A VBScript campaign distributed through WhatsApp deploying RMM software

2026-06-24T08:51:54Z784f8aabe8e1e8d32f7952be9305d2efd189b7e5b8acd0238b0acc529b9fd967
ArgamalCloud AtlasPowerCloudRATReverseSocksTor','SSHUEMSWorld Cup 2026container escapecontainer securitycryptominerexposed secretsgaming malwarehentai gamesmalicious wallpapersmalwaremisconfigurationpiracyrmmsteam workshopsupply chain attackvbscriptwardrivingwhatsappwifi security

What happened

Kaspersky SecureList entries (May–Jun 2026) detail multiple active and emerging threats: a global campaign distributing VBScript via WhatsApp that installs a UEMS RMM agent through a multi-stage chain; malware spread via malicious Steam Workshop wallpapers (targeting gamers, notably in China and Russia); Argamal RAT distributed in infected hentai games; and continued targeting of piracy sites with miners and RAT modules. Operational and defensive coverage includes a wardriving assessment ahead of the 2026 World Cup, analysis of container attack vectors and supply-chain risks, and Kaspersky’s K

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
784f8aabe8e1e8d32f7952be9305d2efd189b7e5b8acd0238b0acc529b9fd967
Enrichment time
2026-06-24T08:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · A VBScript campaign distributed through WhatsApp deploying RMM software · Baitaphish