Argamal: Malware hidden in hentai games

2026-06-14T20:51:54Zb0ea0c8f7b389395ef4444c89e4f5d12fb101a4063f250f0e06f82d41411f121
AppleSeedArgamalCVE-2026-3102Cloud AtlasExifToolIoTKimsukyPebbleDashPowerCloudQ1 2026RATReverseSocksSSHTorWi‑Fi securitycontainer securitycryptominerhentai gamesmacOS compromisemobile threatspirated contentsupply chain attackswardriving

What happened

Kaspersky Securelist published multiple analyses highlighting active malware trends and attack vectors in mid‑2026: a new Argamal RAT distributed via infected hentai games; piracy campaigns that have added miner and RAT modules; and Kimsuky using PebbleDash tools linked to the AppleSeed cluster. They also detailed infrastructure/targeted activity from Cloud Atlas (new PowerCloud payload, persistence via ReverseSocks/SSH/Tor), container attack vectors and supply‑chain risks, and an upcoming World Cup wardriving assessment of Wi‑Fi hotspots in Mexico. A notable vulnerability affecting ExifTool (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
kaspersky_securelist
Record identifier
b0ea0c8f7b389395ef4444c89e4f5d12fb101a4063f250f0e06f82d41411f121
Enrichment time
2026-06-14T20:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.