Our server request, 11 October 2026
- The home page redirects awayThe answer was HTTP 307 Temporary Redirect from a LiteSpeed web server, pointing to hxxps://recaptcha[.]cloud/ with the server's address, our address and the host name added as parameters. recaptcha.cloud is not Google's reCAPTCHA domain. We did not follow the redirect, so we do not know what that page shows. A gate that sends visitors to a page styled as a check is a pattern vendors describe, but we did not see it here.
- Why that is not a clean resultA server that serves malware files can answer a plain request with an unrelated page and still hand the files to a visitor who asks for the exact file address. A quiet or odd home page is not a sign of safety.
- Notification requestNot seen in this one request. There was no page body to see, only the redirect.
- URLhaus listingThree file addresses tagged stealer and runelite, two also CoinMiner; one still online in our copy of the data.
- Downloads and the files themselvesWe did not download any file. We cannot tell you what Ikov.jar, Mina.jar or image.exe contain.
Dangerous: treat it as a malware server Our test was one plain request, so it proves nothing either way. The danger rating comes from the three URLhaus reports and their tags, not from our request. Do not download or run files from this address.
What happened to ikovrsps.com, from registration to our check
The domain is under nine months old and every report is from the last week. The dates come from RDAP and from the URLhaus data we hold; times are UTC.
22 January 2026
The domain is registered
RDAP shows ikovrsps.com registered on 22 January 2026 through Ultahost, Inc. The record was active when we read it on 7 October 2026.
6 October 2026
Ikov.jar is reported
At about 16:19 UTC abuse.ch contributor rc4 adds https://ikovrsps.com/Ikov.jar with the tags CoinMiner, runelite, runelure and stealer. The file is marked offline in our copy.
7 October 2026
Mina.jar and image.exe are reported
At about 04:41 UTC the same reporter adds Mina.jar (tags CoinMiner, runelite, runelure, stealer, offline) and gamefiles/image.exe (tags runelite, runelure, stealer, online). Two entries within two seconds suggest the files were found together.

All three URLhaus entries for ikovrsps.com. The jar files are offline, the exe was still online in our copy. 11 October 2026
Our plain request
The home page answers with a 307 redirect to a different host. We do not know whether the files are still served.

What the pattern suggests, and what it does not: a domain that waits nine months and then serves three files within a day looks like a server prepared for a campaign. That is our reading of the dates; no report says it.
How a Java game file can carry a stealer
We did not open Ikov.jar or Mina.jar. Security vendors have, however, published detailed analyses of Java archives that hide stealers behind game mods, and the mechanism is the same kind. Read the points below as how such files work in general, not as proof of what these two do.

- 1
A person installs a file that looks like part of a game
Check Point Research (18 June 2025) describes fake Minecraft mods and cheat tools on GitHub. The Java archive in that campaign did nothing when run with java -jar; it only ran when it sat in the Minecraft mods folder and the game started. That is why a casual scan or a sandbox without the game can see nothing.
- 2
The first stage checks where it runs
Check Point says the downloader compared system properties with a list of virtualization keywords and ran tasklist to look for analysis and network tools, and quit if it found them. A researcher's test machine therefore often sees a harmless file.
- 3
It fetches the next stage
In Check Point's case the address of the second stage was stored in a Base64 paste on Pastebin and loaded into memory. Bitdefender (published 8 June 2023, updated 21 May 2025) describes a staged Java chain called Fractureiser with a first stage that creates persistence and a later stage that downloads and updates the final payload.
- 4
It spreads and stays
Bitdefender found that the malware tried to infect other Java archives on the PC, including ones that are not game mods, and stripped their signature files afterwards. In one variant it installed a Windows service. Any program that runs Java could therefore be carrying it.
- 5
It sends your data out
Check Point lists Minecraft and Discord tokens, Telegram data, browser logins, wallet data and a screenshot, sent in a zip to a Discord webhook. Intego (29 May 2026) describes a newer polymorphic Java loader whose Windows payload sends Discord tokens and account fields to a Discord webhook.
A cryptocurrency miner, as the CoinMiner tag says, is a different goal: it uses your processor and graphics card, and the first sign is usually a hot, slow PC. Whether Ikov.jar and Mina.jar carry a miner, a stealer or both, we cannot say; URLhaus gives only the tags.
What ikovrsps.com (stealer and CoinMiner files) can steal or download
What a stealer of this kind can take from a Windows PC
The list below is what the sources say comparable Java based stealers take. It is not a list of what these three files take, because we did not open them. Each item is named by at least one source.
Reported for similar Java game malware
- Game account tokens
- Discord tokens
- Microsoft account credentials
- Saved browser logins and cookies
- Telegram data
- Cryptocurrency wallet data
- Clipboard contents, and wallet addresses swapped for the attacker's
- VPN and file transfer logins
- Files from Desktop and Documents
- A screenshot
- Processor time for mining
| Data | Detail | Source |
|---|---|---|
| Game and chat tokens | Minecraft, launcher, Discord and Telegram data taken and sent as JSON or a zip | Check Point |
| Browser data | Chromium, Edge and Firefox credentials (Check Point); cookies and saved logins from popular browsers (Bitdefender) | Check Point; Bitdefender |
| Microsoft login | A function that retrieves Microsoft account credentials | Bitdefender |
| Clipboard and crypto | Wallet data for about a dozen wallets; a clipboard monitor that replaces copied wallet addresses with the attacker's | Check Point; Bitdefender |
| Files and screenshot | Files from Desktop, Documents and source folders, and one screenshot | Check Point |
| Discord accounts | Tokens and account fields sent to a Discord webhook | Intego |
What this can cost you
Reading the site or seeing its name costs nothing. The risks below apply to a PC where one of the three files was run.
- High
Game, Discord and email accounts
A stolen token lets someone use an account without the password, and it can survive a password change until the session is signed out. Game accounts with valuable items are a common target.
- High
Crypto and banking logins
Wallet data and saved browser logins are on the lists above. Crypto sent out cannot be recalled, and a clipboard swapper can redirect a payment you make later.
- Medium
A slow, hot PC from mining
The CoinMiner tag points to a miner. It wears out fans, raises the power bill and makes the PC unusable for games.
- Medium
More infected files
Bitdefender found that the malware it studied infected other Java archives. Files you copy to friends can carry it on.
- Low
Nothing, if you only saw the name
A name in a block list, a log or a warning is not an infection.
What you may notice, and what you may not
Stealers are built to be quiet. The signs below come from the sources and from the CoinMiner tag; none is certain, and many victims notice nothing.
| Sign | What the reports show |
|---|---|
| High processor or graphics use with nothing open | The expected sign of a miner, which is our reading of the CoinMiner tag |
| A java or javaw process you did not start | The Java stages run inside Java. A javaw.exe in Task Manager with no game open is worth a look |
| A Windows service or program you did not install | Bitdefender found one variant that installed a service named NekoService; this is one build, not this server's files |
| Logins from new places, Discord messages you did not send | This follows from stolen tokens; it is our reading, not a quote |
| Jar files that changed | Bitdefender says the malware it studied removed the signature files from jar archives it infected |
| Nothing at all | Java stages that check for analysis tools and run in memory are designed to be quiet |
How to check the PC for ikovrsps.com (stealer and CoinMiner files)
How a person ends up with these files
Nobody needs to visit ikovrsps.com for any other reason than to download the files. We cannot say how people are led there. The routes below are the ones vendors found for similar Java game malware.
- 1
A fake or modified game client
The tag runelite and the folder name gamefiles suggest a client download. The OSRS Wiki says the official RuneLite site is runelite.net and that on 2 March 2022 Jagex and RuneLite added a link to it on the game homepage, particularly to prevent phishing by fake RuneLite websites. Anything else offering a client is not that.
- 2
Mods and cheat tools from a repository or chat
Check Point found fake mods with fake stars on GitHub. Stars and forks do not show a file is safe.
- 3
Files shared inside a gaming community
Intego notes that a jar can be passed through shared folders, chat apps and gaming communities. A file sent by a friend whose account was taken over is a common start.
- 4
A private server's own download
A private game server needs its players to install a client. That makes a download page believable. We did not see this server's page and do not say that the server itself is a fraud; we say that the files URLhaus lists are tagged as malware.
Check your PC before you delete anything
Start with the question that matters: did you or anyone on this PC download or run Ikov.jar, Mina.jar or image.exe, or a game client from a server called Ikov? If you saw the name in a router or DNS log, the device that asked is the one to check. If the answer is yes or you are not sure, do the checks below. None of them deletes anything.
While you check, stop using the PC for banking, email, work or crypto, and disconnect it from the network if you can.
- 1
Find the files
Open File Explorer > Downloads and look for Ikov.jar, Mina.jar and image.exe, and for the game folder you installed. Note names and dates; do not open them.
- 2
Look at Installed apps
Open Settings > Apps > Installed apps and sort by install date. Look for a game client, launcher or Java tool you did not install on purpose.
- 3
Look at Startup apps
Open Settings > Apps > Startup. A name you do not know, or a Java launcher that starts with Windows, is worth writing down. Do not delete yet.
- 4
Check Task Manager
Press Ctrl+Shift+Esc, open Processes and sort by CPU. Look for javaw.exe or a program you do not know using a lot of processor while you do nothing. Bitdefender also names a Windows service called NekoService for one build; look in Services only as a hint, since this server's files may differ.
- 5
Open Protection history
In Windows Security > Virus & threat protection > Protection history, look for anything blocked or quarantined around the time of the download. Microsoft says offline scan results appear there too.
- 6
Check your accounts from another device
Look at sign in activity for email, Discord, your game account, bank and exchange accounts, and at crypto balances. This is quicker than any file check.
- 7
A scan helps, but it does not clear the PC
A scan can find known files. Check Point says the Java downloader it studied had no detections when published, and Java loaders are often overlooked. Treat a clean result as one data point. The plan below is our judgement from Microsoft's pages and the vendor write ups, not a tested removal.
How to remove ikovrsps.com (stealer and CoinMiner files)
How to remove ikovrsps.com
A loader's job is to install other malware, so treat the PC as infected with more than one program until the scans are clean.
Step 1: Delete scheduled tasks that bring it back
Programs like ikovrsps.com add a scheduled task so they return after an uninstall or reopen a page at every sign-in. Start Task Scheduler, open Task Scheduler Library and sort by Last Run Time to see what ran recently.
On the Actions tab, a program in a user folder, a script or a web address is a warning sign; right-click such a task and choose Delete.
Tasks with names copying Google, Edge or Windows updaters but pointing to an odd folder are typical. The tool looks the same in Windows 11 and Windows 10.

Windows 11: Task Scheduler Library, the task selected, the Actions tab shows the file it runs. Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 2: Remove it from startup
Press Ctrl + Shift + Esc to open Task Manager and select Startup apps (Windows 11) or the Startup tab (Windows 10). Disable entries you do not recognise, especially ones with no publisher or with a name that copies a Windows component.
Right-click an entry and choose Open file location to see where it runs from: programs in
%AppData%or%Temp%deserve a closer look. Some entries are not listed there but in the registry Run keys, which the procedure below shows how to check.Full procedure with screenshots: Stop apps from opening at startup On uGetFix
Step 3: Delete the folders left behind
Uninstalling often leaves the program's folders, and some threats reinstall themselves from them.
Press Windows + R, type
%LocalAppData%and press Enter, then do the same for%AppData%and %ProgramData%, and look for folders named after ikovrsps.com, its publisher or created on the day the problem started. Delete those folders, and check C:\Program Files and C:\Program Files (x86) too.If Windows says a file is in use, end it in Task Manager or delete the folder after a restart in Safe Mode. The folders are the same in Windows 11 and Windows 10.
Full procedure with screenshots: Remove what malware leaves behind in Windows
Step 4: Scan the PC, then run the offline scan
A scan finds the parts of ikovrsps.com that the manual steps cannot see. In Windows Security > Virus & threat protection > Scan options, start a Full scan and quarantine what it reports.
Follow it with Microsoft Defender Antivirus (offline scan) > Scan now, which restarts the PC and checks the disk while Windows and the malware are not running.
It takes about 15 minutes and works the same in Windows 11 and Windows 10. If either scan finds something, run the full scan again after removal until it comes back clean.

Windows 11: Windows Security > Virus & threat protection > Scan options. Full procedure with screenshots: Run a Microsoft Defender Offline scan
Step 5: Change passwords from another device and sign out other sessions
Ikovrsps.com can copy saved passwords, cookies and session tokens and send them out in seconds, so cleaning the PC does not undo the theft.
Change your passwords on a device that was never infected, starting with the e-mail account, since every other reset goes through it. On each account, end all other sessions and check the recovery e-mail, phone number and forwarding rules.
Then turn on two-step verification. Sign in on the Windows 11 or Windows 10 PC again only after the offline scan is clean.
Full procedure with screenshots: Turn on two-step verification / secure a hacked account
If you use a Mac, an iPhone or an Android phone
The file image.exe is a Windows program. The two .jar files are Java archives, which can run on any system with Java installed.
| Your device | What we know | What to do |
|---|---|---|
| Mac | Intego says Java carrier files move freely between systems and that the final stealer it studied was for Windows. We do not know what Ikov.jar does on a Mac | If you ran a jar from this address, delete it, change the passwords you used on that Mac and scan it. Do not follow the Windows steps |
| iPhone or iPad | Java archives do not run on iOS. No source describes this threat there | Nothing to remove. If you typed passwords on a page from this address, change them |
| Android | Not known; the tags and sources describe desktop Java and Windows | Nothing to remove for this threat that we know of; change passwords if you entered any |
After removal: passwords, accounts and prevention
If you ran one of the files: clean up in the right order
The PC is one half. The other half is everything you typed or stored on it. The order matters: another device first, then the PC.

- 1
Change passwords from a clean device
Start with email, because it resets everything else, then Discord, game, Microsoft, bank, work and crypto accounts. Anything typed on the PC after the file ran may be known.
- 2
Sign out all sessions and turn on two step sign in
Tokens survive a password change. In Discord, Microsoft, Steam and your game account, use the option to sign out of all devices, then turn on two step sign in. Intego advises treating stolen Discord tokens as compromised and reviewing account activity.
- 3
Move crypto first if a wallet was on the PC
If a seed phrase or wallet file was ever on the PC, assume it is known. Create a new wallet and phrase on a clean device and move the funds.
- 4
Run Microsoft Defender Offline
Microsoft says to open Windows Security > Virus & threat protection > Scan options, choose Microsoft Defender Offline scan and select Scan now. Save your work first: Windows signs you out and restarts, and the scan takes about 15 minutes. If BitLocker is on the system drive, suspend it first or the restart may ask for the recovery key. Results are under Protection history. Microsoft notes that the scan does not run if Windows Recovery Environment is disabled.
- 5
Remove the files and check Java archives
Delete Ikov.jar, Mina.jar, image.exe and the game folder you installed from them. Bitdefender found that its malware infected other jar files, so do not copy jars from that PC to another.
- 6
If you are not sure, reset Windows
Open Settings > System > Recovery > Reset this PC. Remove everything wipes the PC. Because Java stages can spread into other archives and may sit in memory, the full wipe is the answer that does not depend on finding every piece. Back up documents first.
- 7
Restore only documents by hand
Copy back documents and photos, not programs, not jar files and not a system image from after the first contact. Install the game client only from its official site.
- 8
Watch your money and your accounts
Check card statements, exchange logs and game account activity for a few weeks. Turn on alerts. Tell the people you message if your Discord account sent links.
Keep a PC out of this kind of chain
Every write up we read starts with a person running a file that came with a game, a mod or a cheat.
Do
- Download RuneLite only from runelite.net, the address the OSRS Wiki names as official, or through the game's own homepage link.
- Treat any game client, mod or cheat tool from a chat message, a video description or a random repository as untrusted, however many stars it has.
- Keep Windows and Microsoft Defender updated; the offline scan uses the latest definitions.
- Use a password manager and two step sign in, so one stolen token or password is not enough.
- Keep a backup of documents on a disk that you unplug.
Don't
- Do not run image.exe, Ikov.jar or Mina.jar from this address.
- Do not install a private server's client on the PC you use for banking, email or crypto.
- Do not change your passwords on the PC you suspect.
- Do not share jar files from a PC that ran one of these files.
- Do not rely on a quiet scan to say that you are safe.
Questions about ikovrsps.com (stealer and CoinMiner files)
What is ikovrsps.com?
It is a web address that URLhaus, the malware tracking project run by abuse.ch, lists for three files:
- Ikov.jar
- Mina.jar
- gamefiles/image.exe
All are tagged stealer and runelite, and the two jar files are also tagged CoinMiner. They were reported on 6 and 7 October 2026.
It is not a program on your PC. We did not download the files, so what they contain is not confirmed by us.
Is ikovrsps.com safe to open?
No. Do not download or run files from it. Our own check was one plain request from our server, which got a redirect to another host.
That proves nothing, because a server that hands out malware can show a visitor something different from what it gives to a request for an exact file address. The rating comes from the three URLhaus reports and their tags, not from our request.
Is Ikov.jar or image.exe a virus?
URLhaus lists both addresses as malware downloads with the tag stealer. We did not open them, so we cannot name the family or say what each does.
Ikov.jar and Mina.jar are Java archives and image.exe is a Windows program. Treat any copy you ran as malware: change your passwords from another device, run a Microsoft Defender Offline scan, and reset Windows if you are not sure.
What do the tags runelite and runelure mean?
runelite is the name of a well known add on client for Old School RuneScape. The OSRS Wiki names runelite.net as the official site. The tag suggests the files imitate or hide behind that client.
We found no vendor page that explains runelure, so we do not claim to know whether it is a family name. Do not treat either tag as proof of what the files do.
I saw ikovrsps.com in my firewall or DNS log. Am I infected?
Not necessarily, and the name alone proves nothing. It does mean that a device on your network asked for it, which a person usually does only to download something.
Find which device it was, look in its Downloads folder for Ikov.jar, Mina.jar and image.exe, and run the checks on this page. Do any account changes from another device.
How do I remove this stealer from Windows?
Change your passwords and sign out all sessions from another device first. Then run a Microsoft Defender Offline scan (Windows Security, Virus and threat protection, Scan options), delete the three files and the game folder they came with, and check Installed apps and Startup apps for entries you did not add.
If you are not sure, reset Windows with Remove everything and restore only documents. We followed Microsoft's pages and did not test the steps on an infected PC.
What can a Java game stealer take?
Check Point lists Minecraft and Discord tokens, Telegram data, browser credentials, wallet data, files from Desktop and Documents, and a screenshot for a comparable campaign. Bitdefender adds Microsoft account credentials and a clipboard monitor that swaps wallet addresses.
We do not know which of these Ikov.jar does. Treat every password, token and wallet on the PC as known and change them from another device.
Does ikovrsps.com affect Mac, iPhone or Android?
A jar file runs on any system with Java, so a Mac user who ran Ikov.jar is in question, although the stealers vendors describe target Windows.
Intego says the final payload it studied was a Windows stealer and that Mac users should still scan jar files. iPhone cannot run Java archives. For Android we found no source. If you ran a file, change your passwords from another device.
Is the game server Ikov a scam?
We cannot say. We found no primary source about the game server itself, only that this domain serves files that URLhaus tags as malware. Treat the downloads as unsafe.
If you play on a private server, install clients only on a PC you do not use for banking or crypto, and get RuneLite itself only from runelite.net.
Will Fortect remove ikovrsps.com?
Fortect scans Windows for malware and unwanted programs and repairs the system files and settings they change, and its free scan shows what it finds on your PC before you decide anything.
For ikovrsps.com, follow the plan above as well: the browser steps take back permissions and settings that no scanner treats as a threat, and uninstalling the program that brought it removes the source.
Run Microsoft Defender's full scan and, if anything was found, its offline scan as a second opinion. If the symptoms are gone after the plan and both scans are clean, there is nothing more to do.
Sources
- Check Point Research: Fake Minecraft mods distributed by the Stargazers Ghost Network (18 June 2025) (read October 11, 2026)
- Bitdefender Labs: Infected Minecraft mods lead to multi-stage, multi-platform infostealer malware (8 June 2023, updated 21 May 2025) (read October 11, 2026)
- Intego: Java stealer malware hides in mod folders (29 May 2026) (read October 11, 2026)
- Old School RuneScape Wiki: RuneLite (official site and the 2 March 2022 homepage link) (read October 11, 2026)
- Microsoft Learn: Microsoft Defender Offline scan in Windows (updated 25 August 2026) (read October 11, 2026)