Argamal: Malware hidden in hentai games
2026-06-14T20:51:54Z•b0ea0c8f7b389395ef4444c89e4f5d12fb101a4063f250f0e06f82d41411f121
AppleSeedArgamalCVE-2026-3102Cloud AtlasExifToolIoTKimsukyPebbleDashPowerCloudQ1 2026RATReverseSocksSSHTorWi‑Fi securitycontainer securitycryptominerhentai gamesmacOS compromisemobile threatspirated contentsupply chain attackswardriving
What happened
Kaspersky Securelist published multiple analyses highlighting active malware trends and attack vectors in mid‑2026: a new Argamal RAT distributed via infected hentai games; piracy campaigns that have added miner and RAT modules; and Kimsuky using PebbleDash tools linked to the AppleSeed cluster. They also detailed infrastructure/targeted activity from Cloud Atlas (new PowerCloud payload, persistence via ReverseSocks/SSH/Tor), container attack vectors and supply‑chain risks, and an upcoming World Cup wardriving assessment of Wi‑Fi hotspots in Mexico. A notable vulnerability affecting ExifTool (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- b0ea0c8f7b389395ef4444c89e4f5d12fb101a4063f250f0e06f82d41411f121
- Enrichment time
- 2026-06-14T20:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.