A VBScript campaign distributed through WhatsApp deploying RMM software
2026-06-24T08:51:54Z•784f8aabe8e1e8d32f7952be9305d2efd189b7e5b8acd0238b0acc529b9fd967
ArgamalCloud AtlasPowerCloudRATReverseSocksTor','SSHUEMSWorld Cup 2026container escapecontainer securitycryptominerexposed secretsgaming malwarehentai gamesmalicious wallpapersmalwaremisconfigurationpiracyrmmsteam workshopsupply chain attackvbscriptwardrivingwhatsappwifi security
What happened
Kaspersky SecureList entries (May–Jun 2026) detail multiple active and emerging threats: a global campaign distributing VBScript via WhatsApp that installs a UEMS RMM agent through a multi-stage chain; malware spread via malicious Steam Workshop wallpapers (targeting gamers, notably in China and Russia); Argamal RAT distributed in infected hentai games; and continued targeting of piracy sites with miners and RAT modules. Operational and defensive coverage includes a wardriving assessment ahead of the 2026 World Cup, analysis of container attack vectors and supply-chain risks, and Kaspersky’s K
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 784f8aabe8e1e8d32f7952be9305d2efd189b7e5b8acd0238b0acc529b9fd967
- Enrichment time
- 2026-06-24T08:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.