Argamal: Malware hidden in hentai games

2026-06-12T20:51:52Z2d2a1ab4391c5c1d1342e21d03a84c9029502676b80718ce8f62ab79649cdbc4
APTAppleSeedArgamalCVE-2026-3102Cloud AtlasExifToolKimsukyPebbleDashPowerCloudQ1-2026 threat reportRATReverseSocksWi-Fi securitycontainer escapescontainer securitycryptominerhentai-gamesimage-parsing vulnerabilitymacOSsupply chain attackswardriving

What happened

Kaspersky Securelist highlights multiple active threats and security trends: a new Argamal RAT distributed via infected hentai games enabling remote control of victims; a high-impact ExifTool vulnerability (CVE-2026-3102) that can compromise macOS via a malicious image; ongoing Cloud Atlas APT activity targeting public-sector and diplomatic entities using ReverseSocks/SSH/Tor and a new PowerCloud payload; continued attacks on piracy sites where miners acquired RAT capabilities; Kimsuky campaigns using PebbleDash tools linked to the AppleSeed cluster; and broader findings on container attack-vs

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
2d2a1ab4391c5c1d1342e21d03a84c9029502676b80718ce8f62ab79649cdbc4
Enrichment time
2026-06-12T20:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Argamal: Malware hidden in hentai games · Baitaphish