Argamal: Malware hidden in hentai games
2026-06-12T20:51:52Z•2d2a1ab4391c5c1d1342e21d03a84c9029502676b80718ce8f62ab79649cdbc4
APTAppleSeedArgamalCVE-2026-3102Cloud AtlasExifToolKimsukyPebbleDashPowerCloudQ1-2026 threat reportRATReverseSocksWi-Fi securitycontainer escapescontainer securitycryptominerhentai-gamesimage-parsing vulnerabilitymacOSsupply chain attackswardriving
What happened
Kaspersky Securelist highlights multiple active threats and security trends: a new Argamal RAT distributed via infected hentai games enabling remote control of victims; a high-impact ExifTool vulnerability (CVE-2026-3102) that can compromise macOS via a malicious image; ongoing Cloud Atlas APT activity targeting public-sector and diplomatic entities using ReverseSocks/SSH/Tor and a new PowerCloud payload; continued attacks on piracy sites where miners acquired RAT capabilities; Kimsuky campaigns using PebbleDash tools linked to the AppleSeed cluster; and broader findings on container attack-vs
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 2d2a1ab4391c5c1d1342e21d03a84c9029502676b80718ce8f62ab79649cdbc4
- Enrichment time
- 2026-06-12T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.