The Gentlemen are knocking: сustom backdoors and evolving tactics
2026-06-29T20:51:54Z•910e8abdff2205c32faf17381352d4c696c082ba99c716a9bec3840043c7dda9
ArgamalCobalt StrikeCobalt Strike BeaconFIFA World Cup 2026RATRMMRaaSSMB threat landscapeSharkLoaderStrikeSharkThe GentlemenUEMS RMMVBScriptWhatsAppWi‑Fi insecuritycryptominercustom backdoorsfake AI toolsmalicious Steam Workshopmalicious wallpapersphishingpirated content campaignsransomwaresupply chain attacks','container escape','container security','Kwardriving
What happened
Kaspersky Securelist (June 2026) published multiple investigations and landscape reports describing active and evolving threats to organizations and consumers: analysis of The Gentlemen RaaS (custom backdoors and a new ransomware variant); StrikeShark — a global campaign delivering Cobalt Strike Beacon via custom SharkLoader; a VBScript WhatsApp distribution chain that installs a UEMS RMM agent; dozens of malicious Steam Workshop wallpapers spreading malware; Argamal RAT distributed with infected hentai games; wardriving assessment of Wi‑Fi exposure ahead of the 2026 FIFA World Cup; and broad
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 910e8abdff2205c32faf17381352d4c696c082ba99c716a9bec3840043c7dda9
- Enrichment time
- 2026-06-29T20:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.