Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools
2026-06-27T08:51:52Z•c83a701d0813fbe4c03d002f0a3467874cf84b37a1c5de00c975609b7bdc9f24
argamalcloud_atlascobalt_strikecontainer_securitycontainersfake_ai_toolsmalicious_wallpapersmalwarephishingpowercloudratreverse_socksrmmsharkloadersmbsshsteam_workshopstrikesharksupply_chain_attackstoruemsvbscriptwardrivingwhatsappwifi_security
What happened
Kaspersky Securelist published a set of June 2026 reports describing a diverse, active threat landscape affecting SMBs and consumers: increased phishing and scams (including fake AI tools), multiple malware campaigns delivering Cobalt Strike Beacon via a custom SharkLoader (StrikeShark), a WhatsApp-distributed VBScript campaign installing a UEMS RMM agent, and Argamal RAT distributed with pirated hentai games. Researchers also found malicious Steam Workshop wallpapers being used to compromise gamers, ongoing piracy-related campaigns that added RAT/miner modules, and targeted APT activity ("Сlо
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- c83a701d0813fbe4c03d002f0a3467874cf84b37a1c5de00c975609b7bdc9f24
- Enrichment time
- 2026-06-27T08:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.