Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools

2026-06-25T20:51:53Z8bc25a9c0914c5ca7208aeb3fa4ba000d19b5c159255cc425c4eb9daa4b4fcf3
ArgamalBeaconCobalt-StrikeRATRMMSMB-threatsSharkLoaderSteam-WorkshopStrikeSharkUEMSVBScriptWhatsAppWi-Fi-securityWorld-Cup-2026container-escapecontainer-securitydata-leaksfake-AI-toolshentai-distributionmalicious-wallpapersmisconfiguration-risksupply-chain-security (KIRA)phishingsecrets-exposuresupply-chain-attackswardriving

What happened

Kaspersky Securelist (June 2026) roundup highlighting a high-risk threat landscape for SMBs and consumers: rising phishing and fake-AI tool scams and data-for-sale activity; a new global campaign dubbed “StrikeShark” delivering Cobalt Strike Beacon via a custom SharkLoader loader; a WhatsApp-distributed VBScript campaign that installs a UEMS RMM agent through a multi-stage chain; malicious wallpapers circulating on Steam Workshop targeting gamers; Argamal RAT bundled with infected hentai games; wardriving findings exposing insecure public Wi‑Fi ahead of the 2026 World Cup; and persistent cloud

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
8bc25a9c0914c5ca7208aeb3fa4ba000d19b5c159255cc425c4eb9daa4b4fcf3
Enrichment time
2026-06-25T20:51:53Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.