A VBScript campaign distributed through WhatsApp deploying RMM software
2026-06-22T20:51:54Z•3dda2cf0ea41b4b6f494f943d45815dfb0236eae3086d94cee05fc2799096f2e
ArgamalCloud AtlasExifTool vulnerability','macOS compromise'FIFA World Cup 2026KIRA AIPowerCloudReverseSocksSSHSteam WorkshopTorUEMS RMMVBSWhatsAppWi-Fi securitycontainer escapescontainer securityhentai game infectionmalicious wallpapersmalwareminerspiracyransomware?ratsupply chain attackswardriving
What happened
Kaspersky Securelist published multiple security briefings covering active criminal and APT activity: a global WhatsApp-distributed campaign delivering VBS scripts that install a UEMS RMM agent via a multi-stage chain; malicious wallpapers circulating through Steam Workshop targeting gamers (notably in China and Russia); the Argamal RAT distributed inside infected hentai games; and continued distribution of miners and RAT modules via piracy sites. They also reported on Cloud Atlas operations (ReverseSocks, SSH, Tor persistence and a new PowerCloud tool) targeting public sector/diplomatic hosts
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 3dda2cf0ea41b4b6f494f943d45815dfb0236eae3086d94cee05fc2799096f2e
- Enrichment time
- 2026-06-22T20:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.