Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools
2026-06-25T20:51:53Z•8bc25a9c0914c5ca7208aeb3fa4ba000d19b5c159255cc425c4eb9daa4b4fcf3
ArgamalBeaconCobalt-StrikeRATRMMSMB-threatsSharkLoaderSteam-WorkshopStrikeSharkUEMSVBScriptWhatsAppWi-Fi-securityWorld-Cup-2026container-escapecontainer-securitydata-leaksfake-AI-toolshentai-distributionmalicious-wallpapersmisconfiguration-risksupply-chain-security (KIRA)phishingsecrets-exposuresupply-chain-attackswardriving
What happened
Kaspersky Securelist (June 2026) roundup highlighting a high-risk threat landscape for SMBs and consumers: rising phishing and fake-AI tool scams and data-for-sale activity; a new global campaign dubbed “StrikeShark” delivering Cobalt Strike Beacon via a custom SharkLoader loader; a WhatsApp-distributed VBScript campaign that installs a UEMS RMM agent through a multi-stage chain; malicious wallpapers circulating on Steam Workshop targeting gamers; Argamal RAT bundled with infected hentai games; wardriving findings exposing insecure public Wi‑Fi ahead of the 2026 World Cup; and persistent cloud
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 8bc25a9c0914c5ca7208aeb3fa4ba000d19b5c159255cc425c4eb9daa4b4fcf3
- Enrichment time
- 2026-06-25T20:51:53Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.