ToddyCat: your hidden email assistant. Part 2

2026-06-30T20:51:52Z12a298d68f9c1854648f41376231746a624147c1b6775b0db2dc7ce65cc46dcd
APTArgamalCobalt StrikeGmailOAuthRATRaaSSMB threatsSharkLoaderSteam WorkshopStrikeSharkThe GentlemenToddyCatUEMS RMMUmbrijVBScriptWhatsAppWi-Fi securityWorld Cup 2026container security','supply chain attacks','KIRA AIfake-AImalicious wallpapersphishingransomwarewardriving

What happened

Feed of Kaspersky Securelist research covering multiple active threats and defensive guidance: ToddyCat’s new Umbrij tool abuses OAuth tokens to compromise Gmail/Google accounts; StrikeShark campaign delivers Cobalt Strike Beacon via custom SharkLoader; The Gentlemen RaaS is evolving with custom backdoors and a new ransomware variant; a global WhatsApp-distributed VBS campaign installs a UEMS RMM agent; dozens of malicious Steam Workshop wallpapers and Argamal RAT hidden in games were discovered; a wardriving assessment highlights Wi‑Fi exposure ahead of the 2026 World Cup; and containerized‑環

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
12a298d68f9c1854648f41376231746a624147c1b6775b0db2dc7ce65cc46dcd
Enrichment time
2026-06-30T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ToddyCat: your hidden email assistant. Part 2 · Baitaphish