VirusTotal
Coverage of VirusTotal in the Nexus archive.
- ClickLock Mac malware locks apps until you give in
ClickLock is a Mac malware that tricks users into running a Terminal command, leading to data theft and remote access. Discovered by Group-IB, it has infected over 100 systems across 33 countries by stealing passwords, browser data, and cryptocurrency wallet files.
- [US] Opened a dodgy link, what's the likelihood of any issues?
A user joined a Discord to obtain a VRChat skin code, opened a link checked via VirusTotal (no threats detected), and later found Ngrok in their AppData folder via Malwarebytes. The user quarantined Ngrok but is uncertain about its origin and current risk.
- [US] I think that my friend got hacked on Discord. They're wanting me to download a CurseForge plugin for Minecraft
A user's friend received a suspicious Discord message requesting them to download a CurseForge plugin for a Minecraft server. The sender's account may be compromised, as the request involves an unverified ZIP file and JSON file that showed no results on VirusTotal. The user is unsure if this is a scam or a legitimate request.
- [NL] bad treatment scam?
A tour operator employee received a suspicious email requesting tour availability, which lacked details. After the company responded, the sender sent a new email falsely claiming rude treatment and threatening legal action, attaching a malicious 7z file detected as a virus by VirusTotal.
- Need a second opinion on a weird Discord interaction (Odd Minecraft server request + domain flags)
A user received a suspicious Discord friend request from the Wuthering Waves Official Discord, leading to a voice call with a person claiming to be German but speaking Turkish with unnatural vocal glitches. The individual requested feedback on a Minecraft server link with a newly registered domain (May 5, 2026) and defensively dismissed concerns about its legitimacy.
- Crypto Clipper Campaign Abuses Fake Reviews, AI Narrators, and VirusTotal Comments
An unknown threat actor is using fake reviews, AI narrators, and VirusTotal comments to promote malicious software through phishing pages, GitHub, and SourceForge projects, according to Check Point Research.
- Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
A zero-day vulnerability in Adobe Reader has been exploited via malicious PDFs since December 2025, as reported by EXPMON's Haifei Li. The first malicious artifact, 'Invoice540.pdf', appeared on VirusTotal on November 28, 2025.