DeepLoad exploits ClickFix and WMI persistence to steal credentials, enabling stealth reinfection after three days.
When somebody sends you a document as an attachment, don't just open it. Use the free tool Dangerzone to scrub it clean of ...